Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #194895 > unrolled thread

DNS server won't talk to me

Started byFrancois Gouget <fgouget@free.fr>
First post2018-04-20 01:50 +0200
Last post2018-04-25 12:00 +0200
Articles 8 — 4 participants

Back to article view | Back to linux.debian.user


Contents

  DNS server won't talk to me Francois Gouget <fgouget@free.fr> - 2018-04-20 01:50 +0200
    Re: DNS server won't talk to me Bob Weber <bobrweber@gmail.com> - 2018-04-20 02:10 +0200
    Re: DNS server won't talk to me Glenn English <ghe2001@gmail.com> - 2018-04-20 02:20 +0200
      Re: DNS server won't talk to me Francois Gouget <fgouget@free.fr> - 2018-04-20 13:00 +0200
        Re: DNS server won't talk to me Greg Wooledge <wooledg@eeg.ccf.org> - 2018-04-20 15:00 +0200
        Re: DNS server won't talk to me Glenn English <ghe2001@gmail.com> - 2018-04-20 17:10 +0200
          Re: DNS server won't talk to me Greg Wooledge <wooledg@eeg.ccf.org> - 2018-04-20 17:30 +0200
            Re: DNS server won't talk to me Francois Gouget <fgouget@free.fr> - 2018-04-25 12:00 +0200

#194895 — DNS server won't talk to me

FromFrancois Gouget <fgouget@free.fr>
Date2018-04-20 01:50 +0200
SubjectDNS server won't talk to me
Message-ID<vGrtn-7PS-1@gated-at.bofh.it>
So I'm running a bind server and while it works I ran into a domain name 
that it refuses to resolve: maibokun.com.

Digging into it, it looks like one DNS server is refusing to talk to me:

On my box:
$ host maibokun.com
;; connection timed out; no servers could be reached
$ host maibokun.com 210.143.111.171
;; connection timed out; no servers could be reached

Same thing on my laptop. But if I connect the laptop to another Wifi 
network (thus changing it public IP address) or run the command on a 
computer on the other side of the atlantic I get:

$ host maibokun.com
maibokun.com has address 210.188.220.102
maibokun.com mail is handled by 10 mail.maibokun.com.
$ host maibokun.com 210.143.111.171
Using domain server:
Name: 210.143.111.171
Address: 210.143.111.171#53
Aliases: 

maibokun.com has address 210.188.220.102
maibokun.com mail is handled by 10 mail.maibokun.com.


Are DNS servers banning queries from some residential addresses or 
something like this? Anyone else seeing the same issue?


-- 
Francois Gouget <fgouget@free.fr>              http://fgouget.free.fr/
                  Hell is empty and all the devils are here.
                       -- Wm. Shakespeare, "The Tempest"

[toc] | [next] | [standalone]


#194896

FromBob Weber <bobrweber@gmail.com>
Date2018-04-20 02:10 +0200
Message-ID<vGrMJ-8do-3@gated-at.bofh.it>
In reply to#194895

[Multipart message — attachments visible in raw view] — view raw

On 4/19/18 7:44 PM, Francois Gouget wrote:
> So I'm running a bind server and while it works I ran into a domain name
> that it refuses to resolve: maibokun.com.
>
> Digging into it, it looks like one DNS server is refusing to talk to me:
>
> On my box:
> $ host maibokun.com
> ;; connection timed out; no servers could be reached
> $ host maibokun.com 210.143.111.171
> ;; connection timed out; no servers could be reached
>
> Same thing on my laptop. But if I connect the laptop to another Wifi
> network (thus changing it public IP address) or run the command on a
> computer on the other side of the atlantic I get:
>
> $ host maibokun.com
> maibokun.com has address 210.188.220.102
> maibokun.com mail is handled by 10 mail.maibokun.com.
> $ host maibokun.com 210.143.111.171
> Using domain server:
> Name: 210.143.111.171
> Address: 210.143.111.171#53
> Aliases:
>
> maibokun.com has address 210.188.220.102
> maibokun.com mail is handled by 10 mail.maibokun.com.
>
>
> Are DNS servers banning queries from some residential addresses or
> something like this? Anyone else seeing the same issue?
>
>
Try having bind forward the requests to another public DNS server like opendns.  
You could even protect yourself by having opendns block malware and other bad 
sites.   My bind named.conf.options file has the forwarding setup like this.

