Back to articles
Technology Insight

Optimizing Domain Resolution in Vietnam: A Guide to Anycast DNS with Knot DNS and GeoIP on 3 Cheap VPS

June 4, 2026

Introduction: The Quest for Sub-Millisecond DNS Resolution

In the digital economy, speed is not just a luxury; it is a critical metric for user retention and SEO performance. While much attention is paid to front-end optimization and Content Delivery Networks (CDNs), the foundation of network latency often goes overlooked: Domain Name System (DNS) resolution time. For businesses targeting audiences across Vietnam, relying on a single, centralized DNS server inevitably introduces geographic latency bottlenecks between the northern, central, and southern regions.

To solve this, enterprise networks employ Anycast DNS—a routing technique that allows multiple physical servers scattered across different locations to share a single IP address. Routers automatically direct user requests to the topologically nearest node. Historically, deploying an Anycast network required deep pockets and complex enterprise contracts. However, using modern open-source software like Knot DNS, smart routing mechanisms via GeoIP, and BGP (Border Gateway Protocol) features provided by budget-friendly Virtual Private Server (VPS) providers, you can build a high-availability, low-latency DNS infrastructure tailored for Vietnam at a minimal cost.

This comprehensive guide will walk you through setting up a distributed Anycast DNS infrastructure across three affordable VPS nodes strategically selected to optimize performance throughout Vietnam.

---

1. Architecture Overview & VPS Selection Strategy

To establish a resilient and highly performant Anycast network within Vietnam, our architecture relies on deploying three separate VPS instances. The goal is to achieve geographical redundancy and ensure that a user in Hanoi, Da Nang, or Ho Chi Minh City always hits the closest available node.

Strategic Node Placement

For an optimal footprint in Vietnam, your 3-VPS topology should ideally look like this:

  • Node 1 (Northern Vietnam): Deployed in a Hanoi-based datacenter (e.g., Viettel IDC, VNPT, or CMC Telecom). This node services users in Hanoi and the surrounding northern provinces.
  • Node 2 (Southern Vietnam): Deployed in a Ho Chi Minh City datacenter. This node handles traffic from the economic hub and southern delta regions.
  • Node 3 (Regional Failover / Alternative Provider): Deployed either with another distinct network provider in Vietnam or a low-latency regional hub like Singapore (e.g., Linode, DigitalOcean, or Vultr). This serves as a failover and ensures high availability if a major local network segment experiences routing issues.

Prerequisites for the VPS Providers

Not every cheap VPS provider supports an Anycast configuration. When choosing your budget hosts, you must verify the following criteria:

  1. BGP Session Support (BYOIP): The provider must allow you to establish a BGP session from your VPS to their upstream routers to announce your custom IP address block (typically a /24 IPv4 block or /48 IPv6 block).
  2. Root Access: Full root privileges on a stable Linux distribution, preferably Ubuntu Server 22.04 LTS or Debian 12.
  3. Favorable Peering: Ensure the providers have direct peering with major local ISPs like Viettel, FPT, and VNPT to eliminate unnecessary international routing loops.
---

2. Implementing BGP and Anycast Routing with Bird

Once your three VPS instances are provisioned, the first technical step is to configure Bird Internet Routing Daemon (BIRD). BIRD is a powerful, lightweight open-source routing daemon that will handle the BGP peering between your VPS and the provider's infrastructure.

Installing BIRD

Execute the following commands on all three nodes to update your package repositories and install BIRD:

sudo apt update
sudo apt install bird2 -y

Configuring the BGP Session

You will need to acquire specific peering details from your VPS providers, including your Local AS (Autonomous System Number), the Peer AS, and the Neighbor IP addresses. Below is a standardized template for /etc/bird/bird.conf on your nodes:

Note: Replace the placeholder IP addresses and AS numbers with the actual technical details provided by your infrastructure host.

log syslog all;

router id 192.0.2.1; # The unique public IP of your VPS

protocol device {
    scan time 10;
}

protocol direct {
    ipv4;
    interface "lo"; # Bind to the loopback interface
}

# Define the Anycast IP address to announce
protocol static anycast_ip {
    ipv4;
    route 203.0.113.53/32 via 192.0.2.1;
}

# Configure BGP Peering with upstream router
protocol bgp upstream_provider {
    local as 65530;
    neighbor 192.0.2.254 as 64512;
    
    ipv4 {
        export filter {
            if proto = "anycast_ip" then accept;
            reject;
        };
        import all;
    };
}

After saving the configuration, enable and restart the BIRD daemon:

sudo systemctl enable bird
sudo systemctl restart bird

By binding your target Anycast IP address (e.g., 203.0.113.53) to the loopback interface of all three servers and announcing it via BGP, upstream routers will dynamically distribute DNS queries to whichever server is closest in terms of network hops.

