XNUMX幎åã®éçºæéãçµãŠ
æ°ããããŒãžã§ã³ã§ã¯ãEDNS ãã©ã°ãæ〠DNS ãã±ããã®åŠçã«é¢é£ãããã¹ãŠã®åé¡ã解æ¶ãããŸãã 2016 幎ããåã®å€ãããŒãžã§ã³ã® PowerDNS Recursor ã§ã¯ããµããŒããããŠããªã EDNS ãã©ã°ãæã€ãã±ãããå€ã圢åŒã§å¿çãéä¿¡ããã«ç¡èŠããä»æ§ã®èŠæ±ã«åŸã£ãŠ EDNS ãã©ã°ãç Žæ£ãããšããæ
£è¡ããããŸããã以åã¯ããã®éæšæºã®åäœã¯åé¿çã®åœ¢ã§ BIND ã§ãµããŒããããŠããŸãããããã®ç¯å²å
ã§ããã
PowerDNS ã§ã¯ãEDNS ã§ãã±ãããåŠçããéã®äž»ãªåé¡ã¯ 2017 幎ã®ãªãªãŒã¹ 4.1 ã§è§£æ¶ããã2016 幎ã«ãªãªãŒã¹ããã 4.0 ãã©ã³ãã§ã¯ãç¹å®ã®ç¶æ³äžã§çºçããåå¥ã®éäºææ§ãè¡šé¢åããŸããããäžè¬çã«ã¯éåžžã®åäœã«ã¯å¹²æžããŸãããæè¡ã PowerDNS Recursor 4.2 ã§ã¯ã次ã®ããã«
æ¥å¹Žãéå¬ã決å®ããŸãã
ãã®åãçµã¿ã®äžç°ãšããŠææ¡ãããŠããå€æŽã«ãããEDNS ãããã¡ ãµã€ãºã®éžæã«é¢ããæ··ä¹±ã解æ¶ããã倧ã㪠UDP ã¡ãã»ãŒãžã®æçåã®åé¡ã解決ãããŸãããã®åé¡ã®åŠçã«ãããã¯ã©ã€ã¢ã³ãåŽã§ãã±ããæ倱ãã¿ã€ã ã¢ãŠããçºçããããšããããããŸããã¯ã©ã€ã¢ã³ãåŽã§ã¯ãEDNS ãããã¡ ãµã€ãºã¯äžå®ãšãªãã倧ããªå¿ç㯠TCP çµç±ã§ã¯ã©ã€ã¢ã³ãã«å³åº§ã«éä¿¡ãããŸãã UDP çµç±ã§å€§ããªã¡ãã»ãŒãžãéä¿¡ããªãããã«ãããšããããã¯ããããšãã§ããŸãã
PowerDNS Recursor 4.2 ã§ã¯ã倧ã㪠UDP ãã±ããã«é¢ããåé¡ãèæ ®ããã以å䜿çšãããŠãã 1232 ãã€ãã®å¶éã§ã¯ãªãã1680 ãã€ãã® EDNS ãããã¡ ãµã€ãº (edns-outcoming-bufsize) ã®äœ¿çšã«åãæ¿ãããŸããããã«ãããUDP ãã±ããã倱ãããå¯èœæ§ãå€§å¹ ã«æžå°ããŸãã ãå€ 1232 ãéžæãããã®ã¯ãIPv6 ãèæ ®ãã DNS å¿çã®ãµã€ãºãæå° MTU å€ (1280) ã«åãŸãæ倧å€ã§ããããã§ããã¯ã©ã€ã¢ã³ããžã®å¿çãããªãã³ã°ãã圹å²ãæ ã truncation-threshold ãã©ã¡ãŒã¿ã®å€ã 1232 ã«æžããããŸããã
PowerDNS Recursor 4.2 ã®ãã®ä»ã®å€æŽç¹:
- è¿œå ãããã¡ã«ããºã ã®ãµããŒã
XPF (X-Proxied-For)ãX-Forwarded-For HTTP ããããŒã«çžåœãã DNS ã§ãããå ã®ãªã¯ãšã¹ã¿ã® IP ã¢ãã¬ã¹ãšããŒãçªå·ã«é¢ããæ å ±ãäžéãããã·ãšããŒã ãã©ã³ãµ (dnsdist ãªã©) çµç±ã§è»¢éã§ããããã«ããŸãã ã XPF ãæå¹ã«ããã«ã¯ã次ã®ãªãã·ã§ã³ããããŸããxpf-èš±å¯-ãã "ãããŠ"xpf-rr-ã³ãŒã "; - EDNS æ¡åŒµæ©èœã®ãµããŒãã®æ¹å
