[102326] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Repotting report

daemon@ATHENA.MIT.EDU (Leo Bicknell)
Mon Feb 4 20:27:54 2008

Date: Mon, 4 Feb 2008 20:21:27 -0500
From: Leo Bicknell <bicknell@ufp.org>
To: Kevin Loch <kloch@kl.net>
Cc: NANOG list <nanog@nanog.org>
Mail-Followup-To: Kevin Loch <kloch@kl.net>, NANOG list <nanog@nanog.org>
In-Reply-To: <47A7B2EA.5050505@kl.net>
Errors-To: owner-nanog@merit.edu



--qMm9M+Fa2AknHoGS
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

In a message written on Mon, Feb 04, 2008 at 07:50:50PM -0500, Kevin Loch w=
rote:
> There is an interesting variation in what records are returned for a
> standard 512 byte request (dig ns . @[x].root-servers.net):
>=20
> A,C,D,E,F,G,I,J: return the same 10 A records and 4 AAAA records in the
> same order every time.  They never return A records for K,L,M and never
> get AAAA records for K,M.
>=20
> B: returns all 13 A records in random order and then two AAAA records
> in random order.  This allows all records to be returned with equal
> weight within each record type.
>=20
> H,K,L,M: return all 13 A records in static order and then A and F AAAA
> records so H,J,K,M AAAA records are never returned.
>=20
> Tested with dig 9.4.1-p1 on a v6 enabled system.

I concur.  An interesting thing I noticed that doesn't really cause
an operational problem but may confuse some people is their behavior
is also quite different when queried for "any".  If your a lazy
admin like me who is used to typing "dig any foo" for testing you
may try "dig any . @[a-m].root-servers.net."

When I do that, I get the following response:

a, c, d e, f, g, i and j return 1 SOA, 8 A, and 3 AAAA's (the first 3).
b, h, l, k, and m return 1 SOA, 13 A, no AAAA records.

If you make this mistake you might think b, h, l, k and m have no
IPv6 data, which is wrong.  Querying with NS (as nameserver would
do) clearly shows that.

While a cosmetic problem, I fear it may confuse a number of admins
as the troubleshoot problems in the near future.

--=20
       Leo Bicknell - bicknell@ufp.org - CCIE 3440
        PGP keys at http://www.ufp.org/~bicknell/

--qMm9M+Fa2AknHoGS
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (FreeBSD)

iD8DBQFHp7n4Nh6mMG5yMTYRAhWmAJsG+CLg7bn/A8zOw8qtur4dfyKqpwCeP5tz
yNWxT7jb3+miiCVO43O/7Zk=
=mtkQ
-----END PGP SIGNATURE-----

--qMm9M+Fa2AknHoGS--


home help back first fref pref prev next nref lref last post