Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

DNS trace

Posted on 2014-02-11
11
Medium Priority
?
421 Views
Last Modified: 2014-05-24
Hi Team,

I am unable to see the DNS query in the wireshark trace , i tried deleting the cache , tried nslookup and also the browser.. Its the same issue,, no matter what i do i get the only response message in the DNS wireshark trace ,, it never captures the query message .. Also i dont see the reference part for packet number for query message of the DNS.. Let me know if there is any suggestion.

Regards..
0
Comment
Question by:xyz abc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 3
11 Comments
 
LVL 18

Expert Comment

by:LesterClayton
ID: 39852554
Check the following:

Do you have any filters on?
Are you capturing the correct network interface?
Have you tried capturing all network interfaces simultaneously?

Using a capture fulter of "port 53" will capture DNS queries both ways.  Here is a sample trace when I ran "nslookup google.co.uk"

Nslookup google.co.uk
Tip: you can also specify a DNS server to query - try do this while running a capture:
nslookup google.co.uk 8.8.8.8

Open in new window


This will force your query to go to Google's public DNS server at 8.8.8.8
0
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 39852559
0
 

Author Comment

by:xyz abc
ID: 39852611
Do you have any filters on?

---- No
Are you capturing the correct network interface?

Yes, I tried All Interfaces.

Have you tried capturing all network interfaces simultaneously?

Yes

I tried DNS, tcp.port==53 , udp.port==53

I tried for other websites internally in office i can see the query message part, But from internet i dont see the "Query Message " and under the packet there is no reference of packet number in query Response. So basically i see only Query responses no Queries captured in Wireshark.....

I cannot point this to google DNS since we have GSLB in picture the whole point of testing will be gone......

Not sure of this weird behavior.....
0
Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

 
LVL 18

Expert Comment

by:LesterClayton
ID: 39852613
I want to remind you that capture filters and display filters are two different kinds of filters.

Please try to capture all packets with a filter of "port 53", and do not use a display filter.

The purpose of testing against Google's DNS is to help troubleshoot your wireshark problems - it's not there to replace your existing DNS infrastructure.   What I'm trying to get working is your ability to do Wireshark traces, not to test your GSLB infrastructure.
0
 

Author Comment

by:xyz abc
ID: 39852614
Ok Thanks Lester, I agree my point here is when the wireshark can capture the same queries sometimes and it doesnot sometimes... So i dont know if that is something wrong with wireshark.....
0
 

Author Comment

by:xyz abc
ID: 39852620
I think its working.. My Apologies .... I think its capture filters..... i will confirm in sometime...

Thanks Lester.....
0
 
LVL 18

Expert Comment

by:LesterClayton
ID: 39852621
Good to hear :)

Wireshark doesn't have the ability to "choose" what kind of traffic to capture.  It captures what you tell it to capture, and what the WinPCap Driver can see.  

If you have a network infrastrucutre for example which uses 802.1x or IPSEC to communicate with certain servers - like your domain controllers (and subsequently, DNS), then you won't be able to use wireshark effectively, because most if not all of your traffic will be encyrpted, and undecipherable.  Perhaps this is what you are experiencing?
0
 

Author Comment

by:xyz abc
ID: 39852655
Its looks like the same issue when i try from Internet... But it works from my office network... From internet No Query messages only responses....
0
 

Author Comment

by:xyz abc
ID: 39855364
Does anyone what is going on.... ? I have the same issue even after setting the capture filter to port 53 as well no go...... And its only from internet.. when i try the same from office network it works perfectly fine... Any Wireshark DNS experts to help me.... ?
0
 

Accepted Solution

by:
xyz abc earned 0 total points
ID: 40076905
It seems to be some issue on our external DNS
0
 

Author Closing Comment

by:xyz abc
ID: 40088090
Actually it never got fixed
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We recently endured a series of broadcast storms that caused our ISP to shut us down for brief periods of time. After going through a multitude of tests, we determined that the issue was related to Intel NIC drivers on some new HP desktop computers …
An article on effective troubleshooting
This course is ideal for IT System Administrators working with VMware vSphere and its associated products in their company infrastructure. This course teaches you how to install and maintain this virtualization technology to store data, prevent vuln…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question