Solved

DNS trace

Posted on 2014-02-11
11
404 Views
Last Modified: 2014-05-24
Hi Team,

I am unable to see the DNS query in the wireshark trace , i tried deleting the cache , tried nslookup and also the browser.. Its the same issue,, no matter what i do i get the only response message in the DNS wireshark trace ,, it never captures the query message .. Also i dont see the reference part for packet number for query message of the DNS.. Let me know if there is any suggestion.

Regards..
0
Comment
Question by:xyz abc
  • 7
  • 3
11 Comments
 
LVL 18

Expert Comment

by:LesterClayton
ID: 39852554
Check the following:

Do you have any filters on?
Are you capturing the correct network interface?
Have you tried capturing all network interfaces simultaneously?

Using a capture fulter of "port 53" will capture DNS queries both ways.  Here is a sample trace when I ran "nslookup google.co.uk"

Nslookup google.co.uk
Tip: you can also specify a DNS server to query - try do this while running a capture:
nslookup google.co.uk 8.8.8.8

Open in new window


This will force your query to go to Google's public DNS server at 8.8.8.8
0
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 39852559
0
 

Author Comment

by:xyz abc
ID: 39852611
Do you have any filters on?

---- No
Are you capturing the correct network interface?

Yes, I tried All Interfaces.

Have you tried capturing all network interfaces simultaneously?

Yes

I tried DNS, tcp.port==53 , udp.port==53

I tried for other websites internally in office i can see the query message part, But from internet i dont see the "Query Message " and under the packet there is no reference of packet number in query Response. So basically i see only Query responses no Queries captured in Wireshark.....

I cannot point this to google DNS since we have GSLB in picture the whole point of testing will be gone......

Not sure of this weird behavior.....
0
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

 
LVL 18

Expert Comment

by:LesterClayton
ID: 39852613
I want to remind you that capture filters and display filters are two different kinds of filters.

Please try to capture all packets with a filter of "port 53", and do not use a display filter.

The purpose of testing against Google's DNS is to help troubleshoot your wireshark problems - it's not there to replace your existing DNS infrastructure.   What I'm trying to get working is your ability to do Wireshark traces, not to test your GSLB infrastructure.
0
 

Author Comment

by:xyz abc
ID: 39852614
Ok Thanks Lester, I agree my point here is when the wireshark can capture the same queries sometimes and it doesnot sometimes... So i dont know if that is something wrong with wireshark.....
0
 

Author Comment

by:xyz abc
ID: 39852620
I think its working.. My Apologies .... I think its capture filters..... i will confirm in sometime...

Thanks Lester.....
0
 
LVL 18

Expert Comment

by:LesterClayton
ID: 39852621
Good to hear :)

Wireshark doesn't have the ability to "choose" what kind of traffic to capture.  It captures what you tell it to capture, and what the WinPCap Driver can see.  

If you have a network infrastrucutre for example which uses 802.1x or IPSEC to communicate with certain servers - like your domain controllers (and subsequently, DNS), then you won't be able to use wireshark effectively, because most if not all of your traffic will be encyrpted, and undecipherable.  Perhaps this is what you are experiencing?
0
 

Author Comment

by:xyz abc
ID: 39852655
Its looks like the same issue when i try from Internet... But it works from my office network... From internet No Query messages only responses....
0
 

Author Comment

by:xyz abc
ID: 39855364
Does anyone what is going on.... ? I have the same issue even after setting the capture filter to port 53 as well no go...... And its only from internet.. when i try the same from office network it works perfectly fine... Any Wireshark DNS experts to help me.... ?
0
 

Accepted Solution

by:
xyz abc earned 0 total points
ID: 40076905
It seems to be some issue on our external DNS
0
 

Author Closing Comment

by:xyz abc
ID: 40088090
Actually it never got fixed
0

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A common practice in small networks is making file sharing easy which works extremely well when intra-network security is not an issue. In essence, everyone, that is "Everyone", is given access to all of the shared files - often the entire C: drive …
I'm a big fan of Windows' offline folder caching and have used it on my laptops for over a decade.  One thing I don't like about it, however, is how difficult Microsoft has made it for the cache to be moved out of the Windows folder.  Here's how to …
This Micro Tutorial demonstrates using Microsoft Excel pivot tables, how to reverse engineer competitors' marketing strategies through backlinks.
In a recent question (https://www.experts-exchange.com/questions/28997919/Pagination-in-Adobe-Acrobat.html) here at Experts Exchange, a member asked how to add page numbers to a PDF file using Adobe Acrobat XI Pro. This short video Micro Tutorial sh…

815 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now