---

3. Installing and Tuning Knot DNS

For our authoritative DNS engine, we select Knot DNS, developed by CZ.NIC. Knot DNS is a high-performance, multi-threaded authoritative-only nameserver designed to handle intensive query loads with minimal memory and CPU overhead, making it ideal for low-cost VPS instances.

Installation

Install the latest stable release of Knot DNS via the official repository:

sudo add-apt-repository ppa:cz.nic-labs/knot-dns -y
sudo apt update
sudo apt install knot -y

Core Configuration

Open the primary configuration file located at /etc/knot/knot.conf. We must configure Knot to listen specifically on our Anycast IP address on the standard DNS port 53.

server:
    listen: 203.0.113.53@53
    user: knot:knot

log:
    - target: syslog
      any: info

template:
    - id: default
      storage: "/var/lib/knot"
      semantic-check: on

zone:
    - domain: yourbusiness.vn
      file: "yourbusiness.vn.zone"
---

4. Advanced GeoIP Integration for Hyper-Localized Routing

While Anycast naturally directs traffic to the closest node based on network topology, network paths do not always match geographical proximity due to asymmetric BGP routing or commercial peering arrangements. To fine-tune our responses and ensure users are always directed to optimal servers, we implement GeoIP-based policy routing within Knot DNS using the MaxMind GeoIP2 database.

Setting up MaxMind GeoIP

Download the free MaxMind GeoLite2 Country and City databases and place them in your system directory (e.g., /usr/share/GeoIP/). Next, update the mod-geoip configuration inside your Knot DNS server block to differentiate regions within Vietnam:

mod-geoip:
  - id: vn_routing
    config-file: "/etc/knot/geoip_maps.conf"
    db-file: "/usr/share/GeoIP/GeoLite2-City.mmdb"

In your geoip_maps.conf, define specific rules that map geographic regions to localized zone files. For example, if a query originates from northern provinces like Hanoi or Hai Phong, the GeoIP module overrides standard records to return a localized IP addresses for your web assets hosted nearby:

# Mapping regions to specific views
hanoi_view:
  country: VN
  region: ["HN", "HP", "QN"]

hcmc_view:
  country: VN
  region: ["SG", "BD", "DN"]

This dual-layer mechanism combines the structural routing efficiency of Anycast with the absolute precision of GeoIP, resulting in a virtually bulletproof, ultra-low-latency response system across the entire Vietnamese territory.

---

5. Testing, Monitoring, and Benchmarking

After deploying the configuration across all nodes, it is critical to verify that your Anycast network is routing efficiently and failing over as expected.

Testing Propagation and Node Identification

To identify exactly which node is answering a specific query, you can utilize the TXT record protocol. Add a unique identity string to each node’s local configuration (e.g., node-north, node-south). Execute the following command using dig from various client networks within Vietnam (such as a Viettel mobile connection or an FPT home broadband line):

dig @203.0.113.53 id.server TXT CH +short

The output will reveal the active node handling the query for that specific ISP route. If you are physically located in Hanoi, the terminal should return "node-north".

Measuring Latency Improvements

Use diagnostic tools like dnsping or multi-location monitoring services within Vietnam to observe resolution latency. A properly configured Anycast setup on local budget VPS instances can drop DNS resolution times from an average of 80ms - 150ms (when using overseas servers) down to a staggering 2ms - 15ms locally.

User Location Traditional Unicast DNS (Overseas) Optimized 3-VPS Anycast DNS
Hanoi 92 ms 4 ms
Da Nang 114 ms 12 ms
Ho Chi Minh City 78 ms 5 ms
---

Conclusion: Enterprise Performance on a Bootstrapped Budget

Building an advanced Anycast DNS infrastructure is no longer exclusive to tech giants and high-budget enterprises. By combining the efficiency of Knot DNS, the precision of GeoIP database filtering, and the raw routing capability of BIRD via BGP on just three cheap VPS instances, you can build a resilient network infrastructure tailored specifically for the Vietnamese digital landscape.

The benefits are immediate: reduced time-to-first-byte (TTFB) for your web applications, higher resilience against regional network fiber cuts, and a measurably smoother experience for your digital audience. Start small, monitor your routing tables closely, and unlock enterprise-grade network performance today.

Optimizing Domain Resolution in Vietnam: A Guide to Anycast DNS with Knot DNS and GeoIP on 3 Cheap VPS | DPTCloud