Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #194895 > unrolled thread
| Started by | Francois Gouget <fgouget@free.fr> |
|---|---|
| First post | 2018-04-20 01:50 +0200 |
| Last post | 2018-04-25 12:00 +0200 |
| Articles | 8 — 4 participants |
Back to article view | Back to linux.debian.user
DNS server won't talk to me Francois Gouget <fgouget@free.fr> - 2018-04-20 01:50 +0200
Re: DNS server won't talk to me Bob Weber <bobrweber@gmail.com> - 2018-04-20 02:10 +0200
Re: DNS server won't talk to me Glenn English <ghe2001@gmail.com> - 2018-04-20 02:20 +0200
Re: DNS server won't talk to me Francois Gouget <fgouget@free.fr> - 2018-04-20 13:00 +0200
Re: DNS server won't talk to me Greg Wooledge <wooledg@eeg.ccf.org> - 2018-04-20 15:00 +0200
Re: DNS server won't talk to me Glenn English <ghe2001@gmail.com> - 2018-04-20 17:10 +0200
Re: DNS server won't talk to me Greg Wooledge <wooledg@eeg.ccf.org> - 2018-04-20 17:30 +0200
Re: DNS server won't talk to me Francois Gouget <fgouget@free.fr> - 2018-04-25 12:00 +0200
| From | Francois Gouget <fgouget@free.fr> |
|---|---|
| Date | 2018-04-20 01:50 +0200 |
| Subject | DNS server won't talk to me |
| Message-ID | <vGrtn-7PS-1@gated-at.bofh.it> |
So I'm running a bind server and while it works I ran into a domain name
that it refuses to resolve: maibokun.com.
Digging into it, it looks like one DNS server is refusing to talk to me:
On my box:
$ host maibokun.com
;; connection timed out; no servers could be reached
$ host maibokun.com 210.143.111.171
;; connection timed out; no servers could be reached
Same thing on my laptop. But if I connect the laptop to another Wifi
network (thus changing it public IP address) or run the command on a
computer on the other side of the atlantic I get:
$ host maibokun.com
maibokun.com has address 210.188.220.102
maibokun.com mail is handled by 10 mail.maibokun.com.
$ host maibokun.com 210.143.111.171
Using domain server:
Name: 210.143.111.171
Address: 210.143.111.171#53
Aliases:
maibokun.com has address 210.188.220.102
maibokun.com mail is handled by 10 mail.maibokun.com.
Are DNS servers banning queries from some residential addresses or
something like this? Anyone else seeing the same issue?
--
Francois Gouget <fgouget@free.fr> http://fgouget.free.fr/
Hell is empty and all the devils are here.
-- Wm. Shakespeare, "The Tempest"
[toc] | [next] | [standalone]
| From | Bob Weber <bobrweber@gmail.com> |
|---|---|
| Date | 2018-04-20 02:10 +0200 |
| Message-ID | <vGrMJ-8do-3@gated-at.bofh.it> |
| In reply to | #194895 |
[Multipart message — attachments visible in raw view] — view raw
On 4/19/18 7:44 PM, Francois Gouget wrote:
> So I'm running a bind server and while it works I ran into a domain name
> that it refuses to resolve: maibokun.com.
>
> Digging into it, it looks like one DNS server is refusing to talk to me:
>
> On my box:
> $ host maibokun.com
> ;; connection timed out; no servers could be reached
> $ host maibokun.com 210.143.111.171
> ;; connection timed out; no servers could be reached
>
> Same thing on my laptop. But if I connect the laptop to another Wifi
> network (thus changing it public IP address) or run the command on a
> computer on the other side of the atlantic I get:
>
> $ host maibokun.com
> maibokun.com has address 210.188.220.102
> maibokun.com mail is handled by 10 mail.maibokun.com.
> $ host maibokun.com 210.143.111.171
> Using domain server:
> Name: 210.143.111.171
> Address: 210.143.111.171#53
> Aliases:
>
> maibokun.com has address 210.188.220.102
> maibokun.com mail is handled by 10 mail.maibokun.com.
