5 ms·
What background does one need to understand the "4.4.8.8.in-addr.arpa" paragraphs? I'm a career web developer who took a networking course many years ago but "t
by detcader 7y ago
What background does one need to understand the "4.4.8.8.in-addr.arpa" paragraphs? I'm a career web developer who took a networking course many years ago but "timely inversion," "DNS zone," what "public" means as an adjective for a DNS server, "hop," and "block of IP addresses" are all presented like I'm supposed to intimately know them already...maybe I'm just missing something
- bluejekyll 7y agoI commend the author for attempting to make this subject more approachable to people less familiar with networking, but it’s always tough to present this and understand how much you need to explain. - zone: you can think of as an SOA, start of authority, for a set of records. For example: there is an SOA record for example.com. In addition there are NS records that express what nameservers are responsible for being the authority, trusted server, of the zone. Often zones are expressed in a single file, and loaded into the authoritative server, and it contains all the additional records for the zone, like A address records. - public: in this context probably is referring to the fact that it’s exposed and reachable from the greater internet. Often people create internal private zones that only work inside a particular network. - hop: a network hop is a router on the network, and internet. Each represents a hop, this is important for things like the TTL on a UDP packet (distinct from the TTL on a DNS record), each hop decrements the packets TTL by 1. This is really important for multicast packets. - block of IPs: generally refers to the CIDR block, which designated a routable network. 10/8 means all addresses that match 10.x.x.x, where as 10.10.1/24 is the 10.10.1.x network.
- teddyh 7y agoThe article is not actually explaining it, merely obliquely hinting at it. If you want to look up an IP address and get a server name (i.e. the reverse of a normal DNS lookup where you look up a name and get a DNS record containing an IP address), you do a “reverse” DNS lookup. Since the DNS protocol does not support this operation directly, this is enabled by a somewhat ugly hack, namely the transformation of the IP address into a name, which you can then look up and get a DNS record containing a name. For example: foo.example.com. A 192.0.2.3 is a name with an attached DNS record containing an IP address. To do a reverse lookup, we transform the address into the name “3.2.0.192.in-addr.arpa”, and look up not the A record (containing an address) for that name, but the PTR record, containing a name: 3.2.0.192.in-addr.arpa. PTR foo.example.com. You can think of DNS record types (A/PTR/MX/etc.) as types or classes in a programming language. What data a DNS record can contain, and what that data should mean, is controlled by the record type. This is the essence of it. There are always various minutiae one could get into, like the fact that IPv6 has a separate procedure to transform addresses into names, and, just as a name can have more than one address, the lookup of one address can result in more than one name. To directly answer your questions: • “Timely inversion” is not used as a technical term, it’s just a cute way of referencing the transformation procedure for an IP address into a name able to being looked up in the DNS. • A “zone” is technically a collection of DNS records, restricted to a particular domain or subdomain. For example, the zone for “example.com” would normally contain all DNS records for not only “example.com”, but also the records for the names “www.example.com” and “foo.example.com”. The purpose of zones is that a zone is the mechanism by which the responsibility to respond to queries about DNS data is delegated to DNS servers. If you want questions about some names to be answered by some special DNS servers, you have to put those names in a separate zone. This is unusual but not unheard of – the other day¹ Cloudflare had problems related to the fact that they have actually delegated “www.cloudflare.com” to separate name servers from the name servers which are authoritative for the “cloudflare.com” zone. I.e. “www.cloudflare.com” is its own zone. Note however that this is unusual. You can tell if something is its own zone by the presence of an SOA record (and NS records) on the name; www.example.com does not have an SOA record, but www.cloudflare.com does. • “Public” in this context simply means “for use by the public” or “publicly accessible”. And it’s strictly speaking a DNS resolver, not an authoritative DNS server for any specific zone or zones. • The use of the word “hop” is, I believe, a further indication of the belief by the author in the stack-of-resolvers model, but this is a false belief. What actually happens is that a resolver asks one authoritative server (starting with the root servers), receives as a reply a list of better servers to ask, and the resolver asks those authoritative servers in turn. This is the actual “hop” referred to in reality. • A “block” of IP addresses is a contiguous span of IP addresses. IP addresses are not allocated to organizations or ISPs around the world randomly or individually, but are instead delegated into as large and as contiguous spans as is possible. This is because the routing tables in routers are composed of lists of spans of IP addresses, and it is vital to minimize these lists, because if the core routers run out of memory, no more addresses can be routed. 1. https://news.ycombinator.com/item?id=19641155 https://news.ycombinator.com/item?id=19641155
- detcader 7y agoThanks to you and bluejekyll! I am understanding it a bit better with the breakdown
- pm90 7y agoFor the cloudflare case, I found this interesting: dig www.cloudflare.com ; <<>> DiG 9.10.6 <<>> www.cloudflare.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 38923 ;; flags: qr rd ra ad; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 512 ;; QUESTION SECTION: ;www.cloudflare.com. IN A ;; ANSWER SECTION: www.cloudflare.com. 16 IN A 104.17.210.9 www.cloudflare.com. 16 IN A 104.17.209.9 ;; Query time: 14 msec ;; SERVER: 75.75.75.75#53(75.75.75.75) ;; WHEN: Sat Apr 13 14:46:25 PDT 2019 ;; MSG SIZE rcvd: 79 dig cloudflare.com ; <<>> DiG 9.10.6 <<>> cloudflare.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 16630 ;; flags: qr rd ra ad; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 512 ;; QUESTION SECTION: ;cloudflare.com. IN A ;; ANSWER SECTION: cloudflare.com. 536 IN A 198.41.215.162 cloudflare.com. 536 IN A 198.41.214.162 ;; Query time: 73 msec ;; SERVER: 75.75.75.75#53(75.75.75.75) ;; WHEN: Sat Apr 13 14:46:47 PDT 2019 ;; MSG SIZE rcvd: 75 Why does cloudflare.com resolve to a different IP address than www.cloudflare.com?
- teddyh 7y ago> Why does cloudflare.com resolve to a different IP address than www.cloudflare.com? Probably because the IP addresses on cloudflare.com leads to a simpler web server which seems to only reply with redirects to www.cloudflare.com, and might not have any actual web pages.
- bluejekyll 7y agoBased on the outage people noticed the other day with www.cloudflare.com, we actually know that www is delegated to other nameservers. Notice that there is an SOA and NS records for www.cloudflare.com if you dig for them. Given this, they can't just CNAME from one zone to the other (if they want to include additionals from the subzone). So my guess is that the resolution of cloudflare.com is relying on rules setup for an HTTP 301, as opposed to the relying on DNS aliasing.