ืฉื—ืจื•ืจ ืฉืœ PowerDNS Recursor 4.2 ื•ื™ื•ื–ืžืช ื”ื“ื’ืœ ืฉืœ DNS 2020

ืœืื—ืจ ืฉื ื” ื•ื—ืฆื™ ืฉืœ ืคื™ืชื•ื— ื”ืฆื™ื’ ืฉื—ืจื•ืจ ืฉืจืช DNS ืœืื—ืกื•ืŸ ื‘ืžื˜ืžื•ืŸ ืžืฉืื‘ PowerDNS 4.2, ืื—ืจืื™ ืœื”ืžืจืช ืฉืžื•ืช ืจืงื•ืจืกื™ื‘ื™ืช. PowerDNS Recursor ื‘ื ื•ื™ ืขืœ ืื•ืชื• ื‘ืกื™ืก ืงื•ื“ ื›ืžื• PowerDNS Authoritative Server, ืืš ืฉืจืชื™ DNS ืจืงื•ืจืกื™ื‘ื™ื™ื ื•ืกืžื›ื•ืชื™ื™ื ืฉืœ PowerDNS ืžืคื•ืชื—ื™ื ื‘ืืžืฆืขื•ืช ืžื—ื–ื•ืจื™ ืคื™ืชื•ื— ืฉื•ื ื™ื ื•ืžืฉื•ื—ืจืจื™ื ื›ืžื•ืฆืจื™ื ื ืคืจื“ื™ื. ืงื•ื“ ืคืจื•ื™ืงื˜ ืžื•ืคืฅ ืขืœ ื™ื“ื™ ืžื•ืจืฉื” ืชื—ืช GPLv2.

ื”ื’ืจืกื” ื”ื—ื“ืฉื” ืžื‘ื˜ืœืช ืืช ื›ืœ ื”ื‘ืขื™ื•ืช ื”ืงืฉื•ืจื•ืช ืœืขื™ื‘ื•ื“ ืžื ื•ืช DNS ืขื ื“ื’ืœื™ EDNS. ื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ืฉืœ PowerDNS Recursor ืœืคื ื™ 2016 ื ื”ื’ื• ืœื”ืชืขืœื ืžื—ื‘ื™ืœื•ืช ืขื ื“ื’ืœื™ EDNS ืฉืื™ื ื ื ืชืžื›ื™ื ืžื‘ืœื™ ืœืฉืœื•ื— ืชื’ื•ื‘ื” ื‘ืคื•ืจืžื˜ ื”ื™ืฉืŸ, ื•ืœื‘ื˜ืœ ืืช ื“ื’ืœื™ ื”-EDNS ื›ื ื“ืจืฉ ืขืœ ืคื™ ื”ืžืคืจื˜. ื‘ืขื‘ืจ, ื”ืชื ื”ื’ื•ืช ืœื ืกื˜ื ื“ืจื˜ื™ืช ื–ื• ื ืชืžื›ื” ื‘-BIND ื‘ืฆื•ืจื” ืฉืœ ืคืชืจื•ืŸ ืขื•ืงืฃ, ืืš ื‘ืžืกื’ืจืช ื‘ื•ืฆืข ื‘ื™ื•ื–ืžื•ืช ืคื‘ืจื•ืืจ ื™ื•ื ื“ื’ืœ DNS, ืžืคืชื—ื™ ืฉืจืชื™ DNS ื”ื—ืœื™ื˜ื• ืœื ื˜ื•ืฉ ืืช ื”ืคืจื™ืฆื” ื”ื–ื•.

