Sporadic dns issue related to DNSSEC
-
Hopefully it just sucks as a NS, since it works without DNSSEC and I don't want network issues!
It's been a great learning experience. For now I keep DNSSEC on, and have an exeption for broadcom and turned off ipv6 in unbound as you suggested. -
Them pointing cname to cname isn't best practice either. While its allowed - it causes extra lookups..
;; QUESTION SECTION: ;www.broadcom.com. IN A ;; ANSWER SECTION: www.broadcom.com. 300 IN CNAME cdn.broadcom.com. cdn.broadcom.com. 3600 IN CNAME www.broadcom.com.cdn.cloudflare.net.
If they want www.broadcom.com to point to www.broadcom.com.cdn.cloudflare.net.
Then they should just do that, but they are pointing to cdn.broadcom.com first, which then points to the cloudflare.net cname..
Its not efficient to do that.. Just causes extra work..
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.