Re: RRL outcome on legitimate traffic...

2020-12-03 Thread Reindl Harald
Am 01.12.20 um 17:15 schrieb Karl Pielorz: --On 1 December 2020 at 08:24:50 -0600 Lyle Giese wrote: You need to look at the reply named sends when it trips and starts limiting UDP traffic source from a given IP address.  It tells the requestor to try again using TCP instead of UDP. So if t

Re: RRL outcome on legitimate traffic...

2020-12-01 Thread Lyle Giese
Probably best to ask Paul Vixie for confirmation. I had implemented RRL when it was still an addon and that was what was documented back then. On 12/1/20 10:15 AM, Karl Pielorz wrote: --On 1 December 2020 at 08:24:50 -0600 Lyle Giese wrote: You need to look at the reply named sends whe

Re: RRL outcome on legitimate traffic...

2020-12-01 Thread Karl Pielorz
--On 1 December 2020 at 08:24:50 -0600 Lyle Giese wrote: You need to look at the reply named sends when it trips and starts limiting UDP traffic source from a given IP address.  It tells the requestor to try again using TCP instead of UDP. So if the requestor is a legit dns server, it will

Re: RRL outcome on legitimate traffic...

2020-12-01 Thread Lyle Giese
You need to look at the reply named sends when it trips and starts limiting UDP traffic source from a given IP address.  It tells the requestor to try again using TCP instead of UDP. So if the requestor is a legit dns server, it will retry using TCP and still get a valid answer. Named does n