ื‘-PowerDNS, ื”ื‘ืขื™ื•ืช ื”ืขื™ืงืจื™ื•ืช ื‘ืขื™ื‘ื•ื“ ืžื ื•ืช ืขื EDNS ื‘ื•ื˜ืœื• ืขื•ื“ ื‘-2017 ื‘ืžื”ื“ื•ืจื” 4.1, ื•ื‘ืขื ืฃ 2016 ืฉืฉื•ื—ืจืจ ื‘-4.0, ืฆืฆื• ืื™-ื”ืชืืžื” ืื™ื ื“ื™ื‘ื™ื“ื•ืืœื™ืช ื”ืžืชืขื•ืจืจืช ื‘ื ืกื™ื‘ื•ืช ืžืกื•ื™ืžื•ืช, ื•ื‘ืื•ืคืŸ ื›ืœืœื™, ืื™ื ืŸ ืžืคืจื™ืขื•ืช ืœื ื•ืจืžืœื™ื•ืช. ืžื‘ืฆืข. ื‘-PowerDNS Recursor 4.2, ื›ืžื• ื‘ ื›ืจื™ื›ื” 9.14, ื”ื•ืกืจื• ื“ืจื›ื™ื ืœืขืงื™ืคืช ื”ื‘ืขื™ื” ื›ื“ื™ ืœืชืžื•ืš ื‘ืฉืจืชื™ื ืกืžื›ื•ืชื™ื™ื ื”ืžื’ื™ื‘ื™ื ื‘ืื•ืคืŸ ืฉื’ื•ื™ ืœื‘ืงืฉื•ืช ืขื ื“ื’ืœื™ EDNS. ืขื“ ื›ื”, ืื ืœืื—ืจ ืฉืœื™ื—ืช ื‘ืงืฉื” ืขื ื“ื’ืœื™ EDNS ืœื ื”ื™ื™ืชื” ืžืขื ื” ืœืื—ืจ ืคืจืง ื–ืžืŸ ืžืกื•ื™ื, ืฉืจืช ื”-DNS ื”ื ื™ื— ืฉื“ื’ืœื™ื ืžื•ืจื—ื‘ื™ื ืื™ื ื ื ืชืžื›ื™ื ื•ืฉืœื— ื‘ืงืฉื” ืฉื ื™ื™ื” ืœืœื ื“ื’ืœื™ EDNS. ื”ืชื ื”ื’ื•ืช ื–ื• ื”ื•ืฉื‘ืชื” ื›ืขืช ืžื›ื™ื•ื•ืŸ ืฉืงื•ื“ ื–ื” ื”ื‘ื™ื ืœื”ืฉื”ื™ื™ื” ืžื•ื’ื‘ืจืช ืขืงื‘ ืฉื™ื“ื•ืจื™ื ื—ื•ื–ืจื™ื ืฉืœ ืžื ื•ืช, ืขื•ืžืก ืจืฉืช ืžื•ื’ื‘ืจ ื•ืื™ ื‘ื”ื™ืจื•ืช ื›ืืฉืจ ืœื ืžื’ื™ื‘ื™ื ืขืงื‘ ื›ืฉืœื™ื ื‘ืจืฉืช, ื•ืžื ืข ืืช ื”ื˜ืžืขืช ืชื›ื•ื ื•ืช ืžื‘ื•ืกืกื•ืช EDNS ื›ื’ื•ืŸ DNS Cookies ื›ื“ื™ ืœื”ื’ืŸ ืžืคื ื™ ื”ืชืงืคื•ืช DDoS.