         forwarders {
         // opendns
         //        208.67.222.222;
         //        208.67.220.220;
         127.0.2.1;
         };
         forward only;

If you are really worried that your DNS queries are being diverted by man in the 
middle attacks use dnscrypt-proxy.  I have dnscrypt-proxy listening on 127.0.2.1 
(as above shows) and forwarding bind's DNS queries to opendns (cisco) over a 
secure channel.  I even redirect all DNS (port 53 udp) queries to any server to 
my bind with a shorewall redirect rule (firewall).

This setup returns this from a host command:

host  maibokun.com
maibokun.com has address 210.188.220.102
maibokun.com mail is handled by 10 mail.maibokun.com.


-- 


*...Bob*

[toc] | [prev] | [next] | [standalone]


#194898

FromGlenn English <ghe2001@gmail.com>
Date2018-04-20 02:20 +0200
Message-ID<vGrWp-8hj-3@gated-at.bofh.it>
In reply to#194895
On Thu, Apr 19, 2018 at 11:44 PM, Francois Gouget <fgouget@free.fr> wrote:

> Are DNS servers banning queries from some residential addresses or
> something like this?

I'm banning some, off and on, (I see massive hits from all over the
globe on my DNS server -- ~100K hits a day above my rate limit). Have
you tried to ping that unresponsive one to see if it's alive? Or a TCP
Telnet connection to its port 53? Is it possible that you've exceeded
their rate limit?

-- 
Glenn English

[toc] | [prev] | [next] | [standalone]


#194902

FromFrancois Gouget <fgouget@free.fr>
Date2018-04-20 13:00 +0200
Message-ID<vGBVM-6y1-3@gated-at.bofh.it>
In reply to#194898
On Fri, 20 Apr 2018, Glenn English wrote:

> On Thu, Apr 19, 2018 at 11:44 PM, Francois Gouget <fgouget@free.fr> wrote:
> 
> > Are DNS servers banning queries from some residential addresses or
> > something like this?
> 
> I'm banning some, off and on, (I see massive hits from all over the
> globe on my DNS server -- ~100K hits a day above my rate limit). Have
> you tried to ping that unresponsive one to see if it's alive? Or a TCP
> Telnet connection to its port 53?

Indeed I cannot ping their DNS server (210.143.111.171) but I just 
thought they blocked ICMP. However I noticed I can in fact ping it from 
another host so I did a traceroute and the packets get blocked at the 
penultimate hop:

$ traceroute -n 210.143.111.171    
traceroute to 210.143.111.171 (210.143.111.171), 30 hops max, 60 byte packets
[...]
21  60.37.54.202  296.022 ms 60.37.54.198  278.166 ms 122.1.245.126  274.472 ms
22  122.1.246.106  270.430 ms  275.228 ms 122.1.246.110  277.430 ms
23  211.0.221.30  273.257 ms  279.265 ms  277.767 ms
24  * * *

On the other host the traceroute finishes with:

19  60.37.54.202  158.630 ms 122.1.245.130  161.021 ms 122.1.245.126  154.684 ms
20  122.1.246.110  147.979 ms 122.1.246.106  149.896 ms 122.1.246.110  155.476 ms
21  211.0.221.30  156.153 ms  144.694 ms  148.812 ms
22  210.143.111.171  156.433 ms  156.363 ms  159.304 ms


> Is it possible that you've exceeded their rate limit?

I have a script that would try to resolve the maibokun.com hostname once 
a day and the TTL on that appears to be 83334. So I would end up 
accessing their name server once a day. Of course now that it's not 
working and I have tried to figure out what's going on it's been quite a 
bit more.


-- 
Francois Gouget <fgouget@free.fr>              http://fgouget.free.fr/
May your Tongue stick to the Roof of your Mouth with the Force of a Thousand Caramels.

