Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Contemporary requirements for zone transfers
Search
Artyom "Töma" Gavrichenkov
October 12, 2017
Technology
0
51
Contemporary requirements for zone transfers
Artyom "Töma" Gavrichenkov
October 12, 2017
Tweet
Share
More Decks by Artyom "Töma" Gavrichenkov
See All by Artyom "Töma" Gavrichenkov
[EE DNS Forum 2018] DDoS on DNS: past, present and inevitable
ximaera
0
57
Wrong, wrong, WRONG! methods of DDoS mitigation
ximaera
0
350
DDoS Beasts and How to Fight Them (Nginx Conf 2018)
ximaera
0
190
DDoS tutorial (China ISC 360)
ximaera
0
250
[RU] “I, Not Robot". A design of the contemporary CAPTCHA challenges and the future of the Turing test
ximaera
0
120
DDoS 101 (2018, PaymentSecurity RU 2018)
ximaera
0
42
Memcached Amplification: Lessons Learned (NANOG 73)
ximaera
0
220
DDoS Beasts and How to Fight Them
ximaera
0
62
Memcached Amplification DDoS: Lessons Learned (ENOG 15)
ximaera
0
53
Other Decks in Technology
See All in Technology
ニッポンの人に知ってもらいたいGISスポット
sakaik
0
150
Introduction to Sansan Meishi Maker Development Engineer
sansan33
PRO
0
310
Performance Insights 廃止から Database Insights 利用へ/transition-from-performance-insights-to-database-insights
emiki
0
300
「れきちず」のこれまでとこれから - 誰にでもわかりやすい歴史地図を目指して / FOSS4G 2025 Japan
hjmkth
1
310
AWSでAgentic AIを開発するための前提知識の整理
nasuvitz
2
180
AI Agent Dojo #2 watsonx Orchestrateフローの作成
oniak3ibm
PRO
0
130
大規模サーバーレスAPIの堅牢性・信頼性設計 〜AWSのベストプラクティスから始まる現実的制約との向き合い方〜
maimyyym
10
4.9k
生成AI時代のセキュアコーディングとDevSecOps
yuriemori
0
120
20251007: What happens when multi-agent systems become larger? (CyberAgent, Inc)
ornew
1
310
LLMアプリの地上戦開発計画と運用実践 / 2025.10.15 GPU UNITE 2025
smiyawaki0820
1
590
能登半島地震で見えた災害対応の課題と組織変革の重要性
ditccsugii
0
1k
GoでもGUIアプリを作りたい!
kworkdev
PRO
0
150
Featured
See All Featured
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
285
14k
Music & Morning Musume
bryan
46
6.8k
Building Better People: How to give real-time feedback that sticks.
wjessup
369
20k
Six Lessons from altMBA
skipperchong
29
4k
Raft: Consensus for Rubyists
vanstee
140
7.1k
4 Signs Your Business is Dying
shpigford
185
22k
Docker and Python
trallard
46
3.6k
Fight the Zombie Pattern Library - RWD Summit 2016
marcelosomers
234
17k
Balancing Empowerment & Direction
lara
5
690
Visualization
eitanlees
149
16k
RailsConf 2023
tenderlove
30
1.2k
BBQ
matthewcrist
89
9.8k
Transcript
Contemporary requirements for zone transfers Artyom Gavrichenkov <
[email protected]
> GPG: 2deb
97b1 0a3c 151d b67f 1ee5 00e7 94bc 4d08 9191
A long, long time ago. • /etc/hosts • Service owner
responsible for the name resolution
Next. • Authoritative DNS servers • DNS registries • Cloud
DNS services
A Split. Customers Providers
1
2
…
A Split. Customers Providers
Customers Providers • DNSSEC • CAA • TLS …
Customers Providers ? • DNSSEC • CAA • TLS …
Customers Providers • Backup datacenters • Geobalancing • ASN-based balancing
• CI/CD • DNSSEC • CAA • TLS …
None
DDoS Challenges • UDP-based protocol • Thanks God, a truncate
thing • Amplification attacks
Cloud solutions! • Amazon Route53 • Dyn • Azure •
Cloudflare • Google Cloud …
Cloud solutions! • Amazon Route53 • Dyn • Azure •
Cloudflare • Google Cloud … But.
Cloud solutions! • Amazon Route53 • Dyn • Azure •
Cloudflare • Google Cloud … But. What about AXFR?
None
“DNS Zone Transfers (AXFR/IXFR) support for Route53 is a hotly
asked for feature, and is one that we will consider adding in the future.” Amazon, 2012.
None
DNSControl https://github.com/StackExchange/dnscontrol/ “Synchronize your DNS to multiple providers from a
simple DSL”
A Standard? • DOTS • CDNI • DNSops?
A Standard? Zone transfers with blackjack and stuff • Balancing
and failover • Traffic load measurement & rate limiting • Dynamic filters • Extensions
Q&A Artyom Gavrichenkov <
[email protected]
>