#2, Yes, it was/is potentially very confusing for people. Our own case is representative of what can happen. When I first discussed this with our team, the immediate reply was, "we're patched up and god to go"
That didn't seem right to me - as we had an edge firewall ahead of our split DNS Authoritative Host Named DNS Servers). I ordered more tests and sure enough, returns from behind the NAT device, regardless of one to one publishing rules (e.g., no proxy at all, but a straight pass-through), reflected unique TXT ID's; however, the ports being assigned by the NAT were sequential (bad news). So we had to plan to move things and not use NAT to protect the D-DNS servers. We tested again and both ports and TXT ID's were random (as they should be).
BTW, I should have provided this test link in my first post, http://www.doxpara.com there is a check my DNS button - for all users/public host named DNS operators with recursion enabled, please ensure that your systems return no discernable patterns.
|