[toc] | [prev] | [next] | [standalone]


#194904

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2018-04-20 15:00 +0200
Message-ID<vGDNT-7Ku-7@gated-at.bofh.it>
In reply to#194902
On Fri, Apr 20, 2018 at 12:50:16PM +0200, Francois Gouget wrote:
> Indeed I cannot ping their DNS server (210.143.111.171) but I just 
> thought they blocked ICMP. However I noticed I can in fact ping it from 
> another host so I did a traceroute and the packets get blocked at the 
> penultimate hop:

That sounds like their Internet Service Provider may have blocked packets
from your subnet due to a denial of service attack, or spam, or similar
perceived malicious acts.

Or, it could be an accidental misconfiguration of a router.  (Theirs,
not yours.)

[toc] | [prev] | [next] | [standalone]


#194906

FromGlenn English <ghe2001@gmail.com>
Date2018-04-20 17:10 +0200
Message-ID<vGFPH-Rb-9@gated-at.bofh.it>
In reply to#194902
On Fri, Apr 20, 2018 at 10:50 AM, Francois Gouget <fgouget@free.fr> wrote:

> Indeed I cannot ping their DNS server (210.143.111.171) but I just
> thought they blocked ICMP. However I noticed I can in fact ping it from
> another host so I did a traceroute and the packets get blocked at the
> penultimate hop:
>
> $ traceroute -n 210.143.111.171

That IP, according to whois, is in Japan. And those latency numbers a
pretty big. Have you considered using a different DNS?

I just pinged them, and my numbers are also pretty big (143ms), from
Boulder, CO, USA. My latency to the Google DNS server (8.8.8.8) is a
bit under 10ms.

-- 
Glenn English

[toc] | [prev] | [next] | [standalone]


#194907

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2018-04-20 17:30 +0200
Message-ID<vGG93-XO-1@gated-at.bofh.it>
In reply to#194906
On Fri, Apr 20, 2018 at 03:03:22PM +0000, Glenn English wrote:
> On Fri, Apr 20, 2018 at 10:50 AM, Francois Gouget <fgouget@free.fr> wrote:
> 
> > Indeed I cannot ping their DNS server (210.143.111.171) but I just
> > thought they blocked ICMP. However I noticed I can in fact ping it from
> > another host so I did a traceroute and the packets get blocked at the
> > penultimate hop:
> >
> > $ traceroute -n 210.143.111.171
> 
> That IP, according to whois, is in Japan. And those latency numbers a
> pretty big. Have you considered using a different DNS?

You misunderstand.  That's not the resolver that Francois is using.
It's the authoritative name server for the domain he's trying to resolve
(maibokun.com).

wooledg:~$ dig NS maibokun.com
[...]
;; ANSWER SECTION:
maibokun.com.           86400   IN      NS      ns3.fas.jp.
maibokun.com.           86400   IN      NS      ns.maibokun.com.

;; ADDITIONAL SECTION:
ns.maibokun.com.        163881  IN      A       210.143.111.171
ns3.fas.jp.             77481   IN      A       210.143.111.241
[...]


As a *workaround*, sure, he could use a public resolver like Google's
8.8.8.8 as a sort of "proxy" that the Japanese name server is willing
to talk to.  But short of that, he is completely cut off by the
router on the Japanese end.

[toc] | [prev] | [next] | [standalone]


#195062

FromFrancois Gouget <fgouget@free.fr>
Date2018-04-25 12:00 +0200
Message-ID<vIpnr-42U-5@gated-at.bofh.it>
In reply to#194907
On Fri, 20 Apr 2018, Greg Wooledge wrote:
[...]
> You misunderstand.  That's not the resolver that Francois is using.
> It's the authoritative name server for the domain he's trying to resolve
> (maibokun.com).
[...]
> As a *workaround*, sure, he could use a public resolver like Google's
> 8.8.8.8 as a sort of "proxy" that the Japanese name server is willing
> to talk to.  But short of that, he is completely cut off by the
> router on the Japanese end.

Yep. So much for the Internet being a peer-to-peer network :-(

So in the end I configured things to go through a public resolver (but 
not Google). And while I was at it I installed dnscrypt-proxy (which was 
in the news recently and which Bob Weber also mentioned).


-- 
Francois Gouget <fgouget@free.fr>              http://fgouget.free.fr/
                              145 = 1! + 4! + 5!

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web