[dns-wg] DNSSEC and DNS slowdown
- Previous message (by thread): [dns-wg] DNSSEC and DNS slowdown
- Next message (by thread): [dns-wg] DNSSEC and DNS slowdown
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Dave Knight
dave at knig.ht
Fri Jul 30 15:30:54 CEST 2010
Hi Max, On 2010-07-30, at 7:14 AM, Max Tulyev wrote: > Hello! > > I have a strange problem. When I enable DNSSEC in my resolver (bind 9) - > it slows down in several times. > > What do I do wrong? Or may be it is a feature? Your question might be better asked over on <bind-users at isc.org>, however... Switching on DNSSEC validation gives the resolver more work to do, that might slow it down a bit, but not so you'd notice if things are working properly. If you're using a DLV it will have even more work to do, which might slow it down a bit more. If the path between your resolver and the authority servers isn't able to properly pass larger responses you might be suffering from timeouts which would slow it down a lot. A tcpdump at the resolver would probably be informative. dave
- Previous message (by thread): [dns-wg] DNSSEC and DNS slowdown
- Next message (by thread): [dns-wg] DNSSEC and DNS slowdown
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[ dns-wg Archives ]