Hi Wouter,

Here is a patch to implement only "max-udp-size" (a revised version).
I hope this would be applied to mainline.

 max-udp-size: <number>
   Maximum UDP response size.
   Valid values are 512 to 4096. Default is 4096.

In spite of my allow_minimal patch, Unbound should implement
max-udp-size option and defaults to 4096.
Because currently Unbound's response size has no limit and it can be
dangerous high-amplification-rate reflector if Unbound is mistakenly
configured as open-resolver. Also useful if we want to avoid IP
fragment.

Regards,
--
 Daisuke HIGASHI <[email protected]>

Attachment: unbound-maxudpsize.patch
Description: Binary data

_______________________________________________
Unbound-users mailing list
[email protected]
http://unbound.nlnetlabs.nl/mailman/listinfo/unbound-users

Reply via email to