On Wed, 21 Nov 2018, Paul Wouters wrote:
I think you are right, and we are mixing up INTERNAL_IP4_DNS with
INTERNAL_DNS_DOMAIN.
the idea is that the client can decide to not only use some
authoritative internal servers, but also use some recursive internal
servers. But I think those should be specified in the exiting
INTERNAL_IP4_DNS / INTERNAL_IP6_DNS attributes.
Actually, that does not work. The current specification does not allow
a INTERNAL_IP4_DNS or INTERNAL_IP6_DNS to be associated with only some
(or none) of the INTERNAL_DNS_DOMAINS.
I suggest we change the above to:
A client using these configuration payloads will be able to request
and receive Split DNS configurations using the INTERNAL_DNS_DOMAIN
and INTERNAL_DNSSEC_TA configuration attributes. The client device
can use the internal DNS server(s) for any DNS queries within the
assigned domains. DNS queries for other domains MAY be sent to
an internal recursive DNS server specified in an INTERNAL_IP4_DNS
or INTERNAL_IP6_DNS Configuration Payload but MAY also be resolved
using the client's regular DNS resolving mechanisms outside of the
IPsec connection.
So I suggest instead:
A client using these configuration payloads will be able to request
and receive Split DNS configurations using the INTERNAL_DNS_DOMAIN
and INTERNAL_DNSSEC_TA configuration attributes. These attributes
MUST be accompanied by one or more INTERNAL_IP4_DNS or
INTERNAL_IP6_DNS configuration attributes. The client device can
then use the internal DNS server(s) for any DNS queries within the
assigned domains. DNS queries for other domains MUST be sent to the
regular DNS service of the client.
Paul
_______________________________________________
IPsec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipsec