[ratelimits] Fragments of ARM Chapter 6 clarification

Paul Vixie paul at redbarn.org
Mon Feb 11 23:15:50 UTC 2013

Zane Thomas wrote:
> Knowing that there should only be one reply to a given ip for each
> query coming from that ip requires at least some dns-awareness. :)

i'm not sure what we're talking about.

there has to be more than one reply to a given ip address for each
*response* you are thinking of sending. definitely more than one, to
account for multiple outstanding queries, recursives behind NAT, and
postel's robustness principle.

but it's *responses*, not *queries*, that you have to be aware of.


