[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [IPv6] Re: FYI: DNSOPS presentation
On 2010-04-03 09:57, Igor Gashinsky wrote:
...
> :: Surely a better hack would be for recursive resolvers in IPv6-broken
> :: networks not to serve up AAAA records at all? Tunnel users could
> :: always find another resolver.
>
> It is the same hack.
Not if applied administratively, and reversed administratively
when the v6 brokenness is fixed. From a network ops point of view,
this is much cleaner than automated detection, and will also
put the responsibility in the right place: the network manager
who has not deployed v6.
And early adopters who want to bypass the hack can simply
configure a DNS server that does deliver AAAA.
Brian
Brian
You would use that very same feature that was
> developed to accomplish this (filter-aaaa) -- what's more, when your
> network stops being v6-broken, you get the extra benefit that the users
> who can query your dns resolvers over ipv6 can now get AAAA's as first
> step of rollout...
>
> -igor
>