SARR
A mnemonic for the common stateful DHCPv6 exchange: Solicit, Advertise, Request, Reply. Rapid Commit can reduce the exchange to Solicit and Reply when both client and server support it.
Read definition76 definitions beginning with S.
76 terms
A mnemonic for the common stateful DHCPv6 exchange: Solicit, Advertise, Request, Reply. Rapid Commit can reduce the exchange to Solicit and Reply when both client and server support it.
Read definitionSource Address Validation Improvement, a family of mechanisms that binds IP source addresses to attachment points to reduce spoofing. SAVI can use DHCP, Neighbor Discovery, or other control-plane evidence.
Read definitionAutomatic removal of DNS records considered stale according to timestamp and aging settings. In Microsoft DNS, both zone aging and server scavenging schedules must be configured correctly.
Read definitionA context defining which addresses, options, or policies apply. Microsoft DHCP uses scope for an IPv4 subnet and pool, while other systems may use the term for IPv6 reachability or administrative visibility.
Read definitionA DHCP option configured at a particular hierarchy level, such as server, scope, policy, reservation, or class. More-specific settings often override inherited values according to product precedence.
Read definitionThe amount of a DHCP scope currently leased, reserved, excluded, or available. Alerts should account for addresses that are not eligible for ordinary allocation.
Read definitionA domain suffix appended by a client to relative names during resolution. Multiple suffixes form a search list whose order and qualification rules can create unexpected queries.
Read definitionAn authoritative server that obtains zone data from another authoritative source, traditionally through AXFR or IXFR. It can answer clients independently and is not inherently less authoritative than the primary.
Read definitionA read-only authoritative copy of a zone obtained from a primary or another secondary. It refreshes based on SOA timing, NOTIFY, and transfer behavior.
Read definitionA validation state indicating that DNS data has a valid chain of trust to a configured trust anchor and its signatures verify successfully.
Read definitionA delegation in which the parent publishes a valid DS record for the child, allowing validators to continue the chain of trust into the child zone.
Read definitionA DNS UPDATE process authenticated and authorized so only approved clients or services can change records. Common mechanisms include TSIG, GSS-TSIG, SIG(0), and platform identity controls.
Read definitionThe set of security tools and controls that consume or influence DDI data, including SIEM, SOAR, NAC, firewalls, EDR, threat intelligence, protective DNS, and asset inventory.
Read definitionA DNSKEY used directly as a configured trust anchor, normally validated through its self-signature and an out-of-band trust process rather than a parent DS record.
Read definitionThe SOA field used by secondary servers to determine whether zone data has changed. Serial arithmetic wraps modulo 2^32 and should follow RFC 1982.
Read definitionA value identifying the DHCP server participating in a transaction. DHCPv4 commonly uses option 54 with an IPv4 address, while DHCPv6 uses a DUID in OPTION_SERVERID.
Read definitionAn older DHCPv6 feature that allowed clients to send some messages directly to a server address advertised in an option. RFC 9915 marks the Server Unicast option and UseMulticast behavior obsolete.
Read definitionRCODE 2, indicating that the server failed to complete the operation. Causes include upstream timeout, DNSSEC validation failure, lame delegation, expired secondary zone, policy, or internal error.
Read definitionA framework using SVCB and HTTPS records to describe alternative endpoints and connection parameters for a service. It can advertise protocols, ports, address hints, and security-related parameters.
Read definitionThe process of locating service endpoints and parameters through DNS records or related naming conventions. SRV, NAPTR, SVCB, HTTPS, and service-specific records can participate.
Read definitionAn address representing a service rather than a single physical interface, such as a VIP, anycast address, cluster address, or load-balancer frontend.
Read definitionA formal commitment for measurable service outcomes such as availability, response time, support, or recovery. DDI SLAs should define measurement points and exclusions.
Read definitionA target for a service indicator, such as successful DNS responses, DHCP allocation time, or platform availability. SLOs are internal engineering objectives and may support an SLA.
Read definitionThe SVCB or HTTPS record form that directly describes connection parameters for a service endpoint. It uses a nonzero priority and can contain service parameters.
