{"id":95716,"date":"2020-10-02T01:42:50","date_gmt":"2020-10-01T23:42:50","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/inicziativa-dns-flag-day-2020-dlya-resheniya-problem-s-fragmentacziej-i-podderzhkoj-tcp"},"modified":"2020-10-02T01:42:50","modified_gmt":"2020-10-01T23:42:50","slug":"inicziativa-dns-flag-day-2020-dlya-resheniya-problem-s-fragmentacziej-i-podderzhkoj-tcp","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/inicziativa-dns-flag-day-2020-dlya-resheniya-problem-s-fragmentacziej-i-podderzhkoj-tcp","title":{"rendered":"The DNS flag day 2020 initiative to address issues related to fragmentation and TCP support","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Today, a number of major DNS services and DNS server manufacturers will hold a joint event. <noindex><a rel=\"nofollow\" href=\"https:\/\/dnsflagday.net\/2020\/\">DNS flag day 2020<\/a><\/noindex>, aimed at focusing attention on <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/draft-bonica-intarea-frag-fragile-03\">addressing<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.potaroo.net\/ispcol\/2017-08\/xtn-hdrs.html\">issues<\/a><\/noindex> with IP fragmentation when processing large DNS messages. This is the second such event, following last year\u2019s \"DNS flag day\" <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49999\">focused<\/a><\/noindex> on the correct processing of EDNS requests. <\/p>\n<p>Participants in the DNS flag day 2020 initiative urge to set recommended buffer sizes for EDNS to values at the level of 1232 bytes (MTU size 1280 minus 48 bytes for headers), as well as  <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/dns-violations\/dnsflagday\/issues\/89\">the processing of requests over TCP will be transitioned to mandatory support on servers. Currently, processing requests over UDP is mandatory, while TCP is desirable but not obligatory for operation (the standard prescribes the option to disable TCP). It is proposed to remove the option to disable TCP from the standard and to standardize the transition from sending requests over UDP to using TCP in cases where the established EDNS buffer size is insufficient.<\/a><\/noindex> requiring TCP request processing to be supported on servers. In <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc1035\">RFC 1035<\/a><\/noindex>  mandatory support is only marked for UDP request handling, while TCP is indicated as desired but not required for functionality. New <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc7766\">RFC 7766<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc5966\">RFC 5966<\/a><\/noindex> explicitly classify TCP as one of the essential capabilities necessary for the correct functioning of DNS. As part of the ongoing initiative, it is proposed to enforce the transition from sending requests over UDP to using TCP in cases where the set EDNS buffer size is insufficient.<\/p>\n<p>The proposed changes will eliminate confusion regarding EDNS buffer size selection and address the problem of fragmenting large UDP messages, which often leads to packet loss and timeouts on the client side. On the client side, the EDNS buffer size will be constant, and large responses will be sent to the client over TCP immediately. The exclusion of sending large messages over UDP will also resolve issues with the dropping of large packets on certain firewalls and allow for blocking. <noindex><a rel=\"nofollow\" href=\"https:\/\/indico.dns-oarc.net\/event\/31\/contributions\/692\/attachments\/660\/1115\/fujiwara-5.pdf\">attacks<\/a><\/noindex> of DNS cache poisoning, based on manipulating fragmented UDP packets (when fragmented, the second fragment does not include the header with the identifier, so it can be forged as long as the checksum matches).