Hi! We are testing pdns-recursor 3.6 with a query rate about 5000 query/s. The test is simple query for A record of a single domain. I was surprised to found that about 10-20% of the reply don't have Answer RR section. I have disabled the packet cache but the result is the same.
Does someone have an idea how this may be happen? Is that the new DoS protection feature of pdns-resursor? Thanks, Vu ------------- Normal packet ------------- Domain Name System (response) [Request In: 9] [Time: 0.000219000 seconds] Transaction ID: 0x002b Flags: 0x8080 (Standard query response, No error) 1... .... .... .... = Response: Message is a response .000 0... .... .... = Opcode: Standard query (0) .... .0.. .... .... = Authoritative: Server is not an authority for domain .... ..0. .... .... = Truncated: Message is not truncated .... ...0 .... .... = Recursion desired: Don't do query recursively .... .... 1... .... = Recursion available: Server can do recursive queries .... .... .0.. .... = Z: reserved (0) .... .... ..0. .... = Answer authenticated: Answer/authority portion was not authenticated by the server .... .... ...0 .... = Non-authenticated data: Unacceptable .... .... .... 0000 = Reply code: No error (0) Questions: 1 Answer RRs: 1 Authority RRs: 0 Additional RRs: 0 Queries www.spirentcom.com: type A, class IN Name: www.spirentcom.com Type: A (Host address) Class: IN (0x0001) Answers www.spirentcom.com: type A, class IN, addr 69.20.41.238 ------------------------ Packet missing answer RR ------------------------ Domain Name System (response) [Request In: 7] [Time: 0.000390000 seconds] Transaction ID: 0x002b Flags: 0x8080 (Standard query response, No error) 1... .... .... .... = Response: Message is a response .000 0... .... .... = Opcode: Standard query (0) .... .0.. .... .... = Authoritative: Server is not an authority for domain .... ..0. .... .... = Truncated: Message is not truncated .... ...0 .... .... = Recursion desired: Don't do query recursively .... .... 1... .... = Recursion available: Server can do recursive queries .... .... .0.. .... = Z: reserved (0) .... .... ..0. .... = Answer authenticated: Answer/authority portion was not authenticated by the server .... .... ...0 .... = Non-authenticated data: Unacceptable .... .... .... 0000 = Reply code: No error (0) Questions: 1 Answer RRs: 0 Authority RRs: 0 Additional RRs: 0 Queries www.spirentcom.com: type A, class IN Name: www.spirentcom.com Type: A (Host address) Class: IN (0x0001) _______________________________________________ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users