[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference noted::seal

Title:SEAL
Moderator:GALVIA::SMITH
Created:Mon Mar 21 1994
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:1989
Total number of notes:8209

1778.0. "AFWNT dns root server first lookup fails" by BACHUS::ROETS (Chris Roets) Thu Feb 06 1997 09:53

Hello Guys,

I have another interesting problem here :

|DU-dns-server|---------|winntAFW|---------The internet

DU-dns-server can be replace with VMS-dns-server, same problem will occur :

We have a standard hidden config where, the wintAFW dns-client-part
point to the DU-dns-server, which in turn has a forwarders line to
the winntAFW.  This winntAFW goes to the root-servers.

If you now do an nslookup on the winntAFW and you specify a node that
is not yet in the cache and for which the winntAFW needs to contact the
root-servers, you have problems.  Actually you see the problem the first time.
The first time, the nslookup will fail.  All next times the nslookup
work ok (as long as the dns cache does not expire).

analyses : Using a network monitor and the named in debug I could see that
		the information came in correctly to the winntAFW external
		interface, while the up-packet given by the WinntAFW is
		incomplete or incorrect.
		DU-dns-servers get this packet, is able to put the address
		in the cache, but does not pass the info further to its
		client.
		So, first lookup, fails but address is but in cache, next
		lookups work ok.

The global phenomene is that people in the internal network, doing
web-access, alsways get an error the first time...

I simple workaround to this is to put a forwarder in the named.bt file
of the WinntAFW, then all works fine....

I include here the log-files that prove my analyses :

network monitor at WinntAFW external network-interface :
-------------------------------------------------------
************************************************************************************************************************************************************
Frame   Time    Src MAC Addr   Dst MAC Addr   Protocol  Description                                                       Src Other Addr  Dst Other Addr  Type Other Addr
10      22.814  DEC   22CD22   AA00040037D5   DNS       0x6:Std Qry for www.infobel.be. of type Host Addr on class INET a fwright         192.33.4.12     IP

  FRAME: Base frame properties
      FRAME: Time of capture = Feb 6, 1997 14:51:12.429
      FRAME: Time delta from previous physical frame: 163 milliseconds
      FRAME: Frame number: 10
      FRAME: Total frame length: 74 bytes
      FRAME: Capture frame length: 74 bytes
      FRAME: Frame data: Number of data bytes remaining = 74 (0x004A)
  ETHERNET: ETYPE = 0x0800 : Protocol = IP:  DOD Internet Protocol
      ETHERNET: Destination address : AA00040037D5
          ETHERNET: .......0 = Individual address
          ETHERNET: ......1. = Locally administered address
      ETHERNET: Source address : 0000F822CD22
          ETHERNET: .......0 = No routing information present
          ETHERNET: ......0. = Universally administered address
      ETHERNET: Frame Length : 74 (0x004A)
      ETHERNET: Ethernet Type : 0x0800 (IP:  DOD Internet Protocol)
      ETHERNET: Ethernet Data: Number of data bytes remaining = 60 (0x003C)
  IP: ID = 0x87EC; Proto = UDP; Len: 60
      IP: Version = 4 (0x4)
      IP: Header Length = 20 (0x14)
      IP: Service Type = 0 (0x0)
          IP: Precedence = Routine
          IP: ...0.... = Normal Delay
          IP: ....0... = Normal Throughput
          IP: .....0.. = Normal Reliability
      IP: Total Length = 60 (0x3C)
      IP: Identification = 34796 (0x87EC)
      IP: Flags Summary = 0 (0x0)
          IP: .......0 = Last fragment in datagram
          IP: ......0. = May fragment datagram if necessary
      IP: Fragment Offset = 0 (0x0) bytes
      IP: Time to Live = 32 (0x20)
      IP: Protocol = UDP - User Datagram
      IP: Checksum = 0x1DA2
      IP: Source Address = 16.183.32.63
      IP: Destination Address = 192.33.4.12
      IP: Data: Number of data bytes remaining = 40 (0x0028)
  UDP: Src Port: DNS, (53); Dst Port: DNS (53); Length = 40 (0x28)
      UDP: Source Port = DNS
      UDP: Destination Port = DNS
      UDP: Total length = 40 (0x28) bytes
      UDP: UDP Checksum = 0xDD18

page 17


Network Monitor trace  Thu 02/06/97 14:58:42  U:\cab.txt

      UDP: Data: Number of data bytes remaining = 32 (0x0020)
  DNS: 0x6:Std Qry for www.infobel.be. of type Host Addr on class INET addr.
      DNS: Query Identifier = 6 (0x6)
      DNS: DNS Flags = Query, OpCode - Std Qry, RCode - No error
          DNS: 0............... = Query
          DNS: .0000........... = Standard Query
          DNS: .....0.......... = Server not authority for domain
          DNS: ......0......... = Message complete
          DNS: .......0........ = Iterative query desired
          DNS: ........0....... = No recursive queries
          DNS: .........000.... = Reserved
          DNS: ............0000 = No error
      DNS: Question Entry Count = 1 (0x1)
      DNS: Answer Entry Count = 0 (0x0)
      DNS: Name Server Count = 0 (0x0)
      DNS: Additional Records Count = 0 (0x0)
      DNS: Question Section: www.infobel.be. of type Host Addr on class INET addr.
          DNS: Question Name: www.infobel.be.
          DNS: Question Type = Host Address
          DNS: Question Class = Internet address class

00000:  AA 00 04 00 37 D5 00 00 F8 22 CD 22 08 00 45 00   ....7...."."..E.
00010:  00 3C 87 EC 00 00 20 11 1D A2 10 B7 20 3F C0 21   .<.... ..... ?.!
00020:  04 0C 00 35 00 35 00 28 DD 18 00 06 00 00 00 01   ...5.5.(........
00030:  00 00 00 00 00 00 03 77 77 77 07 69 6E 66 6F 62   .......www.infob
00040:  65 6C 02 62 65 00 00 01 00 01                     el.be.....      

