Post by Wietse MuizelaarEnige wat ik nog zou kunnen verzinnen is met wireshark/tcpdump
meespieken wat er op de lijn gebeurt aan DNS-verkeer...
Hm, ik ben hier niet bijster in thuis ... dus maar de hele dump van de dig-
opdracht vanaf de client:
$ dig www.laptopjacks.co.uk @ns195.websitewelcome.com
; <<>> DiG 9.5.0-P1 <<>> www.laptopjacks.co.uk @ns195.websitewelcome.com
;; global options: printcmd
;; connection timed out; no servers could be reached
En dit geeft het volgende te zien op de firewall (eth1 is de WAN-interface):
# tcpdump -i eth1
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes
15:20:38.495388 IP hedgehog.linetec.nl.ipp > 255-55.bbned.dsl.internl.net.ipp: UDP, length 169
15:20:38.497628 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 486+ PTR? 255.55.254.92.in-addr.arpa. (44)
15:20:38.512542 IP vlan83.newxr2.nik-asd.internl.net > hedgehog.linetec.nl: ICMP host 255-55.bbned.dsl.internl.net unreachable, length 36
15:20:38.519665 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 486 1/2/2 (164)
15:20:38.520776 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 40809+ PTR? 6.192.149.217.in-addr.arpa. (44)
15:20:38.542889 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 40809 1/2/2 (157)
15:20:38.543702 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 9574+ PTR? 133.196.149.217.in-addr.arpa. (46)
15:20:38.567746 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 9574 1/2/2 (171)
15:20:43.494592 arp who-has 1-48.bbned.dsl.internl.net tell hedgehog.linetec.nl
15:20:43.496439 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 24291+ PTR? 1.48.254.92.in-addr.arpa. (42)
15:20:43.510644 arp reply 1-48.bbned.dsl.internl.net is-at 00:13:19:bd:a6:a8 (oui Unknown)
15:20:43.518996 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 24291 1/2/2 PTR[|domain]
15:20:54.882818 IP hedgehog.linetec.nl.10359 > ferrari.websitewelcome.com.domain: 30543 [1au] AAAA? ns195.websitewelcome.com. (53)
15:20:54.883684 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 45672+ PTR? 176.54.18.67.in-addr.arpa. (43)
15:20:55.031431 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 45672 1/2/8 (257)
15:21:05.944865 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 18679+ PTR? 59.37.247.121.in-addr.arpa. (44)
15:21:05.967079 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 18679 1/2/2 (180)
15:21:06.371624 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 15012+ PTR? 59.37.247.121.in-addr.arpa. (44)
15:21:06.394047 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 15012 1/2/2 (180)
15:21:06.394886 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 21285+[|domain]
15:21:06.686952 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 21285 NXDomain[|domain]
15:21:06.687553 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 22176+[|domain]
15:21:06.709403 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 22176 NXDomain[|domain]
15:21:06.888533 IP hedgehog.linetec.nl.27076 > b1.36.1243.static.theplanet.com.domain: 4615 [1au] AAAA? ns195.websitewelcome.com. (53)
15:21:06.889315 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 3766+ PTR? 177.54.18.67.in-addr.arpa. (43)
15:21:07.036629 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 3766 1/2/8 (252)
15:21:09.496398 IP hedgehog.linetec.nl.ipp > 255-55.bbned.dsl.internl.net.ipp: UDP, length 169
15:21:09.513428 IP vlan83.newxr2.nik-asd.internl.net > hedgehog.linetec.nl: ICMP host 255-55.bbned.dsl.internl.net unreachable, length 36
15:21:14.882303 IP hedgehog.linetec.nl.43734 > bugatti.websitewelcome.com.domain: 19492+ A? www.laptopjacks.co.uk. (39)