Read definitionThe IPv4 block 100.64.0.0/10 reserved for service-provider shared-address use, especially carrier-grade NAT. It is not an RFC 1918 private block.
Read definitionThe BOOTP/DHCP "next server" address field, historically used to identify a server involved in the client's bootstrap process. Modern DHCP boot behavior may instead use options.
Read definitionThe time after which an RRSIG is no longer valid. Signing automation must refresh signatures early enough to survive outages, propagation, and clock differences.
Read definitionThe time before which an RRSIG is not yet valid. Signers often backdate inception slightly to tolerate clock skew.
Read definitionThe system or process that creates RRSIG records using DNSSEC private keys. It may run inline on an authoritative server, on a hidden primary, in an HSM-backed service, or offline.
Read definitionA controlled destination to which malicious or unwanted traffic is redirected for blocking, observation, or remediation. DNS sinkholes use policy answers to direct clients there.
Read definitionA deprecated IPv6 unicast scope formerly associated with fec0::/10. It was replaced operationally by Unique Local Addresses and should not be used in new designs.
Read definitionA DHCP option code intended for local site use. Such options can conflict across organizations and should be carefully documented when networks merge or devices move.
Read definitionStateless Address Autoconfiguration, by which an IPv6 host forms addresses from Router Advertisement prefixes without a DHCPv6 address lease. DHCPv6 can still provide other configuration, and address registration can improve visibility.
Read definitionAn older term for a secondary authoritative DNS server. Current standards terminology prefers secondary because it is more precise and neutral.
Read definitionThe final field of the SOA record. Historically it had multiple interpretations; current negative-caching rules use it with the SOA TTL to determine the negative TTL.
Read definitionThe Start of Authority record identifies key zone parameters including MNAME, RNAME, serial, refresh, retry, expire, and minimum fields. Every authoritative zone has an SOA at its apex.
Read definitionA tunneling or translation mechanism used to deliver IPv4 service over IPv6 or vice versa. DHCP options can provision mechanisms such as MAP-E, MAP-T, Lightweight 4over6, and 4RD.
Read definitionThe initial DHCPv6 client message used to locate servers and request addresses, prefixes, or other configuration. Servers normally answer with ADVERTISE unless Rapid Commit is used.
Read definitionThe IP address placed in a packet to identify its sender from the network perspective. It may differ from an application identity and can be translated or spoofed.
Read definitionHost logic for choosing the most appropriate source address for a destination based on scope, deprecation, label, precedence, and prefix matching. Incorrect choices can cause asymmetric or failed connectivity.
Read definitionThe system or governed data set designated as authoritative for a class of information. In DDI, one system may own intended allocation while discovery or DHCP owns observed runtime state, so ownership must be explicit.
Read definitionUse of unpredictable UDP source ports in recursive DNS queries to increase the entropy an off-path attacker must guess when forging a response.
Read definitionVerification that a packet's source address is legitimate for the interface, route, binding, or customer from which it arrived. Techniques include ACLs, uRPF, DHCP snooping bindings, SAVI, and provider filtering.
Read definitionAn address block reserved for a defined technical purpose rather than ordinary global unicast use, such as loopback, documentation, link-local, benchmarking, or NAT64 discovery. IANA maintains current registries.
Read definitionA domain name reserved by an RFC for special behavior, such as localhost, invalid, test, or onion. Applications and resolvers may treat such names differently from ordinary public DNS names.
Read definitionSender Policy Framework, an email-authentication mechanism that publishes which systems are authorized to send mail for a domain, normally in a DNS TXT record. The dedicated SPF RR type is obsolete for deployment.
Read definitionA failure in which peer nodes lose communication and both act as the active authority, potentially creating conflicting leases or configuration. Quorum, fencing, MCLT, and operational procedures reduce the risk.
Read definitionA design in which the same name or namespace produces different data depending on the requesting client or network context. It can be implemented with views, separate authoritative systems, private zones, or resolver policy.
Read definitionA common synonym for split DNS. The same namespace is presented differently to different audiences.
