Re: [dnsext] Slamming the TCP door, was Re: Fwd: New Version Notification for draft-ah-dnsext-rfc1995bis-ixfr-02

Edward Lewis <Ed.Lewis@neustar.biz> Mon, 20 June 2011 12:35 UTC

Return-Path: <Ed.Lewis@neustar.biz>
X-Original-To: dnsext@ietfa.amsl.com
Delivered-To: dnsext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BC26711E8169 for <dnsext@ietfa.amsl.com>; Mon, 20 Jun 2011 05:35:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.136
X-Spam-Level:
X-Spam-Status: No, score=-106.136 tagged_above=-999 required=5 tests=[AWL=0.463, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DTtHB4m3tEFe for <dnsext@ietfa.amsl.com>; Mon, 20 Jun 2011 05:35:13 -0700 (PDT)
Received: from stora.ogud.com (stora.ogud.com [66.92.146.20]) by ietfa.amsl.com (Postfix) with ESMTP id 0BE1611E8168 for <dnsext@ietf.org>; Mon, 20 Jun 2011 05:35:12 -0700 (PDT)
Received: from bsul-lt500.cis.neustar.com (nyttbox.md.ogud.com [10.20.30.4]) by stora.ogud.com (8.14.4/8.14.4) with ESMTP id p5KCZ5WH025352; Mon, 20 Jun 2011 08:35:11 -0400 (EDT) (envelope-from Ed.Lewis@neustar.biz)
Received: from [192.168.128.30] by bsul-lt500.cis.neustar.com (PGP Universal service); Mon, 20 Jun 2011 08:35:12 -0400
X-PGP-Universal: processed; by bsul-lt500.cis.neustar.com on Mon, 20 Jun 2011 08:35:12 -0400
Mime-Version: 1.0
Message-Id: <a06240801ca24edde2b90@[192.168.1.104]>
In-Reply-To: <1308572047.2742.37.camel@shane-desktop>
References: <4DB81069.3080404@nic.cz> <4DF9B5BD.7010900@nic.cz> <a06240803ca1fd7525c50@10.31.201.23> <BANLkTinjRDHyKH-tLEoejodXb2+7qQLO7w@mail.gmail.com> <a06240801ca2102b8b4f2@10.31.201.23> <BANLkTikoVVaXF2_LJ3KHm6P7oFpfC+n2tw@mail.gmail.com> <a06240801ca21246f76de@10.31.201.23> <BANLkTinVfuL0WEYwaycTaAnWDS9vYF5NjQ@mail.gmail.com> <4DFEFBDE.4030303@nlnetlabs.nl> <1308572047.2742.37.camel@shane-desktop>
Date: Mon, 20 Jun 2011 08:35:01 -0400
To: dnsext@ietf.org
From: Edward Lewis <Ed.Lewis@neustar.biz>
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-Scanned-By: MIMEDefang 2.68 on 10.20.30.4
Cc: ed.lewis@neustar.biz
Subject: Re: [dnsext] Slamming the TCP door, was Re: Fwd: New Version Notification for draft-ah-dnsext-rfc1995bis-ixfr-02
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Jun 2011 12:35:13 -0000

At 14:14 +0200 6/20/11, Shane Kerr wrote:

>While you will not get the entire zone, you'll likely still get a lot of
>extra data. Your operating system will be happily filling its TCP buffer
>until your application notices that it is getting a AXFR-style transfer
>and then closes the connection.

I really think there's a misunderstanding of the AXFR-style IXFR.

Even if IXFR is on TCP, it's the same protocol that runs over UDP.  I 
once tried to write up an AXFR over UDP and in writing the draft 
learned that AXFR is fundamentally unable to run over UDP.  AXFR and 
IXFR responses are different.  You don't get an AXFR response from an 
IXFR query.

If you have an open TCP connection and see a IXFR query lead to an 
AXFR response, you have to see an IXFR response and AXFR query in 
there too - and also an SOA query/response.  Of else something was 
mis-reporting the AXFR-style IXFR.  Or maybe the IXFR server was 
buggy.

-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Edward Lewis
NeuStar                    You can leave a voice message at +1-571-434-5468

I'm overly entertained.