15:21:14.882955 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 32789+ PTR? 130.90.87.70.in-addr.arpa. (43)
15:21:15.030474 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 32789 1/2/8 (257)
15:21:18.894147 IP hedgehog.linetec.nl.38557 > ferrari.websitewelcome.com.domain: 49181 [1au] AAAA? ns195.websitewelcome.com. (53)
15:21:18.896960 IP hedgehog.linetec.nl.13224 > h.root-servers.net.domain: 63488% [1au] AAAA? ns1.websitewelcome.com. (51)
15:21:18.898550 IP hedgehog.linetec.nl.50779 > h.root-servers.net.domain: 60614% [1au] AAAA? ns2.websitewelcome.com. (51)
15:21:18.899484 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 336+ PTR? 53.2.63.128.in-addr.arpa. (42)
15:21:18.997484 IP h.root-servers.net.domain > hedgehog.linetec.nl.13224: 63488- 0/13/16 (539)
15:21:18.998932 IP h.root-servers.net.domain > hedgehog.linetec.nl.50779: 60614- 0/13/16 (539)
15:21:19.002068 IP hedgehog.linetec.nl.50523 > h.gtld-servers.net.domain: 52824% [1au] AAAA? ns1.websitewelcome.com. (51)
15:21:19.005697 IP hedgehog.linetec.nl.63693 > h.gtld-servers.net.domain: 9995% [1au] AAAA? ns2.websitewelcome.com. (51)
15:21:19.022758 IP h.gtld-servers.net.domain > hedgehog.linetec.nl.50523: 52824- 0/2/3 (115)
15:21:19.024869 IP hedgehog.linetec.nl.52380 > ferrari.websitewelcome.com.domain: 14684% [1au] AAAA? ns1.websitewelcome.com. (51)
15:21:19.026704 IP h.gtld-servers.net.domain > hedgehog.linetec.nl.63693: 9995- 0/2/3 (115)
15:21:19.028611 IP hedgehog.linetec.nl.64548 > ferrari.websitewelcome.com.domain: 61816% [1au] AAAA? ns2.websitewelcome.com. (51)
15:21:19.191832 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 336 1/3/0 PTR[|domain]
15:21:19.192892 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 36513+ PTR? 30.112.54.192.in-addr.arpa. (44)
15:21:19.394637 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 36513 1/7/7 (316)
15:21:19.883077 IP hedgehog.linetec.nl.43734 > bugatti.websitewelcome.com.domain: 19492+ A? www.laptopjacks.co.uk. (39)
15:21:24.884075 IP hedgehog.linetec.nl.43734 > bugatti.websitewelcome.com.domain: 19492+ A? www.laptopjacks.co.uk. (39)
15:21:32.029869 IP hedgehog.linetec.nl.46867 > b1.36.1243.static.theplanet.com.domain: 51239% [1au] AAAA? ns1.websitewelcome.com. (51)
15:21:32.031444 IP hedgehog.linetec.nl.23578 > b1.36.1243.static.theplanet.com.domain: 12427% [1au] AAAA? ns2.websitewelcome.com. (51)
15:21:37.029207 arp who-has 1-48.bbned.dsl.internl.net tell hedgehog.linetec.nl
15:21:37.085012 arp reply 1-48.bbned.dsl.internl.net is-at 00:13:19:bd:a6:a8 (oui Unknown)
15:21:40.498460 IP hedgehog.linetec.nl.ipp > 255-55.bbned.dsl.internl.net.ipp: UDP, length 169
15:21:40.515839 IP vlan83.newxr2.nik-asd.internl.net > hedgehog.linetec.nl: ICMP host 255-55.bbned.dsl.internl.net unreachable, length 36
15:21:45.035058 IP hedgehog.linetec.nl.34390 > ferrari.websitewelcome.com.domain: 9876% [1au] AAAA? ns1.websitewelcome.com. (51)
15:21:45.036387 IP hedgehog.linetec.nl.63736 > ferrari.websitewelcome.com.domain: 2839% [1au] AAAA? ns2.websitewelcome.com. (51)
15:21:49.174724 IP hedgehog.linetec.nl.4734 > resolve20.dns.internl.net.domain: 7534+ PTR? 215.88.95.82.in-addr.arpa. (43)
15:21:49.197564 IP resolve20.dns.internl.net.domain > hedgehog.linetec.nl.4734: 7534 1/2/2 (138)
15:22:11.499440 IP hedgehog.linetec.nl.ipp > 255-55.bbned.dsl.internl.net.ipp: UDP, length 169
15:22:11.516265 IP vlan83.newxr2.nik-asd.internl.net > hedgehog.linetec.nl: ICMP host 255-55.bbned.dsl.internl.net unreachable, length 36
Enig idee wat dit zegt over wat er fout gaat?
Richard Rasker
--
http://www.linetec.nl