Discussion:
Strange DNS behaviour
Xavier Humbert via bind-users
2021-05-09 10:32:01 UTC
Permalink
Hi,
; <<>> DiG 9.16.15 <<>> dns.google.com
;; global options: +cmd
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12276
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
; EDNS: version: 0, flags:; udp: 1232
; COOKIE: 7b606d7c32a99906010000006097b6d7f61894ea0a92dac2 (good)
;dns.google.com.                       
IN      A
dns.google.com.         880     IN      A      
8.8.4.4
dns.google.com.         880     IN      A      
8.8.8.8
;; Query time: 0 msec
;; SERVER: ::1#53(::1)
;; WHEN: Sun May 09 12:17:59 CEST 2021
;; MSG SIZE  rcvd: 103
On other hosts in my home, it works, too.
; (1 server found)
;; global options: +cmd
.                       518400  IN      NS
     m.root-servers.net.
.                       518400  IN      NS
     b.root-servers.net.
.                       518400  IN      NS
     e.root-servers.net.
.                       518400  IN      NS
     d.root-servers.net.
.                       518400  IN      NS
     h.root-servers.net.
.                       518400  IN      NS
     f.root-servers.net.
.                       518400  IN      NS
     g.root-servers.net.
.                       518400  IN      NS
     c.root-servers.net.
.                       518400  IN      NS
     i.root-servers.net.
.                       518400  IN      NS
     j.root-servers.net.
.                       518400  IN      NS
     k.root-servers.net.
.                       518400  IN      NS
     l.root-servers.net.
.                       518400  IN      NS
     a.root-servers.net.
.                       518400  IN
     RRSIG   NS 8 0 518400 20210521170000 20210508160000 14631
. IgUiqHrRXT5hTAa5wnubyCL0T9iq+iRAQIUQlIStRYqZh6Qp5W3sZLum
6O+EkYZALJda6RJwQY8oPEgQVQymGmGyAxcZBekX5vsMm8MgovQIA+Ev
SroSeV9yXDURHqt8af+25bw
6YyUQEOblPehxyUYYkF9cP8FlieAUw1Fn
HMvqpQlEn2sYS4UjA+euhcS2k7jnyEdBNbXbEZVq56zHK1aHPQIp2f4/
byHaC55zPJ5rgLwMUh+8JuP47wb4NWAKIj76EUlqcidfI8hxZI5KPoNZ
vmIcEtQSfRYqVxoc+BiEEgalw5afAmXjEtvJaWm4v5383uatiQ1s9AgC MPQFHw==
couldn't get address for 'm.root-servers.net': not found
None of the root servers can't be found. My root hint file is up to date.
GENERAL.DEVICE:                         enp10s0
                          ethernet
                        04:7D:7B:02:68:67
GENERAL.MTU:                            1500
GENERAL.STATE:                          100
(connected)
GENERAL.CONNECTION:                     Wired
                      /org/freedesktop/NetworkManager/ActiveConnection/3
WIRED-PROPERTIES.CARRIER:               on
                        192.168.100.25/24
                           192.168.100.254
IP4.ROUTE[1]:                           dst
= 0.0.0.0/0, nh = 192.168.100.254, mt = 100
IP4.ROUTE[2]:                           dst
= 192.168.100.0/24, nh = 0.0.0.0, mt = 100
IP4.ROUTE[3]:                           dst
= 169.254.0.0/16, nh = 0.0.0.0, mt = 1000
                            192.168.100.144
                            192.168.100.254
This is not an ACL problem, the whole subnet is allowed. Nmap and/or
telnet shows no blocked port problem

Trying on the secondary leads to the same behaviour

Eventually, I am lost.

Could anyone help ?

