Professional Documents
Culture Documents
KEY FEATURES
Software-only solution for authoritative DNS function, choice of OS and hardware Proprietary database optimized for scaling to a billion resource records Dual active masters that mirror DNS updates with no loss for data resiliency Network visibility and event awareness into DNS queries and trends High DNS query transaction rate of over 100K QPS with millisecond latency On-the-fly DNS zone updates without requiring server restart Fast reload time even with the highest number of resource records Full compliance with DNSSEC standards and optional DNSAUTH to secure DNS data and communication links Automated DNSSEC lifecycle management Templating to easily replicate common zone configuration elements IPv6 support
Authoritative DNS
End user growth, new applications and services, increasing traffic, and changing Internet usage patterns as well as next-generation network architectures all place new demands on the DNS infrastructure. ANS was designed for performance and specifically targeted at carrier grade DNS services. Unlike common industry practice, Nominum developed two entirely independent solutions for authoritative (ANSP) and caching (Vantio).
2010 Nominum, Inc. All rights reserved. Nominum, Navitas, Vantio, Centris and TRUE Architecture are registered trademarks of Nominum, Inc.
DATAS HEET
By building ANSP exclusively as an authoritative server, Nominum was able to achieve levels of performance and scalability not possible in dual-purpose name servers. Nominum VDB (Versioned Database) is the underpinning of all Nominum authoritative DNS offerings. VDB uses a unique in-memory process that makes data instantly available for queries and allows for automatic recovery and near instantaneous restart in the event of server failure. Superior design also allows ANS to support high update rates reliably with DDNS. As demonstrated in more than 140 major networks around the world, Nominum software and services deliver consistent, high-performance, low-latency DNS solutions. Nominums patented performance algorithms and other innovative technologies make it the undisputed performance leader.
Multimastering Support
In the past, master authoritative nameservers were a single point of failure. When one failed, updates could not be propagated to slave nodes, and thus not reflected in the network. Active-standby designs or other techniques to address this problem introduce complexity, unacceptable delay or synchronization problems. This is incompatible with IP services that require frequent changes to DNS data while maintaining 100% uptime. Multimastering (MM) is unique to Nominum, allowing two active authoritative name servers to serve as masters for the same zone. As with existing master servers, each can have multiple slave servers. Multimastering is configured using federations that define groups of ANSP master authoritative name servers that exchange zone information. Zone information added in one multimaster name server using Dynamic DNS or manual updates is instantly synchronized to other multimaster name servers in a federation. Multimastering relies on DNS serial numbers to synchronize data between servers exchanging zones. Servers are instantly and seamlessly synchronized with the same data and do not require a restart. This is vital for services with a real-time component such as VoIP, or to facilitate disaster recovery efforts. Only one live master is required for DNS service, including updates, to be available. Multimastered servers also provide service in the event a network is partitioned, with separated masters serving data to their respective partitions. When a failed master recovers or partitioned masters are rejoined, they automatically synchronize with peers.
DATAS HEET
Fast access to favorite web sites Instant network response for any application Always-on service for any device attached to the network No network slowdowns, even during peak periods No risk of reaching a spoofed or fake web site DNS resolution continues even if the network is under attack
Query streams can also be replayed. The combination of all of this data can be used for planning, tracking, usage trends, forensics or other purposes.
2010 Nominum, Inc. All rights reserved. Nominum, Navitas, Vantio, Centris and TRUE Architecture are registered trademarks of Nominum, Inc.
DATAS HEET
Offline signing is preferred in environments where network owners want private keys used for signing DNS data to be separated from DNS servers. Offline signing takes advantage of a subset of ANSP software, with complete DNSSEC lifecycle management, running on an external server. The protected data is then transferred to another instance of ANS that serves qeueries, thus eliminating the need for proprietary signing appliances.
DNSAUTH
DNSAUTH is a protocol developed by DNS experts at Nominum to secure DNS data while maximizing compatibility with existing DNS infrastructure. It extends Nominum leading DNS defenses by securing communication links between Vantio caching servers and ANSP authoritative servers. DNSAUTH relies on authentication of the authoritative server and optional encryption of DNS responses in transit between caching and authoritative servers. Cryptographic protection of DNS links introduced with DNSAUTH makes it statistically impossible for an attacker to compromise the DNS data. It is fully compatible with DNSSEC.
2010 Nominum, Inc. All rights reserved. Nominum, Navitas, Vantio, Centris and TRUE Architecture are registered trademarks of Nominum, Inc.