>
>
> Are DNS servers banning queries from some residential addresses or
> something like this? Anyone else seeing the same issue?
>
>
Try having bind forward the requests to another public DNS server like opendns.
You could even protect yourself by having opendns block malware and other bad
sites. My bind named.conf.options file has the forwarding setup like this.
forwarders {
// opendns
// 208.67.222.222;
// 208.67.220.220;
127.0.2.1;
};
forward only;
If you are really worried that your DNS queries are being diverted by man in the
middle attacks use dnscrypt-proxy. I have dnscrypt-proxy listening on 127.0.2.1
(as above shows) and forwarding bind's DNS queries to opendns (cisco) over a
secure channel. I even redirect all DNS (port 53 udp) queries to any server to
my bind with a shorewall redirect rule (firewall).
This setup returns this from a host command:
host maibokun.com
maibokun.com has address 210.188.220.102
maibokun.com mail is handled by 10 mail.maibokun.com.
--
*...Bob*
[toc] | [prev] | [next] | [standalone]
| From | Glenn English <ghe2001@gmail.com> |
|---|---|
| Date | 2018-04-20 02:20 +0200 |
| Message-ID | <vGrWp-8hj-3@gated-at.bofh.it> |
| In reply to | #194895 |
On Thu, Apr 19, 2018 at 11:44 PM, Francois Gouget <fgouget@free.fr> wrote: > Are DNS servers banning queries from some residential addresses or > something like this? I'm banning some, off and on, (I see massive hits from all over the globe on my DNS server -- ~100K hits a day above my rate limit). Have you tried to ping that unresponsive one to see if it's alive? Or a TCP Telnet connection to its port 53? Is it possible that you've exceeded their rate limit? -- Glenn English
[toc] | [prev] | [next] | [standalone]
| From | Francois Gouget <fgouget@free.fr> |
|---|---|
| Date | 2018-04-20 13:00 +0200 |
| Message-ID | <vGBVM-6y1-3@gated-at.bofh.it> |
| In reply to | #194898 |
On Fri, 20 Apr 2018, Glenn English wrote: > On Thu, Apr 19, 2018 at 11:44 PM, Francois Gouget <fgouget@free.fr> wrote: > > > Are DNS servers banning queries from some residential addresses or > > something like this? > > I'm banning some, off and on, (I see massive hits from all over the > globe on my DNS server -- ~100K hits a day above my rate limit). Have > you tried to ping that unresponsive one to see if it's alive? Or a TCP > Telnet connection to its port 53? Indeed I cannot ping their DNS server (210.143.111.171) but I just thought they blocked ICMP. However I noticed I can in fact ping it from another host so I did a traceroute and the packets get blocked at the penultimate hop: $ traceroute -n 210.143.111.171 traceroute to 210.143.111.171 (210.143.111.171), 30 hops max, 60 byte packets [...] 21 60.37.54.202 296.022 ms 60.37.54.198 278.166 ms 122.1.245.126 274.472 ms 22 122.1.246.106 270.430 ms 275.228 ms 122.1.246.110 277.430 ms 23 211.0.221.30 273.257 ms 279.265 ms 277.767 ms 24 * * * On the other host the traceroute finishes with: 19 60.37.54.202 158.630 ms 122.1.245.130 161.021 ms 122.1.245.126 154.684 ms 20 122.1.246.110 147.979 ms 122.1.246.106 149.896 ms 122.1.246.110 155.476 ms 21 211.0.221.30 156.153 ms 144.694 ms 148.812 ms 22 210.143.111.171 156.433 ms 156.363 ms 159.304 ms > Is it possible that you've exceeded their rate limit? I have a script that would try to resolve the maibokun.com hostname once a day and the TTL on that appears to be 83334. So I would end up accessing their name server once a day. Of course now that it's not working and I have tried to figure out what's going on it's been quite a bit more. -- Francois Gouget <fgouget@free.fr> http://fgouget.free.fr/ May your Tongue stick to the Roof of your Mouth with the Force of a Thousand Caramels.
