3 ms·
I would encourage fairly tech-savvy users to set up their own DNS resolvers - fast, more private and a way of bypassing your ISPs censorship. Just make sure to
by Libre___ 10y ago
I would encourage fairly tech-savvy users to set up their own DNS resolvers - fast, more private and a way of bypassing your ISPs censorship.
Just make sure to configure ACLs so recursive queries are limited to you and not part of a botnet. Also BIND9 might not be a good idea for a low-maintenance solution.
- Thaxll 10y agoIt's a bad idea for performance, because your ISP has caches for Google, Netflix ect .. so you probably won't get them.
- Libre___ 10y agoThat's not how Google GGC and their LB works, the authoritative NSes looks at the IP of the querying resolver and hands out a response depending on that
- Thaxll 10y agoWell if you use a generic DNS server you won't get DNS answers that are geoip based because you will hit the cache of that DNS server and since they don't query google servers with your ISP IP you will get a generic endpoint.
- sajal83 10y agoFreenom appears to not send part of the IP upstream...
- chris_wot 10y agoI don't think that's such a big deal. Many, many years ago I setup a BIND9 caching forward nameserver. It caches all of those things for me, so there was very little in the way of any slowdown.
- krylon 10y agoDuring my training, at one point, I helped in a BIND4-to-BIND9-migration. I learned more about DNS than I ever wanted to know (and then even more to avoid having to learn Rexx). (I have forgotten most of it since.) I set up a DNS server for my LAN to see if I had understood what I had read. Haven't looked back since. The main advantage, initially, was performance, but it has other advantages, too. Although, now that you mention it, I kind of do use BIND9. It hasn't been that much work over the years, really. I am open to alternatives, but so far, I have not found a solution that would be easier to maintain and serve both as a recursive resolver and as an authoritative nameserver for my local zone. (I do admit that I did not look very hard, because the current situation with BIND works for me.)
- drdaeman 10y agoPowerDNS is nice. Basic setup is as simple as BIND9's, and their backend system is very flexible, so if you encounter yourself in need of something uncommon, you can probably still have it easily (using "pipe" backend and a bit of scripting language of your choice).
- krylon 10y agoThanks! I'll take a look at it!