ã¯ã©ã€ã¢ã³ããµãããã (ECS)ããã§ãŒã³ã«æ²¿ã£ãŠéä¿¡ãããæåã®ãªã¯ãšã¹ãã®éä¿¡å ã®ãµããããã«é¢ããæ å ±ããDNS ã¯ãšãªã§æš©åš DNS ãµãŒããŒã«éä¿¡ã§ããŸã (ã¯ã©ã€ã¢ã³ãã®ãœãŒã¹ ãµããããã«é¢ããããŒã¿ã¯ãã³ã³ãã³ãé ä¿¡ãããã¯ãŒã¯ã®å¹æçãªéçšã«å¿ èŠã§ã)ã ãæ°ãããªãªãŒã¹ã§ã¯ãEDNS ã¯ã©ã€ã¢ã³ã ãµããããã®äœ¿çšãéžæçã«å¶åŸ¡ããããã®èšå®ãè¿œå ãããŠããŸããecs-è¿œå çš Â» çºä¿¡ãªã¯ãšã¹ã㧠ECS ã§äœ¿çšããã IP ã®ãããã¯ãŒã¯ ãã¹ã¯ã®ãªã¹ããæå®ããããã¹ã¯ã®ç¯å²å ã«åãŸããªãã¢ãã¬ã¹ã®å Žåã¯ããã£ã¬ã¯ãã£ãã§æå®ãããäžè¬çãªã¢ãã¬ã¹ã䜿çšãããŸããecs-scope-zero-address ããæ什ãéããŠãåä¿¡ednsãµããããã䜿çšãã » ECS å€ãå ¥åãããåä¿¡ãªã¯ãšã¹ãã眮ãæããããªããµãããããå®çŸ©ã§ããŸãã - 100 ç§ãããã«å€§éã®ãªã¯ãšã¹ã (XNUMX äžä»¥äž) ãåŠçãããµãŒããŒã®å Žåããã£ã¬ã¯ãã£ãã
ãã£ã¹ããªãã¥ãŒã¿ã¹ã¬ãã " ã¯ãåä¿¡ãªã¯ãšã¹ããåä¿¡ããããããã¯ãŒã«ãŒ ã¹ã¬ããéã§åæ£ããããã®ã¹ã¬ããã®æ°ã決å®ããŸã ("pdns-distributes-queries=yes «ïŒã - è¿œå ãããèšå®
ãããªãã¯ãµãã£ãã¯ã¹ãªã¹ããã¡ã€ã« ç¬èªã®ãã¡ã€ã«ãå®çŸ©ããã«ã¯ãããªãã¯ãµãã£ãã¯ã¹ã®ãªã¹ã PowerDNS Recursor ã«çµã¿èŸŒãŸãããªã¹ãã®ä»£ããã«ããŠãŒã¶ãŒãèªåã®ãµããã¡ã€ã³ãç»é²ã§ãããã¡ã€ã³ã
PowerDNS ãããžã§ã¯ãã¯ã4.3 ãæã®éçºãµã€ã¯ã«ãžã®ç§»è¡ãçºè¡šããPowerDNS Recursor 2020 ã®æ¬¡ã®ã¡ãžã£ãŒ ãªãªãŒã¹ã¯ 4.2 幎 2021 æã«äºå®ãããŠããŸããéèŠãªãªãªãŒã¹ã®ã¢ããããŒãã¯å¹ŽéãéããŠéçºããããã®åŸãè匱æ§ä¿®æ£ã¯ããã« 4.2 ãæéãªãªãŒã¹ãããŸãããããã£ãŠãPowerDNS Recursor XNUMX ãã©ã³ãã®ãµããŒã㯠XNUMX 幎 XNUMX æãŸã§ç¶ããŸãã PowerDNS Authoritative Server ã«ãåæ§ã®éçºãµã€ã¯ã«ã®å€æŽãå ããããŠãããè¿ãå°æ¥ XNUMX ããªãªãŒã¹ãããäºå®ã§ãã
PowerDNS Recursor ã®äž»ãªæ©èœ:
- ãªã¢ãŒãçµ±èšåéçšããŒã«ã
- å³æåèµ·åã
- Lua èšèªã§ãã³ãã©ãŒãæ¥ç¶ããããã®çµã¿èŸŒã¿ãšã³ãžã³ã
- DNSSEC ã®å®å
šãªãµããŒããš
DNS64 ; - RPZ (ã¬ã¹ãã³ã¹ ããªã·ãŒ ãŸãŒã³) ã®ãµããŒããšãã©ãã¯ãªã¹ããå®çŸ©ããæ©èœã
- ã¹ããŒãã£ã³ã°é²æ¢ã¡ã«ããºã ã
- 解決çµæã BIND ãŸãŒã³ ãã¡ã€ã«ãšããŠèšé²ããæ©èœã
- é«ãããã©ãŒãã³ã¹ã確ä¿ããããã«ãFreeBSDãLinuxãSolaris ã§ã¯ææ°ã®æ¥ç¶å€éåã¡ã«ããºã (kqueueãepollã/dev/poll) ã䜿çšãããŠããããŸããæ°äžã®ãªã¯ãšã¹ãã䞊è¡ããŠåŠçã§ããé«æ§èœ DNS ãã±ãã ããŒãµãŒã䜿çšãããŠããŸãã
åºæïŒ ãªãŒãã³ããã.ru