[DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147 ) to Internet Standard

"[email protected]" <[email protected]> Mon, 13 Apr 2026 15:54:34 +0200
Newsgroups gmane.ietf.dnsop,gmane.ietf.v6ops
Message-ID <[email protected]>
We did a lot of testing of many possible scenarios in real 464XLAT deployments.

After many years in some of the, we keep collecting information from possible customers complains in case we need to avoid doing synthesis at the DNS64 servers for specific destinations.

It never happened. So that’s what I call real would experience. As said several times, will love to hear from others if they are having this problem and “how much”.


> El 13 abr 2026, a las 15:45, Philip Homburg <[email protected]> escribió:
> 
>>> IPv6 and DNSSEC are independent technologies. We cannot assume that one
>>> implies the other.
>> 
>> And do you have real experience of deployments breaking it? I will
>> love to see those cases.
> 
> You never installed a DNSSEC validating proxy on a laptop without CLAT?
> 
>> I think the point is to understand that DNSSEC with DNS64 is broken
>> only in a very very very small % of situation, which can also be
>> resolved.
> 
> The problem with DNS64 is that it seems to work (to some extent at least)
> without CLAT. But as soon as you install a DNSSEC validating proxy,
> or some other DNSSEC validation, access to IPv4 is lost.
> 
> The same thing is of course true for a DNS proxy that connects to a 
> public resolver over DoH or DoT.
> 
> That means that devices that rely on DNS64 make it is a lot harder to
> deploy those technologies.
> 


**********************************************
IPv4 is over
Are you ready for the new Internet ?
http://www.theipv6company.com
The IPv6 Company

This electronic message contains information which may be privileged or confidential. The information is intended to be for the exclusive use of the individual(s) named above and further non-explicilty authorized disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited and will be considered a criminal offense. If you are not the intended recipient be aware that any disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited, will be considered a criminal offense, so you must reply to the original sender to inform about this communication and delete it.



_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]