4 ms·
Thank you for opening the can of worms. That was my goal when I asked this question! As for what am I thinking of? All of the above! They're all part of my day
by softfalcon 1y ago
Thank you for opening the can of worms. That was my goal when I asked this question!
As for what am I thinking of? All of the above! They're all part of my day job for the software I build.
Also, this isn't meant to be flippant, I agree with what you're saying! :D
- m3047 1y ago> This is because standard TCP packets max out at ~65 Kb. BTW, frags are bad. DNS infra is still kneecapped by what turned out to be an extremely exuberant kicking of the can down the road packaged as "best practice". I think the architectural discussion must have been "100 nameservers for an AD domain, plus AUTHORITY and ADDITIONAL, not to mention DNSSEC..." "Oh UDP is fine. Frags aren't a problem, the routers and smart NICs will handle it fine." "4096 ought to be enough for anybody." "Good. I'll have another Old Fashioned then." And then the clever attacks begin. Jumbos are great, but the PMTU has to support it. Localhost or a datacenter, maybe a local network. Somewhere between BIND 9.12.3 and BIND 9.18.21 the default for max-udp-size changed from 4096 to 1232. Just sayin....