Maintained by: NLnet Labs

[Unbound-users] multicast address alerts in logs

bmanning at vacation.karoshi.com
Sat Mar 5 06:39:55 CET 2011


On Fri, Mar 04, 2011 at 08:56:17PM -0500, Michael Watters wrote:
> > That's not a multicast address; it's an (unusable) class-E 240/4 address.
> >
> > Weird to see traffic to it...
> >
> > Maybe someone has some bad glue?
> 
> That's entirely possible.  These servers are handling queries from
> thousands of servers and I'm sure that some domains have bad records.
> 
> Each server has interface tracking set to automatic and the anycast
> IPs are on loopback interfaces.  The messages don't seem to be causing
> any problems but I'd like to figure out what's causing them.


	there is a modification to unbound that allows it to
	use IPv4 multicast addreses to discover other DNS servers	

	there is also a patch for BIND that does the same thing.

	I thought I was pretty careful w/ the code and didn't think
	it had escaped into the wild.

	if there is anyone w/ logs they would be willing to share,
	I'd like to ensure it not my code doing this...

--bill