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2018-04-20 15:00 +0200 |
| Message-ID | <vGDNT-7Ku-7@gated-at.bofh.it> |
| In reply to | #194902 |
On Fri, Apr 20, 2018 at 12:50:16PM +0200, Francois Gouget wrote: > Indeed I cannot ping their DNS server (210.143.111.171) but I just > thought they blocked ICMP. However I noticed I can in fact ping it from > another host so I did a traceroute and the packets get blocked at the > penultimate hop: That sounds like their Internet Service Provider may have blocked packets from your subnet due to a denial of service attack, or spam, or similar perceived malicious acts. Or, it could be an accidental misconfiguration of a router. (Theirs, not yours.)
[toc] | [prev] | [next] | [standalone]
| From | Glenn English <ghe2001@gmail.com> |
|---|---|
| Date | 2018-04-20 17:10 +0200 |
| Message-ID | <vGFPH-Rb-9@gated-at.bofh.it> |
| In reply to | #194902 |
On Fri, Apr 20, 2018 at 10:50 AM, Francois Gouget <fgouget@free.fr> wrote: > Indeed I cannot ping their DNS server (210.143.111.171) but I just > thought they blocked ICMP. However I noticed I can in fact ping it from > another host so I did a traceroute and the packets get blocked at the > penultimate hop: > > $ traceroute -n 210.143.111.171 That IP, according to whois, is in Japan. And those latency numbers a pretty big. Have you considered using a different DNS? I just pinged them, and my numbers are also pretty big (143ms), from Boulder, CO, USA. My latency to the Google DNS server (8.8.8.8) is a bit under 10ms. -- Glenn English
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2018-04-20 17:30 +0200 |
| Message-ID | <vGG93-XO-1@gated-at.bofh.it> |
| In reply to | #194906 |
On Fri, Apr 20, 2018 at 03:03:22PM +0000, Glenn English wrote: > On Fri, Apr 20, 2018 at 10:50 AM, Francois Gouget <fgouget@free.fr> wrote: > > > Indeed I cannot ping their DNS server (210.143.111.171) but I just > > thought they blocked ICMP. However I noticed I can in fact ping it from > > another host so I did a traceroute and the packets get blocked at the > > penultimate hop: > > > > $ traceroute -n 210.143.111.171 > > That IP, according to whois, is in Japan. And those latency numbers a > pretty big. Have you considered using a different DNS? You misunderstand. That's not the resolver that Francois is using. It's the authoritative name server for the domain he's trying to resolve (maibokun.com). wooledg:~$ dig NS maibokun.com [...] ;; ANSWER SECTION: maibokun.com. 86400 IN NS ns3.fas.jp. maibokun.com. 86400 IN NS ns.maibokun.com. ;; ADDITIONAL SECTION: ns.maibokun.com. 163881 IN A 210.143.111.171 ns3.fas.jp. 77481 IN A 210.143.111.241 [...] As a *workaround*, sure, he could use a public resolver like Google's 8.8.8.8 as a sort of "proxy" that the Japanese name server is willing to talk to. But short of that, he is completely cut off by the router on the Japanese end.
[toc] | [prev] | [next] | [standalone]
| From | Francois Gouget <fgouget@free.fr> |
|---|---|
| Date | 2018-04-25 12:00 +0200 |
| Message-ID | <vIpnr-42U-5@gated-at.bofh.it> |
| In reply to | #194907 |
On Fri, 20 Apr 2018, Greg Wooledge wrote:
[...]
> You misunderstand. That's not the resolver that Francois is using.
> It's the authoritative name server for the domain he's trying to resolve
> (maibokun.com).
[...]
> As a *workaround*, sure, he could use a public resolver like Google's
> 8.8.8.8 as a sort of "proxy" that the Japanese name server is willing
> to talk to. But short of that, he is completely cut off by the
> router on the Japanese end.
Yep. So much for the Internet being a peer-to-peer network :-(
So in the end I configured things to go through a public resolver (but
not Google). And while I was at it I installed dnscrypt-proxy (which was
in the news recently and which Bob Weber also mentioned).
--
Francois Gouget <fgouget@free.fr> http://fgouget.free.fr/
145 = 1! + 4! + 5!
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web