4 ms·
So, could one really do this OpenDNS thing behind a pay-for-internet-service? Yes but it requires the pay-for-internet provider to think about their real usage
by iigs 17y ago
So, could one really do this OpenDNS thing behind a pay-for-internet-service?
Yes but it requires the pay-for-internet provider to think about their real usage scenarios and plan for them appropriately. I'm involved in the engineering of a similar system that has nearly a million users, and we've chosen to leave port 53 wide open, even though it can theoretically be used for DNS tunneling or other nefarious use.
Also, I disagree with the comments on the post that claim that ISP DNS is the #1 cause of slowdowns -- DNS on an ISP scale is surprisingly easy to dimension and support in the common case. The important aspects of DNS administration center around debugging misbehaving authoritative servers and management of Denial of Service attacks.
- pbhjpbhj 17y agoI used to find that I'd get slow downs when performing requests because the ISP wasn't answering the DNS query in a timely fashion. This would usually resolve itself in half-an-hour or so, possibly a load issue. But with OpenDNS I've not had those problems, my ISP nameservers are there as backup however if I should need them. Also OpenDNS optionally does filtering and allows reporting of lookups made. As my kids grow and explore for themselves I think this will be useful.