better if dnsmasq just implemented https://tools.ietf.org/html/draft-vixie-dnsext-dns0x20-00 which alas, has never become an RFC, AFAIK.
Alternatively, DNSSEC was designed to deal with the entire gamut of DNS cache poisioning. More fiddling with ICMP source ports is not going to help in the long run. -- Michael Richardson <mcr+i...@sandelman.ca> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide
signature.asc
Description: PGP signature
_______________________________________________ openwrt-devel mailing list openwrt-devel@lists.openwrt.org https://lists.openwrt.org/mailman/listinfo/openwrt-devel