Thanks,

Regards

--
Xavier Humbert
CRT Supervision et Exploitation de Niveau 1
Rectorat de Nancy-Metz
03 83 86 27 39
Xavier Humbert via bind-users
2021-05-09 11:44:22 UTC
Permalink
Post by Xavier Humbert via bind-users
Hi,
; <<>> DiG 9.16.15 <<>> dns.google.com
;; global options: +cmd
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12276
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
; EDNS: version: 0, flags:; udp: 1232
; COOKIE: 7b606d7c32a99906010000006097b6d7f61894ea0a92dac2 (good)
;dns.google.com.                       
IN      A
dns.google.com.         880     IN     
A       8.8.4.4
dns.google.com.         880     IN     
A       8.8.8.8
;; Query time: 0 msec
;; SERVER: ::1#53(::1)
;; WHEN: Sun May 09 12:17:59 CEST 2021
;; MSG SIZE  rcvd: 103
On other hosts in my home, it works, too.
; (1 server found)
;; global options: +cmd
.                       518400  IN
     NS      m.root-servers.net.
.                       518400  IN
     NS      b.root-servers.net.
.                       518400  IN
     NS      e.root-servers.net.
.                       518400  IN
     NS      d.root-servers.net.
.                       518400  IN
     NS      h.root-servers.net.
.                       518400  IN
     NS      f.root-servers.net.
.                       518400  IN
     NS      g.root-servers.net.
.                       518400  IN
     NS      c.root-servers.net.
.                       518400  IN
     NS      i.root-servers.net.
.                       518400  IN
     NS      j.root-servers.net.
.                       518400  IN
     NS      k.root-servers.net.
.                       518400  IN
     NS      l.root-servers.net.
.                       518400  IN
     NS      a.root-servers.net.
.                       518400  IN
     RRSIG   NS 8 0 518400 20210521170000 20210508160000 14631
. IgUiqHrRXT5hTAa5wnubyCL0T9iq+iRAQIUQlIStRYqZh6Qp5W3sZLum
6O+EkYZALJda6RJwQY8oPEgQVQymGmGyAxcZBekX5vsMm8MgovQIA+Ev
SroSeV9yXDURHqt8af+25bw
6YyUQEOblPehxyUYYkF9cP8FlieAUw1Fn
HMvqpQlEn2sYS4UjA+euhcS2k7jnyEdBNbXbEZVq56zHK1aHPQIp2f4/
byHaC55zPJ5rgLwMUh+8JuP47wb4NWAKIj76EUlqcidfI8hxZI5KPoNZ
vmIcEtQSfRYqVxoc+BiEEgalw5afAmXjEtvJaWm4v5383uatiQ1s9AgC MPQFHw==
couldn't get address for 'm.root-servers.net': not found
None of the root servers can't be found. My root hint file is up to date.
GENERAL.DEVICE:                         enp10s0
                          ethernet
                        04:7D:7B:02:68:67
GENERAL.MTU:                            1500
GENERAL.STATE:                          100
(connected)
GENERAL.CONNECTION:                     Wired
                      /org/freedesktop/NetworkManager/ActiveConnection/3
WIRED-PROPERTIES.CARRIER:               on
                        192.168.100.25/24
                           192.168.100.254
IP4.ROUTE[1]:                           dst
= 0.0.0.0/0, nh = 192.168.100.254, mt = 100
IP4.ROUTE[2]:                           dst
= 192.168.100.0/24, nh = 0.0.0.0, mt = 100
IP4.ROUTE[3]:                           dst
= 169.254.0.0/16, nh = 0.0.0.0, mt = 1000
                            192.168.100.144
                            192.168.100.254
This is not an ACL problem, the whole subnet is allowed. Nmap and/or
telnet shows no blocked port problem
Trying on the secondary leads to the same behaviour
Eventually, I am lost.
Sorry for the disturbance, it was caused by faulty remnants of a VPN
connection. I fixed that in /etc/systemd/resolved.conf