ื”ื•ื—ืœื˜ ืœืงื™ื™ื ืืช ื”ืื™ืจื•ืข ื‘ืฉื ื” ื”ื‘ืื” ื™ื•ื ื”ื“ื’ืœ ืฉืœ DNS 2020ืฉื ื•ืขื“ ืœืžืงื“ ืืช ืชืฉื•ืžืช ื”ืœื‘ ื”ื”ื—ืœื˜ื” ะฟั€ะพะฑะปะตะผ ืขื ืคื™ืฆื•ืœ IP ื‘ืขืช ืขื™ื‘ื•ื“ ื”ื•ื“ืขื•ืช DNS ื’ื“ื•ืœื•ืช. ื‘ืžืกื’ืจืช ื”ื™ื•ื–ืžื” ืžืชื•ื›ื ืŸ ืชืงืŸ ืืช ื’ื“ืœื™ ื”ืžืื’ืจ ื”ืžื•ืžืœืฆื™ื ืขื‘ื•ืจ EDNS ืœ-1200 ื‘ืชื™ื, ื•ื›ืŸ ืœืชืจื’ื ืขื™ื‘ื•ื“ ื‘ืงืฉื•ืช ื‘ืืžืฆืขื•ืช TCP ื”ื•ื ืชื›ื•ื ื” ื—ื•ื‘ื” ื‘ืฉืจืชื™ื. ื›ืขืช ื ื“ืจืฉืช ืชืžื™ื›ื” ื‘ืขื™ื‘ื•ื“ ื‘ืงืฉื•ืช ื‘ืืžืฆืขื•ืช UDP, ื•-TCP ืจืฆื•ื™, ืืš ืื™ื ื• ื ื“ืจืฉ ืœืชืคืขื•ืœ (ื”ืชืงืŸ ื“ื•ืจืฉ ื™ื›ื•ืœืช ืœื‘ื˜ืœ ืืช TCP). ืžื•ืฆืข ืœื”ืกื™ืจ ืืช ื”ืืคืฉืจื•ืช ืœื ื˜ืจืœ TCP ืžื”ืชืงืŸ ื•ืœืชืงืŸ ืืช ื”ืžืขื‘ืจ ืžืฉืœื™ื—ืช ื‘ืงืฉื•ืช ื“ืจืš UDP ืœืฉื™ืžื•ืฉ ื‘-TCP ื‘ืžืงืจื™ื ื‘ื”ื ื’ื•ื“ืœ ื”ืžืื’ืจ ืฉืœ EDNS ืฉื ืงื‘ืข ืื™ื ื• ืžืกืคื™ืง.

ื”ืฉื™ื ื•ื™ื™ื ื”ืžื•ืฆืขื™ื ื‘ืžืกื’ืจืช ื”ื™ื•ื–ืžื” ื™ื‘ื˜ืœื• ืืช ื”ื‘ืœื‘ื•ืœ ื‘ื‘ื—ื™ืจืช ื’ื•ื“ืœ ื”ืžืื’ืจ ืฉืœ ื”-EDNS ื•ื™ืคืชืจื• ืืช ื‘ืขื™ื™ืช ื”ืคื™ืฆื•ืœ ืฉืœ ื”ื•ื“ืขื•ืช UDP ื’ื“ื•ืœื•ืช, ืฉืขื™ื‘ื•ื“ืŸ ืžื•ื‘ื™ืœ ืœืจื•ื‘ ืœืื•ื‘ื“ืŸ ืžื ื•ืช ื•ืคืกืงื™ ื–ืžืŸ ื‘ืฆื“ ื”ืœืงื•ื—. ื‘ืฆื“ ื”ืœืงื•ื—, ื’ื•ื“ืœ ื”ืžืื’ืจ ืฉืœ EDNS ื™ื”ื™ื” ืงื‘ื•ืข ื•ืชื’ื•ื‘ื•ืช ื’ื“ื•ืœื•ืช ื™ื™ืฉืœื—ื• ืžื™ื“ ืœืœืงื•ื— ื‘ืืžืฆืขื•ืช TCP. ื”ื™ืžื ืขื•ืช ืžืฉืœื™ื—ืช ื”ื•ื“ืขื•ืช ื’ื“ื•ืœื•ืช ื“ืจืš UDP ืชืืคืฉืจ ืœืš ื’ื ืœื—ืกื•ื ื”ืชืงืคื•ืช ืœื”ืจืขืœืช ืžื˜ืžื•ืŸ ื”-DNS, ื‘ื”ืชื‘ืกืก ืขืœ ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืžื ื•ืช UDP ืžืคื•ืฆืœื•ืช (ื›ืืฉืจ ืžืคื•ืฆืœื™ื ืœืคืจื’ืžื ื˜ื™ื, ื”ืคืจื’ืžื ื˜ ื”ืฉื ื™ ืื™ื ื• ื›ื•ืœืœ ื›ื•ืชืจืช ืขื ืžื–ื”ื”, ื›ืš ืฉื ื™ืชืŸ ืœื–ื™ื™ืฃ, ืฉืขื‘ื•ืจื• ื–ื” ืžืกืคื™ืง ืจืง ื›ื“ื™ ืฉืกื›ื•ื ื”ื‘ื“ื™ืงื” ื™ืชืื™ื) .

