On Wed, Jan 29, 2014 at 2:02 PM, Toke Høiland-Jørgensen <[email protected]> wrote: > Dave Taht <[email protected]> writes: > >> works. yea! no more nat holes for ipv4 dns. > > Eh? Nat holes for DNS? What exactly are you doing, and what is your > setup? :) > > -Toke
1 case: Since most forwarders can't be trusted to return NXDOMAIN, an internal email box at several of my sites runs dns directly. A few dnsrbl providers offer ipv6 transport, so it's possible. One advantage of dnssec is we get NXDOMAIN working again, so a forwarder can be used... -- Dave Täht Fixing bufferbloat with cerowrt: http://www.teklibre.com/cerowrt/subscribe.html _______________________________________________ Cerowrt-devel mailing list [email protected] https://lists.bufferbloat.net/listinfo/cerowrt-devel