Cheers

--
Xavier Humbert
CRT Supervision et Exploitation de Niveau 1
Rectorat de Nancy-Metz
03 83 86 27 39
Xavier Humbert via bind-users
2021-05-09 12:35:23 UTC
Permalink
Post by Xavier Humbert via bind-users
Hi,
; <<>> DiG 9.16.15 <<>> dns.google.com
;; global options: +cmd
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12276
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
; EDNS: version: 0, flags:; udp: 1232
; COOKIE: 7b606d7c32a99906010000006097b6d7f61894ea0a92dac2 (good)
;dns.google.com.                       
IN      A
dns.google.com.         880     IN     
A       8.8.4.4
dns.google.com.         880     IN     
A       8.8.8.8
;; Query time: 0 msec
;; SERVER: ::1#53(::1)
;; WHEN: Sun May 09 12:17:59 CEST 2021
;; MSG SIZE  rcvd: 103
On other hosts in my home, it works, too.
; (1 server found)
;; global options: +cmd
.                       518400  IN
     NS      m.root-servers.net.
.                       518400  IN
     NS      b.root-servers.net.
.                       518400  IN
     NS      e.root-servers.net.
.                       518400  IN
     NS      d.root-servers.net.
.                       518400  IN
     NS      h.root-servers.net.
.                       518400  IN
     NS      f.root-servers.net.
.                       518400  IN
     NS      g.root-servers.net.
.                       518400  IN
     NS      c.root-servers.net.
.                       518400  IN
     NS      i.root-servers.net.
.                       518400  IN
     NS      j.root-servers.net.
.                       518400  IN
     NS      k.root-servers.net.
.                       518400  IN
     NS      l.root-servers.net.
.                       518400  IN
     NS      a.root-servers.net.
.                       518400  IN
     RRSIG   NS 8 0 518400 20210521170000 20210508160000
14631 . IgUiqHrRXT5hTAa5wnubyCL0T9iq+iRAQIUQlIStRYqZh6Qp5W3sZLum
6O+EkYZALJda6RJwQY8oPEgQVQymGmGyAxcZBekX5vsMm8MgovQIA+Ev
SroSeV9yXDURHqt8af+25bw
6YyUQEOblPehxyUYYkF9cP8FlieAUw1Fn
HMvqpQlEn2sYS4UjA+euhcS2k7jnyEdBNbXbEZVq56zHK1aHPQIp2f4/
byHaC55zPJ5rgLwMUh+8JuP47wb4NWAKIj76EUlqcidfI8hxZI5KPoNZ
vmIcEtQSfRYqVxoc+BiEEgalw5afAmXjEtvJaWm4v5383uatiQ1s9AgC MPQFHw==
couldn't get address for 'm.root-servers.net': not found
None of the root servers can't be found. My root hint file is up to date.
GENERAL.DEVICE:                         enp10s0
                          ethernet
                        04:7D:7B:02:68:67
GENERAL.MTU:                            1500
GENERAL.STATE:                          100
(connected)
GENERAL.CONNECTION:                     Wired
                      /org/freedesktop/NetworkManager/ActiveConnection/3
WIRED-PROPERTIES.CARRIER:               on
                        192.168.100.25/24
                           192.168.100.254
                          dst = 0.0.0.0/0,
nh = 192.168.100.254, mt = 100
                          dst =
192.168.100.0/24, nh = 0.0.0.0, mt = 100
                          dst =
169.254.0.0/16, nh = 0.0.0.0, mt = 1000
                            192.168.100.144
                            192.168.100.254
This is not an ACL problem, the whole subnet is allowed. Nmap and/or
telnet shows no blocked port problem
Trying on the secondary leads to the same behaviour
Eventually, I am lost.
Sorry, typed too quickly. Problem stands.

--
Xavier Humbert
CRT Supervision et Exploitation de Niveau 1
Rectorat de Nancy-Metz
03 83 86 27 39
Matus UHLAR - fantomas
2021-05-09 14:37:58 UTC
Permalink
are you aware that +trace sends queries across the servers from root to
leaf, it doesn't go through the server numenor?
Post by Xavier Humbert via bind-users
Post by Xavier Humbert via bind-users
couldn't get address for 'm.root-servers.net': not found
None of the root servers can't be found. My root hint file is up to date.
Sorry, typed too quickly. Problem stands.
--
Matus UHLAR - fantomas, ***@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Linux is like a teepee: no Windows, no Gates and an apache inside...
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.


bind-users mailing list
bind-***@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users
Loading...