Skip site navigation (1)Skip section navigation (2)

  
 
  

home | help
COREDNS-BUFSIZE(7)		 CoreDNS Plugins	      COREDNS-BUFSIZE(7)

NAME
     bufsize - limits EDNS0 buffer size to prevent IP fragmentation.

DESCRIPTION
     bufsize  limits  a  requester's UDP payload size to within a maximum value.
     If a request with an OPT RR has a bufsize greater than the limit, the  buf-
     size  of  the request will be reduced. Otherwise the request is unaffected.
     It prevents IP fragmentation, mitigating certain DNS  vulnerabilities.   It
     cannot  increase  UDP size requested by the client, it can be reduced only.
     This  will  only  affect	queries   that	 have	an   OPT   RR	(EDNS(0)
     <https://www.rfc-editor.org/rfc/rfc6891>).

SYNTAX
	    bufsize [SIZE]

     [SIZE]  is  an int value for setting the buffer size.  The default value is
     1232, and the value must be within 512 - 4096.  Only one  argument  is  ac-
     ceptable, and it covers both IPv4 and IPv6.

EXAMPLES
     Enable  limiting  the  buffer  size  of  outgoing	query  to  the	resolver
     (172.31.0.10):

	    . {
		bufsize 1100
		forward . 172.31.0.10
		log
	    }

     Enable limiting the buffer size as an authoritative nameserver:

	    . {
		bufsize 1220
		file db.example.org
		log
	    }

CONSIDERATIONS
     *	 Setting 1232 bytes to bufsize may avoid fragmentation on  the	majority
	 of  networks  in  use	today, but it depends on the MTU of the physical
	 network links.

CoreDNS 			   March 2026		      COREDNS-BUFSIZE(7)

Want to link to this manual page? Use this URL:
<https://man.freebsd.org/cgi/man.cgi?query=coredns-bufsize&sektion=7&manpath=FreeBSD+Ports+15.1.quarterly>

home | help