Solved

DNS trace

Posted on 2014-02-11
11
411 Views
Last Modified: 2014-05-24
Hi Team,

I am unable to see the DNS query in the wireshark trace , i tried deleting the cache , tried nslookup and also the browser.. Its the same issue,, no matter what i do i get the only response message in the DNS wireshark trace ,, it never captures the query message .. Also i dont see the reference part for packet number for query message of the DNS.. Let me know if there is any suggestion.

Regards..
0
Comment
Question by:xyz abc
  • 7
  • 3
11 Comments
 
LVL 18

Expert Comment

by:LesterClayton
ID: 39852554
Check the following:

Do you have any filters on?
Are you capturing the correct network interface?
Have you tried capturing all network interfaces simultaneously?

Using a capture fulter of "port 53" will capture DNS queries both ways.  Here is a sample trace when I ran "nslookup google.co.uk"

Nslookup google.co.uk
Tip: you can also specify a DNS server to query - try do this while running a capture:
nslookup google.co.uk 8.8.8.8

Open in new window


This will force your query to go to Google's public DNS server at 8.8.8.8
0
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 39852559
0
 

Author Comment

by:xyz abc
ID: 39852611
Do you have any filters on?

---- No
Are you capturing the correct network interface?

Yes, I tried All Interfaces.

Have you tried capturing all network interfaces simultaneously?

Yes

I tried DNS, tcp.port==53 , udp.port==53

I tried for other websites internally in office i can see the query message part, But from internet i dont see the "Query Message " and under the packet there is no reference of packet number in query Response. So basically i see only Query responses no Queries captured in Wireshark.....

I cannot point this to google DNS since we have GSLB in picture the whole point of testing will be gone......

Not sure of this weird behavior.....
0
Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

 
LVL 18

Expert Comment

by:LesterClayton
ID: 39852613
I want to remind you that capture filters and display filters are two different kinds of filters.

Please try to capture all packets with a filter of "port 53", and do not use a display filter.

The purpose of testing against Google's DNS is to help troubleshoot your wireshark problems - it's not there to replace your existing DNS infrastructure.   What I'm trying to get working is your ability to do Wireshark traces, not to test your GSLB infrastructure.
0
 

Author Comment

by:xyz abc
ID: 39852614
Ok Thanks Lester, I agree my point here is when the wireshark can capture the same queries sometimes and it doesnot sometimes... So i dont know if that is something wrong with wireshark.....
0
 

Author Comment

by:xyz abc
ID: 39852620
I think its working.. My Apologies .... I think its capture filters..... i will confirm in sometime...

Thanks Lester.....
0
 
LVL 18

Expert Comment

by:LesterClayton
ID: 39852621
Good to hear :)

Wireshark doesn't have the ability to "choose" what kind of traffic to capture.  It captures what you tell it to capture, and what the WinPCap Driver can see.  

If you have a network infrastrucutre for example which uses 802.1x or IPSEC to communicate with certain servers - like your domain controllers (and subsequently, DNS), then you won't be able to use wireshark effectively, because most if not all of your traffic will be encyrpted, and undecipherable.  Perhaps this is what you are experiencing?
0
 

Author Comment

by:xyz abc
ID: 39852655
Its looks like the same issue when i try from Internet... But it works from my office network... From internet No Query messages only responses....
0
 

Author Comment

by:xyz abc
ID: 39855364
Does anyone what is going on.... ? I have the same issue even after setting the capture filter to port 53 as well no go...... And its only from internet.. when i try the same from office network it works perfectly fine... Any Wireshark DNS experts to help me.... ?
0
 

Accepted Solution

by:
xyz abc earned 0 total points
ID: 40076905
It seems to be some issue on our external DNS
0
 

Author Closing Comment

by:xyz abc
ID: 40088090
Actually it never got fixed
0

Featured Post

Webinar: Aligning, Automating, Winning

Join Dan Russo, Senior Manager of Operations Intelligence, for an in-depth discussion on how Dealertrack, leading provider of integrated digital solutions for the automotive industry, transformed their DevOps processes to increase collaboration and move with greater velocity.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is in response to a question (http://www.experts-exchange.com/Networking/Network_Management/Network_Analysis/Q_28230497.html) here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
Are you one of those front-line IT Service Desk staff fielding calls, replying to emails, all-the-while working to resolve end-user technological nightmares? I am! That's why I have put together this brief overview of tools and techniques I use in o…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question