I'm getting very irratic behavior on my 6.103 DNS proxy. On one interface Astaro will not resolve DNS queries. I have a Win2k3 server that has been attempting to use the DNS proxy as a forwarder. I've tried all sorts of work-arounds including allowing DNS through the firewall and using external DNS servers as forwarders. Still I see irratic behavior. As an additional note I found that somehow Astaro is dropping UDP packets between interfaces on the same network. This is very strange indeed since these packets should not be crossing interfaces on the firewall at all. [see below for details]
The DNS proxy works well when clients are pointed directly to it. If, however the clients are pointed to the Win2k3 server which then needs to either use the DNS proxy or traverse the firewall for direct DNS functionality, all hell breaks loose.
Can anyone help me with this?
Thanks,
~Doug
Logs showing dropping of port 53 packets within a single network: [?] I'm wondering if my switch is somehow misbehaving.
2006:02:17-04:06:03 (none) ulogd[2351]: DROP: IN=eth1 OUT= MAC=00:01:02:24:25:73:00:01:02:46:59:7f:08:00 SRC=10.1.1.100 DST=10.1.1.2 LEN=57 TOS=00 PREC=0x00 TTL=64 ID=54096 CE DF PROTO=UDP SPT=1250 DPT=53 LEN=37
2006:02:17-04:06:13 (none) ulogd[2351]: DROP: IN=eth1 OUT= MAC=00:01:02:24:25:73:00:01:02:46:59:7f:08:00 SRC=10.1.1.100 DST=10.1.1.2 LEN=57 TOS=00 PREC=0x00 TTL=64 ID=54097 CE DF PROTO=UDP SPT=1250 DPT=53 LEN=37
2006:02:17-04:26:48 (none) ulogd[2351]: DROP: IN=eth1 OUT= MAC=00:01:02:24:25:73:00:01:02:46:59:7f:08:00 SRC=10.1.1.100 DST=10.1.1.2 LEN=57 TOS=00 PREC=0x00 TTL=64 ID=37806 CE DF PROTO=UDP SPT=1251 DPT=53 LEN=37
2006:02:17-04:26:58 (none) ulogd[2351]: DROP: IN=eth1 OUT= MAC=00:01:02:24:25:73:00:01:02:46:59:7f:08:00 SRC=10.1.1.100 DST=10.1.1.2 LEN=57 TOS=00 PREC=0x00 TTL=64 ID=37807 CE DF PROTO=UDP SPT=1251 DPT=53 LEN=37
2006:02:17-04:47:49 (none) ulogd[2351]: DROP: IN=eth1 OUT= MAC=00:01:02:24:25:73:00:01:02:46:59:7f:08:00 SRC=10.1.1.100 DST=10.1.1.2 LEN=57 TOS=00 PREC=0x00 TTL=64 ID=25269 DF PROTO=UDP SPT=1252 DPT=53 LEN=37
2006:02:17-04:48:00 (none) ulogd[2351]: DROP: IN=eth1 OUT= MAC=00:01:02:24:25:73:00:01:02:46:59:7f:08:00 SRC=10.1.1.100 DST=10.1.1.2 LEN=57 TOS=00 PREC=0x00 TTL=64 ID=25270 DF PROTO=UDP SPT=1252 DPT=53 LEN=37
2006:02:17-09:00:02 (none) ulogd[2351]: DROP: IN=eth0 OUT=eth2 MAC=00:09:5b:e1:a6:7c:00:10:60:03:2b:55:08:00 SRC=192.168.1.253 DST=66.93.87.2 LEN=60 TOS=00 PREC=0x00 TTL=127 ID=7951 PROTO=UDP SPT=1025 DPT=53 LEN=40
2006:02:17-09:30:44 (none) ulogd[2351]: DROP: IN=eth0 OUT=eth2 MAC=00:09:5b:e1:a6:7c:00:10:60:03:2b:55:08:00 SRC=192.168.1.253 DST=66.93.87.2 LEN=61 TOS=00 PREC=0x00 TTL=127 ID=32231 PROTO=UDP SPT=1025 DPT=53 LEN=41
2006:02:17-11:58:07 (none) ulogd[2351]: DROP: IN=eth1 OUT= MAC=00:01:02:24:25:73:00:0d:56:39:be:2c:08:00 SRC=10.1.1.5 DST=10.1.1.2 LEN=70 TOS=00 PREC=0x00 TTL=128 ID=47766 CE PROTO=UDP SPT=2807 DPT=53 LEN=50
2006:02:17-11:58:07 (none) ulogd[2351]: DROP: IN=eth1 OUT= MAC=00:01:02:24:25:73:00:0d:56:39:be:2c:08:00 SRC=10.1.1.5 DST=10.1.1.2 LEN=70 TOS=00 PREC=0x00 TTL=128 ID=47801 CE PROTO=UDP SPT=2807 DPT=53 LEN=50
2006:02:17-11:58:08 (none) ulogd[2351]: DROP: IN=eth1 OUT= MAC=00:01:02:24:25:73:00:0d:56:39:be:2c:08:00 SRC=10.1.1.5 DST=10.1.1.2 LEN=70 TOS=00 PREC=0x00 TTL=128 ID=47814 CE PROTO=UDP SPT=2807 DPT=53 LEN=50
2006:02:17-11:58:08 (none) ulogd[2351]: DROP: IN=eth1 OUT= MAC=00:01:02:24:25:73:00:0d:56:39:be:2c:08:00 SRC=10.1.1.5 DST=10.1.1.2 LEN=65 TOS=00 PREC=0x00 TTL=128 ID=47826 CE PROTO=UDP SPT=4338 DPT=53 LEN=45
2006:02:17-11:58:10 (none) ulogd[2351]: DROP: IN=eth1 OUT= MAC=00:01:02:24:25:73:00:0d:56:39:be:2c:08:00 SRC=10.1.1.5 DST=10.1.1.2 LEN=65 TOS=00 PREC=0x00 TTL=128 ID=47833 CE PROTO=UDP SPT=4338 DPT=53 LEN=45
This thread was automatically locked due to age.