PowerDNS Recursor 4.2 ืœื•ืงื— ื‘ื—ืฉื‘ื•ืŸ ื‘ืขื™ื•ืช ืขื ืžื ื•ืช UDP ื’ื“ื•ืœื•ืช ื•ืขื•ื‘ืจ ืœืฉื™ืžื•ืฉ ื‘ื’ื•ื“ืœ ืžืื’ืจ EDNS (edns-outgoing-bufsize) ืฉืœ 1232 ื‘ืชื™ื, ื‘ืžืงื•ื ื”ืžื’ื‘ืœื” ืฉื ืขืฉืชื” ื‘ืขื‘ืจ ืฉืœ 1680 ื‘ืชื™ื, ืžื” ืฉืืžื•ืจ ืœื”ืคื—ื™ืช ืžืฉืžืขื•ืชื™ืช ืืช ื”ืกื‘ื™ืจื•ืช ืœืื•ื‘ื“ืŸ ืžื ื•ืช UDP . ื”ืขืจืš 1232 ื ื‘ื—ืจ ืžื›ื™ื•ื•ืŸ ืฉื”ื•ื ื”ืžืงืกื™ืžื•ื ืฉื‘ื• ื’ื•ื“ืœ ืชื’ื•ื‘ืช ื”-DNS, ื‘ื”ืชื—ืฉื‘ ื‘-IPv6, ืžืชืื™ื ืœืขืจืš ื”-MTU ื”ืžื™ื ื™ืžืœื™ (1280). ื’ื ื”ืขืจืš ืฉืœ ืคืจืžื˜ืจ ื”-triuncation-threshold, ืฉืื—ืจืื™ ืขืœ ื—ื™ืชื•ืš ื”ืชื’ื•ื‘ื•ืช ืœืœืงื•ื—, ื™ืจื“ ืœ-1232.

ืฉื™ื ื•ื™ื™ื ื ื•ืกืคื™ื ื‘-PowerDNS Recursor 4.2:

