RE: ftp.perl.org strangeness

From: Dave Hart (davehart_at_davehart.com)
Date: 03/16/04

  • Next message: David Malone: "Re: ftp.perl.org strangeness"
    Date: Tue, 16 Mar 2004 07:55:57 -0000
    To: "Mark Andrews" <Mark_Andrews@isc.org>, "Rick Knospler" <rick@skylands.net>, <ask@develooper.com>, <freebsd-stable@freebsd.org>
    
    

    I've run across this issue with a few websites in the last 18 months.
    It might help to ask if they're using a "load balancer" on
    ddns5.develooper.com (the nameserver for ddns.develooper.com which is
    the zone containing ftp.cpan.ddns.develooper.com which is CNAMEd from
    ftp.perl.org). One DNS-based load balancing product exhibited this
    broken behavior, though I don't know which product it was. When queried
    for type A or any type, the correct responses are returned, but when
    querying for AAAA, NXDOMAIN is returned, which is evil because it
    communicates false information that there are no records of any type at
    that name. Since IPv6-enabled clients query AAAA before A or any, they
    tend to trip up 100% of the time. I've not yet heard of a
    general-purpose DNS server getting this wrong, I assume any such
    offenders were fixed earlier in the 8 years of AAAA. DNS-based load
    balancers are on average greener.

    I ran across this first with a major computer reseller website and
    complained to their admins. It took many months for them to get the fix
    from their load-balancing vendor and convince themselves it was safe,
    but they did eventually correct the fault.

    ask <at> develooper.com is listed as the contact in the SOA for
    ddns.develooper.com, hopefully including them on this email will get the
    ball rolling.

    Dave Hart
    davehart@davehart.com
    _______________________________________________
    freebsd-stable@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-stable
    To unsubscribe, send any mail to "freebsd-stable-unsubscribe@freebsd.org"


  • Next message: David Malone: "Re: ftp.perl.org strangeness"

    Relevant Pages

    • Cisco CSS11050 - IIS5.0 - HTTPS site does not work after bouncing the website
      ... We are using Cisco CSS11050 to load balance between two IIS5.0 websites ... we cannot access the website via https ... Port 80 is ... service in Load Balancer for port 443 and make the service active. ...
      (comp.dcom.sys.cisco)
    • suggest a good hardware load balancer?
      ... I know Windows 2003 supports load balancing, but I already have two Windows ... 2000 web servers and now I want to run the same websites on both and put a ... Also, with the hardware load balancer, do you know if I *must* change the ...
      (microsoft.public.inetserver.iis)