Solved

DNS trace

Posted on 2014-02-11
11
398 Views
Last Modified: 2014-05-24
Hi Team,

I am unable to see the DNS query in the wireshark trace , i tried deleting the cache , tried nslookup and also the browser.. Its the same issue,, no matter what i do i get the only response message in the DNS wireshark trace ,, it never captures the query message .. Also i dont see the reference part for packet number for query message of the DNS.. Let me know if there is any suggestion.

Regards..
0
Comment
Question by:xyz abc
  • 7
  • 3
11 Comments
 
LVL 17

Expert Comment

by:LesterClayton
ID: 39852554
Check the following:

Do you have any filters on?
Are you capturing the correct network interface?
Have you tried capturing all network interfaces simultaneously?

Using a capture fulter of "port 53" will capture DNS queries both ways.  Here is a sample trace when I ran "nslookup google.co.uk"

Nslookup google.co.uk
Tip: you can also specify a DNS server to query - try do this while running a capture:
nslookup google.co.uk 8.8.8.8

Open in new window


This will force your query to go to Google's public DNS server at 8.8.8.8
0
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 39852559
0
 

Author Comment

by:xyz abc
ID: 39852611
Do you have any filters on?

---- No
Are you capturing the correct network interface?

Yes, I tried All Interfaces.

Have you tried capturing all network interfaces simultaneously?

Yes

I tried DNS, tcp.port==53 , udp.port==53

I tried for other websites internally in office i can see the query message part, But from internet i dont see the "Query Message " and under the packet there is no reference of packet number in query Response. So basically i see only Query responses no Queries captured in Wireshark.....

I cannot point this to google DNS since we have GSLB in picture the whole point of testing will be gone......

Not sure of this weird behavior.....
0
 
LVL 17

Expert Comment

by:LesterClayton
ID: 39852613
I want to remind you that capture filters and display filters are two different kinds of filters.

Please try to capture all packets with a filter of "port 53", and do not use a display filter.

The purpose of testing against Google's DNS is to help troubleshoot your wireshark problems - it's not there to replace your existing DNS infrastructure.   What I'm trying to get working is your ability to do Wireshark traces, not to test your GSLB infrastructure.
0
 

Author Comment

by:xyz abc
ID: 39852614
Ok Thanks Lester, I agree my point here is when the wireshark can capture the same queries sometimes and it doesnot sometimes... So i dont know if that is something wrong with wireshark.....
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 

Author Comment

by:xyz abc
ID: 39852620
I think its working.. My Apologies .... I think its capture filters..... i will confirm in sometime...

Thanks Lester.....
0
 
LVL 17

Expert Comment

by:LesterClayton
ID: 39852621
Good to hear :)

Wireshark doesn't have the ability to "choose" what kind of traffic to capture.  It captures what you tell it to capture, and what the WinPCap Driver can see.  

If you have a network infrastrucutre for example which uses 802.1x or IPSEC to communicate with certain servers - like your domain controllers (and subsequently, DNS), then you won't be able to use wireshark effectively, because most if not all of your traffic will be encyrpted, and undecipherable.  Perhaps this is what you are experiencing?
0
 

Author Comment

by:xyz abc
ID: 39852655
Its looks like the same issue when i try from Internet... But it works from my office network... From internet No Query messages only responses....
0
 

Author Comment

by:xyz abc
ID: 39855364
Does anyone what is going on.... ? I have the same issue even after setting the capture filter to port 53 as well no go...... And its only from internet.. when i try the same from office network it works perfectly fine... Any Wireshark DNS experts to help me.... ?
0
 

Accepted Solution

by:
xyz abc earned 0 total points
ID: 40076905
It seems to be some issue on our external DNS
0
 

Author Closing Comment

by:xyz abc
ID: 40088090
Actually it never got fixed
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Suggested Solutions

Occasionally you run into the website or two that will not resolve properly using your own DNS servers.  Some people simply set up global forwarders for their DNS server.  I don’t recommend doing this because it can cause problems resolving addresse…
Trying to figure out group policy inheritance and which settings apply where can be a chore.  Here's a very simple summary I've written which might help.  Keep in mind, this is just a high-level conceptual overview where I try to avoid getting bogge…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now