[72209] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: ultradns reachability

daemon@ATHENA.MIT.EDU (Leo Bicknell)
Fri Jul 2 10:43:56 2004

Date: Fri, 2 Jul 2004 10:43:17 -0400
From: Leo Bicknell <bicknell@ufp.org>
To: "Nanog@Merit. Edu" <nanog@merit.edu>
Mail-Followup-To: "Nanog@Merit. Edu" <nanog@merit.edu>
In-Reply-To: <33C3E77C-CC33-11D8-AB36-000A95E7E6B4@isc.org>
Errors-To: owner-nanog-outgoing@merit.edu



--82I3+IH0IqGh5yIs
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

In a message written on Fri, Jul 02, 2004 at 10:22:09AM -0400, Joe Abley wr=
ote:
> This leaves the anycast servers providing all the optimisation that=20
> they are good for (local nameserver in toplogically distant networks;=20
> distributed DDoS traffic sink; reduced transaction RTT) and provides a=20
> fall-back in case of effective reachability problems for the anycast=20
> nameservers.
>=20
> This is so trivial, I continue to be amazed that PIR hasn't done it.

I talked to Rodney about this a long time ago, as well as a few
other people.  What in practice seems simple is complicated by some
of the software that is out there.  See:

http://www.nanog.org/mtg-0310/pdf/wessels.pdf

Note in the later pages what happens to particular servers under
packet loss.  They all start to show an affinity for a subset of
the servers.  It's been said that by putting some non-anycasted
servers in with the anycasted servers what can happen is if the
anycast has issues many things will "latch on" to the non-anycasted
servers and not go back even when the anycast is fixed.

How serious this is for something like .org I have no idea, but it's
clear all the software has issues, and until they are fixed I don't
think this is just a slam dunk.

--=20
       Leo Bicknell - bicknell@ufp.org - CCIE 3440
        PGP keys at http://www.ufp.org/~bicknell/
Read TMBG List - tmbg-list-request@tmbg.org, www.tmbg.org

--82I3+IH0IqGh5yIs
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (FreeBSD)

iD8DBQFA5XSFNh6mMG5yMTYRAoUTAJ42SWGlDS7JGRhlJc2c787OqTKJUQCePza/
n71oUHrxiFTntnXbBBtu+zI=
=yF4U
-----END PGP SIGNATURE-----

--82I3+IH0IqGh5yIs--

home help back first fref pref prev next nref lref last post