Project

General

Profile

Actions

Feature #10449

closed

Aggressive NSEC option

Added by Viktor Gurov almost 4 years ago. Updated almost 4 years ago.

Status:
Resolved
Priority:
Normal
Category:
DNS Resolver
Target version:
Start date:
04/13/2020
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:

Description

Very nice feature for DNS optimization, which can reduce the number of queries to authoritative name servers.
See https://tools.ietf.org/html/rfc8198

unbound.conf(5):

aggressive-nsec: <yes or no>
              Aggressive  NSEC uses the DNSSEC NSEC chain to synthesize NXDOMAIN and other denials, using information from previous
              NXDOMAINs answers.  Default is no.  It helps to reduce the query rate towards targets that get a very  high  nonexis‐
              tent name lookup rate.

Actions

Also available in: Atom PDF