On Wed, 21 Nov 2018, Paul Wouters wrote:

I think you are right, and we are mixing up INTERNAL_IP4_DNS with
INTERNAL_DNS_DOMAIN.

the idea is that the client can decide to not only use some
authoritative internal servers, but also use some recursive internal
servers. But I think those should be specified in the exiting
INTERNAL_IP4_DNS / INTERNAL_IP6_DNS attributes.

Actually, that does not work. The current specification does not allow
a INTERNAL_IP4_DNS or INTERNAL_IP6_DNS to be associated with only some
(or none) of the INTERNAL_DNS_DOMAINS.

I suggest we change the above to:

  A client using these configuration payloads will be able to request
   and receive Split DNS configurations using the INTERNAL_DNS_DOMAIN
   and INTERNAL_DNSSEC_TA configuration attributes.  The client device
   can use the internal DNS server(s) for any DNS queries within the
   assigned domains.  DNS queries for other domains MAY be sent to
   an internal recursive DNS server specified in an INTERNAL_IP4_DNS
   or INTERNAL_IP6_DNS Configuration Payload but MAY also be resolved
   using the client's regular DNS resolving mechanisms outside of the
   IPsec connection.

So I suggest instead:

   A client using these configuration payloads will be able to request
   and receive Split DNS configurations using the INTERNAL_DNS_DOMAIN
   and INTERNAL_DNSSEC_TA configuration attributes.  These attributes
   MUST be accompanied by one or more INTERNAL_IP4_DNS or
   INTERNAL_IP6_DNS configuration attributes.  The client device can
   then use the internal DNS server(s) for any DNS queries within the
   assigned domains.  DNS queries for other domains MUST be sent to the
   regular DNS service of the client.

Paul

_______________________________________________
IPsec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipsec

Reply via email to