Read definitionA legacy DHCPv4 availability design in which two independent servers each own a non-overlapping portion of a subnet's address range, often in an 80/20 ratio. DHCP failover is generally preferred when supported.
Read definitionA Service record identifies the target host and port for a named service, with priority and weight values for selection. The owner name normally begins with _service._protocol.
Read definitionA mistaken or informal rendering sometimes used for SLAAC. The standardized acronym is SLAAC, Stateless Address Autoconfiguration.
Read definitionAn expired cached response served by a resolver when authoritative refresh is temporarily impossible and policy permits serving stale data. It can improve resilience during outages while carrying an EDE explanation.
Read definitionA record that no longer reflects the current device, address, owner, or service. Stale data can cause misrouting, security exposure, and incorrect capacity reports.
Read definitionDHCPv6 operation in which the server assigns addresses or prefixes and maintains bindings, typically through IA_NA or IA_PD. Router Advertisements still provide default-router information.
Read definitionDHCPv6 used only to provide configuration such as DNS or domain search information without assigning addresses. Clients normally learn addresses through SLAAC and send INFORMATION-REQUEST.
Read definitionA persistent client-to-address association configured by an administrator. Products may implement it as a reservation, fixed address, manual allocation, or host object.
Read definitionA DNS record created without an aging timestamp or otherwise protected from automatic scavenging. "Static" describes management behavior, not a distinct DNS record type.
Read definitionA manually configured route rather than one learned through a dynamic routing protocol. DHCP can provide limited static-route information to hosts through options.
Read definitionAn authoritative server not listed in the public NS RRset, often used as a hidden primary or internal transfer source. The term is informal.
Read definitionA simple resolver on an endpoint that sends queries to a recursive resolver and does little or no iterative resolution itself. Operating-system libraries commonly provide stub functionality.
Read definitionA zone configuration containing only enough authoritative data, usually SOA, NS, and glue, to locate the zone's current authoritative servers. It tracks delegation data without storing the full zone.
Read definitionA delegation from one zone to a child zone below it. Each subdelegation creates a new zone cut and administrative boundary.
Read definitionA domain contained beneath another domain in the DNS hierarchy. A subdomain is not necessarily a separate zone unless a delegation creates a zone cut.
Read definitionAn attack in which a DNS record points to a deprovisioned third-party resource that an attacker can claim. Removing dangling records and validating external targets reduces risk.
Read definitionA prefix used as an on-link network or administrative allocation unit. In IPv4 it has a network mask and usually network and broadcast addresses; IPv6 LANs commonly use /64.
Read definitionThe portion of an address plan used to distinguish subnets within a larger assigned prefix. In IPv6 enterprise planning, it often refers to bits between the global routing prefix and the interface identifier.
Read definitionA 32-bit mask identifying network and host bits in an IPv4 address. Contiguous masks are represented more compactly by CIDR prefix length.
Read definitionAn option that lets a client or relay identify the subnet from which an address should be selected when GIADDR or the receiving interface is insufficient.
Read definitionA typed field nested within another DHCP option, such as circuit ID inside option 82 or vendor-specific data inside an enterprise container. Its namespace is defined by the parent option.
Read definitionA sequence of ending labels in a domain name. DNS hierarchy, search lists, public-suffix policy, and QNAME minimization all use suffix concepts in different ways.
Read definitionA larger aggregate prefix that contains multiple smaller networks. Supernetting supports route summarization and hierarchical address management.
Read definitionA Microsoft DHCP grouping of multiple IPv4 scopes on the same physical network. It supports multinets where several logical subnets share one broadcast domain, but routing and client behavior must be designed carefully.
Read definitionA Service Binding record that describes alternative service endpoints and connection parameters. It supports alias mode and service mode and is the base format specialized by the HTTPS record.
Read definitionA key-value parameter carried in SVCB or HTTPS RDATA, such as alpn, port, ipv4hint, ipv6hint, ech, or mandatory. IANA maintains the parameter-key registry.
Read definitionAutomated tests that periodically perform DNS lookups, DHCP transactions, API calls, or application checks from controlled probes. It measures user-like outcomes even when no real user reports an issue.
Read definition