On Jul 28, 2017, at 8:16 PM, Stephen Farrell <stephen.farrell@xxxxxxxxx> wrote:
The point is that if you are validating on your host, which I think is a great plan, you should also be doing DNS64 on your host; otherwise you will not be able to operate on a NAT64 network. I guess the other option is to never do NAT64, but that's a bit extreme at the present time. And, if you find that the current solution for doing DNS64 on your host isn't adequately secure, I would personally like you to complain about _that_, because that would likely provoke useful work. :) |