  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืžื ื’ื ื•ืŸ XPF (X-Proxied-For), ืฉื”ื™ื ื”ืžืงื‘ื™ืœื” ืœ-DNS ืฉืœ ื›ื•ืชืจืช ื”-X-Forwarded-For HTTP, ื”ืžืืคืฉืจืช ืœื”ืขื‘ื™ืจ ืžื™ื“ืข ืขืœ ื›ืชื•ื‘ืช ื”-IP ื•ืžืกืคืจ ื”ื™ืฆื™ืื” ืฉืœ ื”ืžื‘ืงืฉ ื”ืžืงื•ืจื™ ื‘ืืžืฆืขื•ืช ืคืจื•ืงืกื™ ื‘ื™ื ื™ื™ื ื•ืžืื–ื ื™ ืขื•ืžืกื™ื (ื›ื’ื•ืŸ dnsdist) . ื›ื“ื™ ืœื”ืคืขื™ืœ XPF ื™ืฉ ืืคืฉืจื•ื™ื•ืช "xpf-allow-from"ื•"xpf-rr-code";
  • ืชืžื™ื›ื” ืžืฉื•ืคืจืช ื‘ื”ืจื—ื‘ืช EDNS ืจืฉืช ืžืฉื ื” ืฉืœ ืœืงื•ื— (ECS), ื”ืžืืคืฉืจืช ืœืš ืœื”ืขื‘ื™ืจ ื‘-DNS ืฉืื™ืœืชื•ืช ืœืฉืจืช DNS ืกืžื›ื•ืชื™ ืžื™ื“ืข ืขืœ ืชืช-ื”ืจืฉืช ืฉืžืžื ื” ื”ื•ืจืขืœื” ื”ื‘ืงืฉื” ื”ืจืืฉื•ื ื™ืช ืฉืฉื•ื“ืจื” ืœืื•ืจืš ื”ืฉืจืฉืจืช (ื ืชื•ื ื™ื ืขืœ ืชืช-ื”ืจืฉืช ื”ืžืงื•ืจ ืฉืœ ื”ืœืงื•ื— ื ื—ื•ืฆื™ื ืœืคืขื™ืœื•ืช ื™ืขื™ืœื” ืฉืœ ืจืฉืชื•ืช ืืกืคืงืช ืชื•ื›ืŸ) . ื”ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื” ืžื•ืกื™ืคื” ื”ื’ื“ืจื•ืช ืœืฉืœื™ื˜ื” ืกืœืงื˜ื™ื‘ื™ืช ืขืœ ื”ืฉื™ืžื•ืฉ ื‘ืจืฉืช ื”ืžืฉื ื” ืฉืœ ืœืงื•ื— EDNS: "ecs-add-forยป ืขื ืจืฉื™ืžื” ืฉืœ ืžืกื›ื•ืช ืจืฉืช ืฉืขื‘ื•ืจืŸ ื™ืฉืžืฉ ื”-IP ื‘-ECS ื‘ื‘ืงืฉื•ืช ื™ื•ืฆืื•ืช. ืขื‘ื•ืจ ื›ืชื•ื‘ื•ืช ืฉืื™ื ืŸ ื ื›ื ืกื•ืช ืœืžืกื›ื•ืช ืฉืฆื•ื™ื ื•, ื”ื›ืชื•ื‘ืช ื”ื›ืœืœื™ืช ื”ืžืฆื•ื™ื ืช ื‘ื”ื ื—ื™ื” "ecs-scope-zero-address". ื“ืจืš ื”ื”ื ื—ื™ื”"use-incoming-edns-subnetยป ืืชื” ื™ื›ื•ืœ ืœื”ื’ื“ื™ืจ ืจืฉืชื•ืช ืžืฉื ื” ืฉืžื”ืŸ ืœื ื™ื•ื—ืœืคื• ื‘ืงืฉื•ืช ื ื›ื ืกื•ืช ืขื ืขืจื›ื™ ECS ืžืœืื™ื;
  • ืขื‘ื•ืจ ืฉืจืชื™ื ื”ืžืขื‘ื“ื™ื ืžืกืคืจ ืจื‘ ืฉืœ ื‘ืงืฉื•ืช ื‘ืฉื ื™ื™ื” (ื™ื•ืชืจ ืž-100 ืืœืฃ), ื”ื”ื ื—ื™ื” "ื—ื•ื˜ื™ ืžืคื™ืฅ", ืืฉืจ ืงื•ื‘ืข ืืช ืžืกืคืจ ื”ืฉืจืฉื•ืจื™ื ืœืงื‘ืœืช ื‘ืงืฉื•ืช ื ื›ื ืกื•ืช ื•ื”ืคืฆืชื ื‘ื™ืŸ ืฉืจืฉื•ืจื™ ืขื•ื‘ื“ื™ื (ื”ื’ื™ื•ื ื™ ืจืง ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-"pdns-distributes-queries=yes").
  • ื ื•ืกืคื” ื”ื’ื“ืจื” ืงื•ื‘ืฅ-ืกื™ื•ืžืช-ืฆื™ื‘ื•ืจ ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืื™ืชื• ืงื•ื‘ืฅ ืžืฉืœืš ืจืฉื™ืžื” ืฉืœ ืกื™ื•ืžื•ืช ืฆื™ื‘ื•ืจื™ื•ืช ื“ื•ืžื™ื™ื ื™ื ืฉื‘ื”ื ืžืฉืชืžืฉื™ื ื™ื›ื•ืœื™ื ืœืจืฉื•ื ืืช ืชืช-ื”ื“ื•ืžื™ื™ื ื™ื ืฉืœื”ื, ื‘ืžืงื•ื ื”ืจืฉื™ืžื” ื”ืžื•ื‘ื ื™ืช ื‘- PowerDNS Recursor.

