The Importance of Diversity
Cricket Liu (Infoblox)
Our friends at The Measurement Factory just completed the 2010 DNS Survey, and we’ll release the complete results soon. For those of you who just can’t wait, though, here’s a preview of some of the results.
One of our datasets was a large (i.e., millions of zones), random sample of subzones of .COM, .NET and .ORG. Looking at the IP addresses of the authoritative name servers for these zones, we found that nearly 20% seem to have all of their authoritative name servers on the same network. (They’re on the same /24, at least—in some cases, of course, that might be multiple networks, but it’s relatively unlikely.)
This is an accident waiting to happen. Some of you might remember the embarrassing DNS outage Microsoft suffered several years ago when a technician misconfigured a border router in Redmond: Because all of their authoritative name servers were on a single network behind that router, users couldn’t resolve most Microsoft domain names for an extended period. Don’t let that happen to you.
Posted in Microsoft | DNS Security | DNS Best Practices | Disaster Recovery | DNS Survey |
0 comments