<\/p>\n<p>Starting today, participating DNS providers, including CloudFlare, Quad 9, Cisco (OpenDNS), and Google, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/dns-violations\/dnsflagday\/issues\/139#issuecomment-673489183\">will gradually change<\/a><\/noindex> the EDNS buffer size from 4096 to 1232 bytes on their DNS servers (the EDNS change will be spread over 4-6 weeks and will eventually cover an increasing number of requests). Responses to UDP requests that exceed the new limit will be sent via TCP. DNS server manufacturers, including BIND, Unbound, Knot, NSD, and PowerDNS, will release updates changing the default EDNS buffer size from 4096 to 1232 bytes. <\/p>\n<p>Ultimately, the introduced changes may lead to resolution issues when accessing DNS servers whose DNS responses over UDP exceed 1232 bytes and cannot send a response over TCP. An experiment conducted by Google showed that changing the EDNS buffer size has little effect on failure rates \u2014 with a buffer of 4096 bytes, the number of truncated UDP queries is 0.345%, and the number of unreachable TCP responses is 0.115%. With a buffer of 1232 bytes, these rates are 0.367% and 0.116%. Making TCP support mandatory for DNS features will cause issues interacting with about 0.1% of DNS servers. It is noted that under current conditions, the operation of those servers without TCP is inherently unstable.<\/p>\n<p>Administrators of authoritative DNS servers should ensure their server responds over TCP on network port 53 and that this TCP port is not blocked by a firewall. An authoritative DNS server should also not send UDP responses exceeding<br \/>\nthe requested size of the EDNS buffer. The buffer size on the server itself should be set to 1232 bytes. Resolvers are subject to roughly the same requirements \u2014 mandatory capability for TCP responses, mandatory support for resending queries over TCP when receiving truncated UDP responses, and setting the EDNS buffer to 1232 bytes.<\/p>\n<p>The following parameters are responsible for configuring the EDNS buffer size across different DNS servers:<\/p>\n<li class=\"l\"> BIND\n<p>    options {<br \/>\n      edns-udp-size 1232;<br \/>\n      max-udp-size 1232;<br \/>\n    };<\/p>\n<li class=\"l\"> Knot DNS\n<p>      max-udp-payload: 1232<\/p>\n<li class=\"l\"> Knot Resolver\n<p>    net.bufsize(1232)<\/p>\n<li class=\"l\"> PowerDNS Authoritative\n<p>    udp-truncation-threshold=1232<\/p>\n<li class=\"l\"> PowerDNS Recursor\n<p>    edns-outgoing-bufsize=1232<br \/>\n    udp-truncation-threshold=1232<\/p>\n<li class=\"l\"> Unbound\n<p>      edns-buffer-size: 1232<\/p>\n<li class=\"l\"> NSD\n<p>      ipv4-edns-size: 1232<br \/>\n      ipv6-edns-size: 1232<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53816\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u0440\u044f\u0434 \u043a\u0440\u0443\u043f\u043d\u044b\u0445 DNS-\u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u0439 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043f\u0440\u043e\u0432\u0435\u0434\u0443\u0442 \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e\u0435 \u043c\u0435\u0440\u043e\u043f\u0440\u0438\u044f\u0442\u0438\u0435 DNS flag day 2020, \u043f\u0440\u0438\u0437\u0432\u0430\u043d\u043d\u043e\u0435 \u0441\u0444\u043e\u043a\u0443\u0441\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0440\u0435\u0448\u0435\u043d\u0438\u0438 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0441 IP-\u0444\u0440\u0430\u0433\u043c\u0435\u043d\u0442\u0430\u0446\u0438\u0435\u0439 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 DNS-\u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u0439 \u0431\u043e\u043b\u044c\u0448\u043e\u0433\u043e \u0440\u0430\u0437\u043c\u0435\u0440\u0430. \u042d\u0442\u043e \u0432\u0442\u043e\u0440\u043e\u0435 \u043f\u043e\u0434\u043e\u0431\u043d\u043e\u0435 \u043c\u0435\u0440\u043e\u043f\u0440\u0438\u044f\u0442\u0438\u0435, \u0432 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u0433\u043e\u0434\u0443 &#171;DNS flag day&#187; \u0431\u044b\u043b \u0441\u043e\u0441\u0440\u0435\u0434\u043e\u0442\u043e\u0447\u0435\u043d \u043d\u0430 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 EDNS. \u0423\u0447\u0430\u0441\u0442\u043d\u0438\u043a\u0438 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u044b DNS flag day 2020 \u043f\u0440\u0438\u0437\u044b\u0432\u0430\u044e\u0442 \u0437\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u0440\u0430\u0437\u043c\u0435\u0440\u044b \u0431\u0443\u0444\u0435\u0440\u043e\u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-95716","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u0440\u044f\u0434 \u043a\u0440\u0443\u043f\u043d\u044b\u0445 DNS-\u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u0439 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043f\u0440\u043e\u0432\u0435\u0434\u0443\u0442 \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e\u0435 \u043c\u0435\u0440\u043e\u043f\u0440\u0438\u044f\u0442\u0438\u0435 DNS flag day 2020, \u043f\u0440\u0438\u0437\u0432\u0430\u043d\u043d\u043e\u0435 \u0441\u0444\u043e\u043a\u0443\u0441\u0438\u0440\u043e\u0432\u0430\u0442\u044c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/inicziativa-dns-flag-day-2020-dlya-resheniya-problem-s-fragmentacziej-i-podderzhkoj-tcp\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0418\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u0430 DNS flag day 2020 \u0434\u043b\u044f \u0440\u0435\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0441 \u0444\u0440\u0430\u0433\u043c\u0435\u043d\u0442\u0430\u0446\u0438\u0435\u0439 \u0438 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u043e\u0439 TCP | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u0440\u044f\u0434 \u043a\u0440\u0443\u043f\u043d\u044b\u0445 DNS-\u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u0439 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043f\u0440\u043e\u0432\u0435\u0434\u0443\u0442 \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e\u0435 \u043c\u0435\u0440\u043e\u043f\u0440\u0438\u044f\u0442\u0438\u0435 DNS flag day 2020, \u043f\u0440\u0438\u0437\u0432\u0430\u043d\u043d\u043e\u0435 \u0441\u0444\u043e\u043a\u0443\u0441\u0438\u0440\u043e\u0432\u0430\u0442\u044c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/inicziativa-dns-flag-day-2020-dlya-resheniya-problem-s-fragmentacziej-i-podderzhkoj-tcp\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-10-01T23:42:50+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-10-01T23:42:50+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47The DNS flag day 2020 initiative to address issues with fragmentation and TCP support | ProHoster","description":"Today, several major DNS services and DNS server manufacturers will hold a joint event, DNS flag day 2020, aimed at focusing on.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/inicziativa-dns-flag-day-2020-dlya-resheniya-problem-s-fragmentacziej-i-podderzhkoj-tcp","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0418\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u0430 DNS flag day 2020 \u0434\u043b\u044f \u0440\u0435\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0441 \u0444\u0440\u0430\u0433\u043c\u0435\u043d\u0442\u0430\u0446\u0438\u0435\u0439 \u0438 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u043e\u0439 TCP | ProHoster","og:description":"\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u0440\u044f\u0434 \u043a\u0440\u0443\u043f\u043d\u044b\u0445 DNS-\u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u0439 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043f\u0440\u043e\u0432\u0435\u0434\u0443\u0442 \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e\u0435 \u043c\u0435\u0440\u043e\u043f\u0440\u0438\u044f\u0442\u0438\u0435 DNS flag day 2020, \u043f\u0440\u0438\u0437\u0432\u0430\u043d\u043d\u043e\u0435 \u0441\u0444\u043e\u043a\u0443\u0441\u0438\u0440\u043e\u0432\u0430\u0442\u044c.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/inicziativa-dns-flag-day-2020-dlya-resheniya-problem-s-fragmentacziej-i-podderzhkoj-tcp","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-10-01T23:42:50+00:00","article:modified_time":"2020-10-01T23:42:50+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"95716","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 10:59:41","updated":"2022-10-02 16:18:32","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/95716","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=95716"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/95716\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=95716"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=95716"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=95716"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}