>This is true.  Including the Client IP in constructing the Client Cookie
>was intended to deal with this, but this operation is impractical with
>UDP; expensive at best and not suitable for high volume recursive to
>authoritative traffic.
>
>We could recommend it for stub to recursive traffic, for which the high
>volume performance requirements are less of an issue... what do you think?

Maybe high volume should be the exception.

I think it is better to specify that all code should include the Client IP
unless explicitly configured to leave it out.

A bit of testing suggests that a naive way of getting the Client IP takes 
about 2 microseconds on modern hardware. So a bit of caching on high 
performance resolvers would be enough.


_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to