Re: Middleboxes and EDNS(0)

Ted Lemon <[email protected]> Fri, 19 Dec 2014 14:45:45 -0500
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
On Dec 19, 2014, at 11:25 AM, Paul Hoffman <[email protected]> wrote:
> Huh? The text says no such thing, which is why I asked the question. That is a consistent interpretation, but it is certainly not in the text.

Here's what the text says:

   Middleboxes that simply forward requests to a recursive resolver MUST
   NOT modify and MUST NOT delete the OPT record contents in either
   direction.

   Middleboxes that have additional functionality, such as answering
   queries or acting as intelligent forwarders, SHOULD be able to
   process the OPT record and act based on its contents.  These
   middleboxes MUST consider the incoming request and any outgoing
   requests as separate transactions if the characteristics of the
   messages are different.

I read the last sentence as saying what I paraphrased:

> No, that's not what the text says.   If you read the whole section, it says that if the middlebox isn't being intelligent about what's in the OPT RR, it should forward it without modification.   If it is intelligent, it is assumed to be able to do the right thing, and the interaction between it and the upstream server is a separate transaction from the interaction between it and the downstream client: that is, state must somehow be maintained.

I don't see another way to read this.

Now, to be honest, I interjected here in response to Kumar Ashutosh's comment, not with the motivation of actually answering your original question.   The answer to your original question seems obvious to me: follow the advice on middleboxes.   The other advice is for DNS _servers_ of various flavors, not for middleboxes.   This seems explicit to me in the text; I can understand how you could be confused if the section on middleboxes were not present, but since it is, it doesn't make sense to prefer the other text for your use case.

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext