Adding root servers as local secondary zone to local caching server

Chriztoffer Hansen ch at ntrv.dk
Thu Sep 2 14:10:41 UTC 2021


On Thu, 2 Sept 2021 at 15:27, Charles Sharp via Unbound-users
<unbound-users at lists.nlnetlabs.nl> wrote:
> Do most of you use the root hints or forwarders?

Tried both. Now using forwarders.

> I currently use the following, in order:
>
> 1.1.1.1
> 9.9.9.9
> 8.8.8.8

No IPv6? Or not on a dual-stacked endpoint?

Joke questions aside, my own upstream is reasonably well-connected.
Has had configured the local dns forwarder to use root hints in the
past. Compared to using the "big cdn forwarders" the user experience
*perceived* is 99 % non-existent if the avg. lookup time is low.

If configuring the local resolver to cache all lookups for a reasonbly
minimum amount of time (e.g. 5 - 60 min). Only the user doing the
lookup when the cache entry is cold will (maybe) notice a delay if the
lookup is "slow".

Side-note: Depending on your choice of local resolver software. Some
implementations will ask the configured forwarders one at a time (i.e.
try entry 1, try 2 if 1 fail, try 3 if 2 fail, etc.).
Others (e.g. dnsmasq) defaults to ask _all_ configured forwarders
simultaniously.
Others will "regularly" test all configured forwarders to measure the
response time and only use the fastest forwarder.



More information about the Unbound-users mailing list