Re: Syntax for ECS ACL Entry

2021-09-02 Thread Ondřej Surý
FTR The PROXY protocol is on the todo list, but the demand hasn’t been great so it’s more in the “patches accepted” area then something that’s just around the corner… -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply o

Re: Syntax for ECS ACL Entry

2021-09-02 Thread Ryan McGuire
In this case I use dnsdist (by PowerDNS) for load balancing and failover -- requests are balanced between my internal bind9 servers, and if they are all down queries go to public DNS directly to avoid a total outage. The challenge here is that the source IP for all requests is now coming from d

Re: Syntax for ECS ACL Entry

2021-09-02 Thread Evan Hunt
On Thu, Sep 02, 2021 at 02:26:59PM -0400, Ryan McGuire wrote: > Thank you, in my searching I failed to come across that. > > Do you know if it's been replaced by something more "practical to > deploy"? I found some discussion regarding support for "The PROXY > Protocol" (https://www.haproxy.org/

Re: Syntax for ECS ACL Entry

2021-09-02 Thread Ryan McGuire
Thank you, in my searching I failed to come across that. Do you know if it's been replaced by something more "practical to deploy"? I found some discussion regarding support for "The PROXY Protocol" (https://www.haproxy.org/download/2.2/doc/proxy-protocol.txt) but I don't believe it's planned.

Re: Syntax for ECS ACL Entry

2021-09-02 Thread Evan Hunt
> I did compile 9.16.20 from source since the latest in Debian repos is > 9.16.15 but the result is the same. The doc snippet in my original email > was from 9.11 docs -- could this feature not have been brought forward > into 9.16 at all? The only related documented removed feature is > geoi

Re: Syntax for ECS ACL Entry

2021-09-02 Thread Ryan McGuire
I did compile 9.16.20 from source since the latest in Debian repos is 9.16.15 but the result is the same. The doc snippet in my original email was from 9.11 docs -- could this feature not have been brought forward into 9.16 at all? The only related documented removed feature is geoip-use-ecs.