infoblox_nios:ecs
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| infoblox_nios:ecs [2024/12/21 13:25] – bstafford | infoblox_nios:ecs [2025/02/21 09:03] (current) – [NIOS-X] bstafford | ||
|---|---|---|---|
| Line 5: | Line 5: | ||
| By default, when ECS queries come into NIOS, NIOS will strip the ECS data when forwarding. To keep the ECS data when forwarding on a domain-by-domain basis, add the domain to the "Query Zone Permissions" | By default, when ECS queries come into NIOS, NIOS will strip the ECS data when forwarding. To keep the ECS data when forwarding on a domain-by-domain basis, add the domain to the "Query Zone Permissions" | ||
| - | If you include +subnet=10.10.10.0/ | + | If you include +subnet=10.10.10.0/ |
| If you include +subnet=10.10.10.0/ | If you include +subnet=10.10.10.0/ | ||
| Line 12: | Line 12: | ||
| IPv4 Source Prefix: 16 - This is configuration but (for example) a value of 16 means that when we receive a query with ECS, if the query has a more specific subnet (e.g. /24) then the subnet will be rounded up to the value of this source prefix when forwarding to the next server. i.e. if you query NIOS with +subnet=10.10.10.0/ | IPv4 Source Prefix: 16 - This is configuration but (for example) a value of 16 means that when we receive a query with ECS, if the query has a more specific subnet (e.g. /24) then the subnet will be rounded up to the value of this source prefix when forwarding to the next server. i.e. if you query NIOS with +subnet=10.10.10.0/ | ||
| + | ===== NIOS-X ===== | ||
| + | If a client queries NIOS-X and the NIOS-X server has ECS0 enabled, then DTC further up the chain get the ECS subnet. If the DNS query hitting the NIOS-X server already has ECS0 data, that data is copied over to the server that the NIOS-X forwards the queries to. | ||
| + | |||
| + | ==== DFP ===== | ||
| + | DFP by itself will not ADD EDNS0 but it will COPY EDNS0 if present. | ||
| + | ===== DTC ===== | ||
| + | When using DTC, if you want DTC to consider EDNS0 option, select "When DNS Traffic Control is enabled, direct traffic according to EDNS0 Client Subnet when possible" | ||
| + | |||
| + | Note: DTC takes no notice of the Add/Copy source IP feature. | ||
infoblox_nios/ecs.1734787510.txt.gz · Last modified: by bstafford
