Today's fun debug adventure, on one of the bgp.tools remote IX collector boxes in Iraq, all DNS packets appear to be ACL'd now. See the difference in mtr's for port 53 vs 54

Not too much of a problem, as just flipping the switch on systemd-resolved to use DNS Over TLS "fixed" the problem. I guess systemd-resolved is good for something then!

8rS613FXdQzx76r1p4.png
0

If you have a fediverse account, you can quote this note from your own instance. Search https://benjojo.co.uk/u/benjojo/h/222C9643d4LLh6xR5t on your instance and quote it. (Note that quoting is not supported in Mastodon.)