[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: vserver: Problem mit Namesauflösung



Hallo Reinhold,

Wednesday, December 24, 2003, 2:43:05 PM, you wrote:

RP> Das Ganze heisst für mich, das vserver keinen Kontakt über Port 53
RP> bekommt, irgendwer steht da auf der Leitung.

RP> Schau mal mit tcpdump an etho, eth0:vs1 und ppp0, was dort vom 
RP> vserver beim [nslookup|host] <name> ankommt.
RP> Vielleicht wird es dann klarer, wo die Pakete hängenbleiben.

also ein nslookup auf spiegel.de ergab folgendes:

vs1:/tmp# tcpdump -i ppp0
tcpdump: WARNING: ppp0: no IPv4 address assigned
tcpdump: listening on ppp0
21:01:43.021376 vs1.spunkzone.1126 > 213.191.74.18.domain:  28042+ A? spiegel.de. (28) (DF)
21:01:43.026135 vs1.spunkzone.1127 > 213.191.74.18.domain:  6569+ PTR? 18.74.191.213.in-addr.arpa. (44) (DF)
21:01:44.031326 vs1.spunkzone.1128 > 213.191.74.19.domain:  28042+ A? spiegel.de. (28) (DF)
21:01:46.030876 vs1.spunkzone.1129 > 213.191.74.19.domain:  6569+ PTR? 18.74.191.213.in-addr.arpa. (44) (DF)
21:01:50.051013 vs1.spunkzone.1126 > 213.191.74.18.domain:  28042+ A? spiegel.de. (28) (DF)
21:01:51.060982 vs1.spunkzone.1128 > 213.191.74.19.domain:  28042+ A? spiegel.de. (28) (DF)
21:01:52.041182 vs1.spunkzone.1130 > 213.191.74.18.domain:  6569+ PTR? 18.74.191.213.in-addr.arpa. (44) (DF)
21:01:55.050835 vs1.spunkzone.1131 > 213.191.74.19.domain:  6569+ PTR? 18.74.191.213.in-addr.arpa. (44) (DF)
21:02:01.063170 vs1.spunkzone.1131 > 213.191.74.18.domain:  6570+ PTR? 19.74.191.213.in-addr.arpa. (44) (DF)
21:02:04.070888 vs1.spunkzone.1132 > 213.191.74.19.domain:  6570+ PTR? 19.74.191.213.in-addr.arpa. (44) (DF)
21:02:10.081163 vs1.spunkzone.1133 > 213.191.74.18.domain:  6570+ PTR? 19.74.191.213.in-addr.arpa. (44) (DF)
21:02:13.090835 vs1.spunkzone.1134 > 213.191.74.19.domain:  6570+ PTR? 19.74.191.213.in-addr.arpa. (44) (DF)
12 packets received by filter
0 packets dropped by kernel

vs1:/tmp# tcpdump -i eth0:vs1
tcpdump: listening on eth0:vs1
21:04:00.598546 vs1.spunkzone.ssh > 192.168.0.10.1076: P 1731509150:1731509202(52) ack 1739820095 win 8576 (DF) [tos 0x10]
21:04:00.598974 vs1.spunkzone.ssh > 192.168.0.10.1076: P 52:136(84) ack 1 win 8576 (DF) [tos 0x10]
21:04:00.599195 192.168.0.10.1076 > vs1.spunkzone.ssh: . ack 136 win 63260 (DF)
21:04:00.599511 192.168.0.10.1076 > vs1.spunkzone.ssh: P 1:53(52) ack 136 win 63260 (DF)
21:04:00.599572 vs1.spunkzone.ssh > 192.168.0.10.1076: . ack 53 win 8576 (DF) [tos 0x10]
21:04:00.599924 192.168.0.10.1076 > vs1.spunkzone.ssh: P 53:105(52) ack 136 win 63260 (DF)
21:04:00.599985 vs1.spunkzone.ssh > 192.168.0.10.1076: . ack 105 win 8576 (DF) [tos 0x10]
21:04:00.605021 PPPoE  [ses 0x1254] IP 73: vs1.spunkzone.1134 > 213.191.74.18.domain:  28033+ PTR? 10.0.168.192.in-addr.arpa. (43) (DF)
21:04:01.878254 PPPoE  [ses 0x1254] IP 62:
9 packets received by filter
0 packets dropped by kernel

vs1:/tmp# tcpdump -i eth0
tcpdump: WARNING: eth0: no IPv4 address assigned
tcpdump: listening on eth0
21:05:01.011291 vs1.spunkzone.ssh > 192.168.0.10.1076: P 1731510718:1731510786(68) ack 1739821083 win 8576 (DF) [tos 0x10]
21:05:01.012027 192.168.0.10.1076 > vs1.spunkzone.ssh: P 1:53(52) ack 68 win 63464 (DF)
21:05:01.029965 PPPoE  [ses 0x1254] IP 73: vs1.spunkzone.1146 > 213.191.74.18.domain:  10030+ PTR? 10.0.168.192.in-addr.arpa. (43) (DF)
21:05:01.030994 vs1.spunkzone.ssh > 192.168.0.10.1076: P 68:168(100) ack 53 win 8576 (DF) [tos 0x10]
21:05:01.031757 192.168.0.10.1076 > vs1.spunkzone.ssh: P 53:105(52) ack 168 win 63364 (DF)
21:05:01.070730 vs1.spunkzone.ssh > 192.168.0.10.1076: . ack 105 win 8576 (DF) [tos 0x10]
21:05:04.041102 PPPoE  [ses 0x1254] IP 73:
7 packets received by filter
0 packets dropped by kernel

Daraus kann ich allerdings ehrlich gesagt nicht viel ersehen.

-- 
greetz,
 Carsten                          
mailto:spunk@synapsentennis.de
----------------------------------------------
http://www.againsttcpa.com/



Reply to: