Re: Middleboxes and EDNS(0)

Ray Bellis <[email protected]> Tue, 16 Dec 2014 09:19:43 +0000
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
> On 15 Dec 2014, at 15:48, Paul Hoffman <[email protected]> wrote:
>> 
> The problem is that the first quote is in a section called "6.1.1.  Basic Elements". This seems, well, basic.
> 
> So, is this an errata for the first quote?
> 

I wouldn't say the first quote is incorrect - a protocol-savvy forwarder (e.g. BIND configured as a forwarder) _should_ strip EDNS options and insert its own.

IMHO the fault is in the working of the second quote, where the word "forwarder" has been used again, but in practise should probably have read "proxy".  I believe it was intended to be a nod towards this from Section 3 of RFC 5625:

 "The role of the proxy should therefore be no more and no less than to
  receive DNS requests from clients on the LAN side, forward those
  verbatim to one of the known upstream recursive resolvers on the WAN
  side, and ensure that the whole response is returned verbatim to the
  original client.

  It is RECOMMENDED that proxies should be as transparent as possible,
  such that any "hop-by-hop" mechanisms or newly introduced protocol
  extensions operate as if the proxy were not there."

Ray


_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext