User Tools

Site Tools


infoblox_nios:ecs

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
infoblox_nios:ecs [2024/12/21 13:27] bstaffordinfoblox_nios:ecs [2025/02/21 09:03] (current) – [NIOS-X] bstafford
Line 12: Line 12:
  
 IPv4 Source Prefix: 16 - This is configuration but (for example) a value of 16 means that when we receive a query with ECS, if the query has a more specific subnet (e.g. /24) then the subnet will be rounded up to the value of this source prefix when forwarding to the next server. i.e. if you query NIOS with +subnet=10.10.10.0/24, then when NIOS forwards to the next NIOS and ECS is copied over (i.e. the domain is in the "Query Zone Permission" list) and forwarded to the next server (or root, etc), then the value of the ECS field will be changed from 10.10.10.0/24 to 10.10.0.0/16. IPv4 Source Prefix: 16 - This is configuration but (for example) a value of 16 means that when we receive a query with ECS, if the query has a more specific subnet (e.g. /24) then the subnet will be rounded up to the value of this source prefix when forwarding to the next server. i.e. if you query NIOS with +subnet=10.10.10.0/24, then when NIOS forwards to the next NIOS and ECS is copied over (i.e. the domain is in the "Query Zone Permission" list) and forwarded to the next server (or root, etc), then the value of the ECS field will be changed from 10.10.10.0/24 to 10.10.0.0/16.
 +===== NIOS-X =====
 +If a client queries NIOS-X and the NIOS-X server has ECS0 enabled, then DTC further up the chain get the ECS subnet. If the DNS query hitting the NIOS-X server already has ECS0 data, that data is copied over to the server that the NIOS-X forwards the queries to.
 +
 +==== DFP =====
 +DFP by itself will not ADD EDNS0 but it will COPY EDNS0 if present.
 +===== DTC =====
 +When using DTC, if you want DTC to consider EDNS0 option, select "When DNS Traffic Control is enabled, direct traffic according to EDNS0 Client Subnet when possible" from Grid Properties > Traffic Control.
 +
 +Note: DTC takes no notice of the Add/Copy source IP feature.
infoblox_nios/ecs.1734787679.txt.gz · Last modified: by bstafford