Re: Middleboxes and EDNS(0)

Ted Lemon <[email protected]> Fri, 19 Dec 2014 08:11:38 -0500
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
On Dec 18, 2014, at 11:29 PM, Kumar Ashutosh <[email protected]> wrote:
> If DNS gets OPT RR (A) in an incoming packet, it will return back the same OPT RR in the final response back to the sender.

No, that's not what the text says.   If you read the whole section, it says that if the middlebox isn't being intelligent about what's in the OPT RR, it should forward it without modification.   If it is intelligent, it is assumed to be able to do the right thing, and the interaction between it and the upstream server is a separate transaction from the interaction between it and the downstream client: that is, state must somehow be maintained.   Having implemented a proxy that fiddles with EDNS0 on the way through, this is how I handled it, and it seems to work nicely.

Section 6.1.1 says that if an OPT RR is received, one must be returned, but there is no requirement that it be the _same_ one.   Indeed, that doesn't really make sense.

Of course, I am not exactly an expert on this, so I'm curious whether the assertion I have just made will provoke a stern correction, but I would be surprised if it did.

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext