Re: Sporadic but noticable SERVFAILs in specific nodes of an anycast resolving farm running BIND

2014-03-09 Thread Kostas Zorbadelos
LuKreme krem...@kreme.com writes: On 08 Mar 2014, at 12:52 , Kostas Zorbadelos kzo...@otenet.gr wrote: One mitigation approach is to blackhole the domains using local zones. That’s not much of a mitigation. Not having open resolvers would be mitigation. It is a quick and dirty approach,

Re: Sporadic but noticable SERVFAILs in specific nodes of an anycast resolving farm running BIND

2014-03-09 Thread Doug Barton
On 3/8/2014 1:30 PM, sth...@nethelp.no wrote: One mitigation approach is to blackhole the domains using local zones. That�s not much of a mitigation. Not having open resolvers would be mitigation. Not having open resolvers is good - but unfortunately doesn't help against misbehaving clients