[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

DNS trace

Posted on 2014-02-11
11
Medium Priority
?
428 Views
Last Modified: 2014-05-24
Hi Team,

I am unable to see the DNS query in the wireshark trace , i tried deleting the cache , tried nslookup and also the browser.. Its the same issue,, no matter what i do i get the only response message in the DNS wireshark trace ,, it never captures the query message .. Also i dont see the reference part for packet number for query message of the DNS.. Let me know if there is any suggestion.

Regards..
0
Comment
Question by:xyz abc
  • 7
  • 3
11 Comments
 
LVL 18

Expert Comment

by:LesterClayton
ID: 39852554
Check the following:

Do you have any filters on?
Are you capturing the correct network interface?
Have you tried capturing all network interfaces simultaneously?

Using a capture fulter of "port 53" will capture DNS queries both ways.  Here is a sample trace when I ran "nslookup google.co.uk"

Nslookup google.co.uk
Tip: you can also specify a DNS server to query - try do this while running a capture:
nslookup google.co.uk 8.8.8.8

Open in new window


This will force your query to go to Google's public DNS server at 8.8.8.8
0
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 39852559
0
 

Author Comment

by:xyz abc
ID: 39852611
Do you have any filters on?

---- No
Are you capturing the correct network interface?

Yes, I tried All Interfaces.

Have you tried capturing all network interfaces simultaneously?

Yes

I tried DNS, tcp.port==53 , udp.port==53

I tried for other websites internally in office i can see the query message part, But from internet i dont see the "Query Message " and under the packet there is no reference of packet number in query Response. So basically i see only Query responses no Queries captured in Wireshark.....

I cannot point this to google DNS since we have GSLB in picture the whole point of testing will be gone......

Not sure of this weird behavior.....
0
Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

 
LVL 18

Expert Comment

by:LesterClayton
ID: 39852613
I want to remind you that capture filters and display filters are two different kinds of filters.

Please try to capture all packets with a filter of "port 53", and do not use a display filter.

The purpose of testing against Google's DNS is to help troubleshoot your wireshark problems - it's not there to replace your existing DNS infrastructure.   What I'm trying to get working is your ability to do Wireshark traces, not to test your GSLB infrastructure.
0
 

Author Comment

by:xyz abc
ID: 39852614
Ok Thanks Lester, I agree my point here is when the wireshark can capture the same queries sometimes and it doesnot sometimes... So i dont know if that is something wrong with wireshark.....
0
 

Author Comment

by:xyz abc
ID: 39852620
I think its working.. My Apologies .... I think its capture filters..... i will confirm in sometime...

Thanks Lester.....
0
 
LVL 18

Expert Comment

by:LesterClayton
ID: 39852621
Good to hear :)

Wireshark doesn't have the ability to "choose" what kind of traffic to capture.  It captures what you tell it to capture, and what the WinPCap Driver can see.  

If you have a network infrastrucutre for example which uses 802.1x or IPSEC to communicate with certain servers - like your domain controllers (and subsequently, DNS), then you won't be able to use wireshark effectively, because most if not all of your traffic will be encyrpted, and undecipherable.  Perhaps this is what you are experiencing?
0
 

Author Comment

by:xyz abc
ID: 39852655
Its looks like the same issue when i try from Internet... But it works from my office network... From internet No Query messages only responses....
0
 

Author Comment

by:xyz abc
ID: 39855364
Does anyone what is going on.... ? I have the same issue even after setting the capture filter to port 53 as well no go...... And its only from internet.. when i try the same from office network it works perfectly fine... Any Wireshark DNS experts to help me.... ?
0
 

Accepted Solution

by:
xyz abc earned 0 total points
ID: 40076905
It seems to be some issue on our external DNS
0
 

Author Closing Comment

by:xyz abc
ID: 40088090
Actually it never got fixed
0

Featured Post

Will You Be GDPR Compliant by 5/28/2018?

GDPR? That's a regulation for the European Union. But, if you collect data from customers or employees within the EU, then you need to know about GDPR and make sure your organization is compliant by May 2018. Check out our preparation checklist to make sure you're on track today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Configuring network clients can be a chore, especially if there are a large number of them or a lot of itinerant users.  DHCP dynamically manages this process, much to the relief of users and administrators alike!
This installment of Make It Better gives Media Temple customers the latest news, plugins, and tutorials to make their Grid shared hosting experience that much smoother.
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
There may be issues when you are trying to access Outlook or send & receive emails or due to Outlook crash which leads to corrupt or damaged PST file. To eliminate the corruption from your PST file, you need to repair the corrupt Outlook PST file. U…

612 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question