Re: [v6ops] Scope of Unique Local IPv6 Unicast Addresses (Fwd: New Version Notification for draft-gont-6man-ipv6-ula-scope-00.txt)

Ted Lemon <> Wed, 06 January 2021 18:09 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 782373A10DA for <>; Wed, 6 Jan 2021 10:09:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (2048-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id Gq8EYBjJkKeb for <>; Wed, 6 Jan 2021 10:09:03 -0800 (PST)
Received: from ( [IPv6:2607:f8b0:4864:20::834]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 5DFB33A0EE5 for <>; Wed, 6 Jan 2021 10:09:03 -0800 (PST)
Received: by with SMTP id a6so2618994qtw.6 for <>; Wed, 06 Jan 2021 10:09:03 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=lI1K76zbEooCB95VgnJbDrPuqokTja1trr1xk39pa1s=; b=QnivyyyFbBGERu1GRNI3VNflNZXxtGnBZcQhHzEFUwsAu2lV7TJRpquD10JIrRyj5I KDCpSignmzDYEhMmqKK1aniXtngFa2j00zA/cYtikBIIynAgIOFygeGv1nqKbJsB9/sN 2J/4J6WSXPQPo/sFPoqt7V88A9aBhy/tXAzezHVeKyV3BBt+8wN+PrJ46yinEuRxCD9r adconG4kStQF7se7THxvNnuKBOZucTF0VxUsAGtbnuSsa3+zAlRmbhf0aKXpcoyBxK6o Fn2I9Yrj2MpA4lrcQ0spNu4x75m81WjUoKQlo4EJm346cecYCfdpjLpKj16OfwD5TqBt lFyQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=lI1K76zbEooCB95VgnJbDrPuqokTja1trr1xk39pa1s=; b=MJSZAOGOZ9P3CKS3zhHg+O4AdPWq/VlNXxb2MFWqPIPfZshVWawma52T/GpnNKCwj/ mJzqAsE3bXkIEsJuw+SULqH3OxAEa82wihJznKBFg6BAL8Ybtc1dlssMaTCBEvoZMYzz FYMHlYEiiWFH0lTWijYjw+/lD28k6bE7/QpqKBa/voR+0Up8SRYhDwLchf1xtE4nZBt7 j75yfZ6BDXHMy70oIJdTZmTMEV3h6kn4Kpv6HAcV2MQFMdwmr+0x8MSBQ38EMh1ruyKr ZV/x/IYG+F5teVvYMwSDWZkKn0DdiCI719zSJ5nvQw2etU2G5tc0hbJSoMwCoBI0GmHr kDOg==
X-Gm-Message-State: AOAM5334iEJKeFFQcIEJooBmfL2UPKcMkaOz/4Nby6GRcD0vGoZbR11R sin68ggMwNnbhoF7VDzDaI8a1Q==
X-Google-Smtp-Source: ABdhPJwUR9nH81OHF6GjmKiSG7V4owprwzPWlVhI90JlwEgm0OMlTB12U4gy5rrkwArcs2lKJqjavg==
X-Received: by 2002:ac8:5a90:: with SMTP id c16mr5070025qtc.331.1609956542471; Wed, 06 Jan 2021 10:09:02 -0800 (PST)
Received: from mithrandir.lan ( []) by with ESMTPSA id q32sm1591342qtb.0.2021. (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 06 Jan 2021 10:09:01 -0800 (PST)
From: Ted Lemon <>
Message-Id: <>
Content-Type: multipart/alternative; boundary="Apple-Mail=_47C06E68-CF31-4E53-A189-1212BBB9B1C3"
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.\))
Subject: Re: [v6ops] Scope of Unique Local IPv6 Unicast Addresses (Fwd: New Version Notification for draft-gont-6man-ipv6-ula-scope-00.txt)
Date: Wed, 6 Jan 2021 13:08:59 -0500
In-Reply-To: <13054.1609955471@localhost>
Cc: Fernando Gont <>, IPv6 Operations <>,, Gert Doering <>
To: Michael Richardson <>
References: <> <> <> <> <> <> <20210106162652.GX13005@Space.Net> <> <1169.1609953092@localhost> <> <13054.1609955471@localhost>
X-Mailer: Apple Mail (2.3654.
Archived-At: <>
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 06 Jan 2021 18:09:06 -0000

On Jan 6, 2021, at 12:51 PM, Michael Richardson <> wrote:
> But... caching and outsourcing of DNS servers and outsourcing of DNS resolvers.
> I hate all of that: except for simpler (IoT) devices, which should always use
> local DNS server to get local policy,  all this policy should be in the
> client, not the server.

Okay, if that’s possible, sure, but the way to do that sort of policy would be to say what server to contact for what domain. The VPN example is just one example; you could certainly also do this without a VPN. It’s pretty easy to do on the Mac—just add a scoped DNS resolver; not sure how hard it is on Linux.

The thing is, though, that somebody has to provide the intelligence to decide either who to ask or what address to use. I think that by default you should never see a ULA other than from the local resolver, because there’s just no way for someone who _doesn’t_ know that ULA to know whether it would work or not. So if there are some domains that you want treated specially, the easiest way to do that is to have a different resolver for those domains (a scoped resolver).