How do clients discover the DNS server in a SLAAC environment?
How do clients discover the DNS server in a SLAAC environment?
2. Then you have your router advertise that prefix.
3. Then you have your DNS server pick a non-temporary address within that prefix (either manually set it, or let the OS pick one).
4. Then you tell your router to advertise that address as the DNS server in the RA.
Depending on how you have your network set up, your DNS server will have probably four IPv6 addresses: A link-local one; one on the ULA prefix you created; a non-temporary address on the prefix delegated by your ISP; and one or more temporary addresses on the prefix delegated by your ISP.
Outgoing connections (for recursive resolving) will be on one of the temporary addresses from the PD prefix. The DNS server listens on the static ULA address.
You need to configure your firewall such that traffic from the delegated prefix can get to the ULA one, and vice versa. This usually just means blocking traffic from the WAN port to the ULA prefix.
For Internet-facing DNS you don't. For your internal resolver you could create a static address within a ULA (e.g. $PREFIX::1).
How do clients discover the DNS server in a SLAAC environment?
Then there was a bug in CoreDNS that wouldn't bind link local. What I learned from the text is that I should have probably generated a unique address for the DNS.
It is not only confusing theoretically but also the ISP router config makes it even more confusing.
Your link local or ULA is static address and can be used for DNS.
DNS server is advertised when prefix is advertised.
Mine specifies the router's ULA, which is effectively static, and it runs unbounded.
This seems like the "rogue DHCP" problem in v4.