[ipv6hackers] Fwd: Some stats on IPv6 fragments and EH filtering on the Internet

Gert Doering gert at space.net
Thu Nov 7 13:40:47 CET 2013


Hi,

On Thu, Nov 07, 2013 at 11:57:28AM +0100, Enno Rey wrote:
> > > As of late 2013 I personally can't really see much use/need for
> > > fragmented IPv6 traffic at all.
> > 
> > DNS?
> 
> heard that many times ;-)
> may I ask (the list) two questions:
> 
> a) need for fragmented DNS_over_IPv6 inbound into an enterprise network (as opposed to a SP environment)?

Yes.  DNS responses carrying DNSSEC keys.  You don't want to have to 
fallback to TCP for the generic case.

> b) as you, Fernando, like to ask: any real-world numbers here anybody? [amount/numbers/percentage of fragmented DNS_over_IPv6 traffic]

Not that much DNSSEC going on, but the number of signed zones is rising,
as is the size of the reply packets...

Gert Doering
        -- NetMaster
-- 
have you enabled IPv6 on something today...?

SpaceNet AG                        Vorstand: Sebastian v. Bomhard
Joseph-Dollinger-Bogen 14          Aufsichtsratsvors.: A. Grundner-Culemann
D-80807 Muenchen                   HRB: 136055 (AG Muenchen)
Tel: +49 (0)89/32356-444           USt-IdNr.: DE813185279



More information about the Ipv6hackers mailing list