ืคืจื•ื™ืงื˜ PowerDNS ื”ื›ืจื™ื– ื’ื ืขืœ ืžืขื‘ืจ ืœืžื—ื–ื•ืจ ืคื™ืชื•ื— ืฉืœ ืฉื™ืฉื” ื—ื•ื“ืฉื™ื, ื›ืืฉืจ ื”ืžื”ื“ื•ืจื” ื”ื’ื“ื•ืœื” ื”ื‘ืื” ืฉืœ PowerDNS Recursor 4.3 ืฆืคื•ื™ื” ื‘ื™ื ื•ืืจ 2020. ืขื“ื›ื•ื ื™ื ืœืžื”ื“ื•ืจื•ืช ืžืฉืžืขื•ืชื™ื•ืช ื™ืคื•ืชื—ื• ื‘ืžื”ืœืš ื”ืฉื ื”, ื•ืœืื—ืจ ืžื›ืŸ ื™ืฉื•ื—ืจืจื• ืชื™ืงื•ื ื™ ืคื’ื™ืขื•ืช ืœืžืฉืš ืฉื™ืฉื” ื—ื•ื“ืฉื™ื ื ื•ืกืคื™ื. ืœืคื™ื›ืš, ื”ืชืžื™ื›ื” ื‘ืกื ื™ืฃ PowerDNS Recursor 4.2 ืชื™ืžืฉืš ืขื“ ื™ื ื•ืืจ 2021. ืฉื™ื ื•ื™ื™ื ื“ื•ืžื™ื ื‘ืžื—ื–ื•ืจ ื”ืคื™ืชื•ื— ื ืขืฉื• ืขื‘ื•ืจ PowerDNS Authoritative Server, ืฉืฆืคื•ื™ ืœืฉื—ืจืจ ืืช 4.2 ื‘ืขืชื™ื“ ื”ืงืจื•ื‘.

ืชื›ื•ื ื•ืช ืขื™ืงืจื™ื•ืช ืฉืœ PowerDNS Recursor:

  • ื›ืœื™ื ืœืื™ืกื•ืฃ ื ืชื•ื ื™ื ืกื˜ื˜ื™ืกื˜ื™ื™ื ืžืจื—ื•ืง;
  • ื”ืคืขืœื” ืžื—ื“ืฉ ืžื™ื™ื“ื™ืช;
  • ืžื ื•ืข ืžื•ื‘ื ื” ืœื—ื™ื‘ื•ืจ ืžื˜ืคืœื™ื ื‘ืฉืคืช Lua;
  • ืชืžื™ื›ื” ืžืœืื” ื‘-DNSSEC ื• DNS64;
  • ืชืžื™ื›ื” ื‘-RPZ (Response Policy Zones) ื•ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ืจืฉื™ืžื•ืช ืฉื—ื•ืจื•ืช;
  • ืžื ื’ื ื•ื ื™ื ื ื’ื“ ื–ื™ื•ืฃ;
  • ื™ื›ื•ืœืช ืœื”ืงืœื™ื˜ ืชื•ืฆืื•ืช ืจื–ื•ืœื•ืฆื™ื” ื›ืงื‘ืฆื™ ืื–ื•ืจ BIND.
  • ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ื‘ื™ืฆื•ืขื™ื ื’ื‘ื•ื”ื™ื, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžื ื’ื ื•ื ื™ ืจื™ื‘ื•ื™ ื—ื™ื‘ื•ืจื™ื ืžื•ื“ืจื ื™ื™ื ื‘-FreeBSD, Linux ื•-Solaris (kqueue, epoll, /dev/poll), ื›ืžื• ื’ื ืžื ืชื— ืžื ื•ืช DNS ื‘ืขืœ ื‘ื™ืฆื•ืขื™ื ื’ื‘ื•ื”ื™ื ื”ืžืกื•ื’ืœ ืœืขื‘ื“ ืขืฉืจื•ืช ืืœืคื™ ื‘ืงืฉื•ืช ืžืงื‘ื™ืœื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”