************************************************************************************************************************************************************
Frame   Time    Src MAC Addr   Dst MAC Addr   Protocol  Description                                                       Src Other Addr  Dst Other Addr  Type Other Addr
11      26.654  AA00040005D6   DEC   22CD22   DNS       0x6:Std Qry Resp. Auth. NS is BE. of type Auth. NS on class INET  192.33.4.12     fwright         IP

  FRAME: Base frame properties
      FRAME: Time of capture = Feb 6, 1997 14:51:16.269
      FRAME: Time delta from previous physical frame: 3840 milliseconds
      FRAME: Frame number: 11
      FRAME: Total frame length: 332 bytes
      FRAME: Capture frame length: 332 bytes
      FRAME: Frame data: Number of data bytes remaining = 332 (0x014C)
  ETHERNET: ETYPE = 0x0800 : Protocol = IP:  DOD Internet Protocol
      ETHERNET: Destination address : 0000F822CD22
          ETHERNET: .......0 = Individual address
          ETHERNET: ......0. = Universally administered address
      ETHERNET: Source address : AA00040005D6
          ETHERNET: .......0 = No routing information present
          ETHERNET: ......1. = Locally administered address
      ETHERNET: Frame Length : 332 (0x014C)
      ETHERNET: Ethernet Type : 0x0800 (IP:  DOD Internet Protocol)
      ETHERNET: Ethernet Data: Number of data bytes remaining = 318 (0x013E)
  IP: ID = 0xAEDD; Proto = UDP; Len: 318
      IP: Version = 4 (0x4)
      IP: Header Length = 20 (0x14)
      IP: Service Type = 0 (0x0)
          IP: Precedence = Routine

page 18


Network Monitor trace  Thu 02/06/97 14:58:42  U:\cab.txt

          IP: ...0.... = Normal Delay
          IP: ....0... = Normal Throughput
          IP: .....0.. = Normal Reliability
      IP: Total Length = 318 (0x13E)
      IP: Identification = 44765 (0xAEDD)
      IP: Flags Summary = 2 (0x2)
          IP: .......0 = Last fragment in datagram
          IP: ......1. = Cannot fragment datagram
      IP: Fragment Offset = 0 (0x0) bytes
      IP: Time to Live = 240 (0xF0)
      IP: Protocol = UDP - User Datagram
      IP: Checksum = 0xE5AD
      IP: Source Address = 192.33.4.12
      IP: Destination Address = 16.183.32.63
      IP: Data: Number of data bytes remaining = 298 (0x012A)
  UDP: Src Port: DNS, (53); Dst Port: DNS (53); Length = 298 (0x12A)
      UDP: Source Port = DNS
      UDP: Destination Port = DNS
      UDP: Total length = 298 (0x12A) bytes
      UDP: UDP Checksum = 0x451E
      UDP: Data: Number of data bytes remaining = 290 (0x0122)
  DNS: 0x6:Std Qry Resp. Auth. NS is BE. of type Auth. NS on class INET addr.
      DNS: Query Identifier = 6 (0x6)
      DNS: DNS Flags = Response, OpCode - Std Qry, RCode - No error
          DNS: 1............... = Response
          DNS: .0000........... = Standard Query
          DNS: .....0.......... = Server not authority for domain
          DNS: ......0......... = Message complete
          DNS: .......0........ = Iterative query desired
          DNS: ........0....... = No recursive queries
          DNS: .........000.... = Reserved
          DNS: ............0000 = No error
      DNS: Question Entry Count = 1 (0x1)
      DNS: Answer Entry Count = 0 (0x0)
      DNS: Name Server Count = 5 (0x5)
      DNS: Additional Records Count = 8 (0x8)
      DNS: Question Section: www.infobel.be. of type Host Addr on class INET addr.
          DNS: Question Name: www.infobel.be.
          DNS: Question Type = Host Address
          DNS: Question Class = Internet address class
      DNS: Authority Section: BE. of type Auth. NS on class INET addr.(5 records present)
          DNS: Resource Record: BE. of type Auth. NS on class INET addr.
              DNS: Resource Name: BE.
              DNS: Resource Type = Authoritative Name Server
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)
              DNS: Resource Data Length = 20 (0x14)
              DNS: Authoritative Name Server: NS.CS.KULEUVEN.AC.BE.
          DNS: Resource Record: BE. of type Auth. NS on class INET addr.
              DNS: Resource Name: BE.
              DNS: Resource Type = Authoritative Name Server
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)

page 19


Network Monitor trace  Thu 02/06/97 14:58:42  U:\cab.txt

              DNS: Resource Data Length = 11 (0xB)
              DNS: Authoritative Name Server: NS.EUNET.BE.
          DNS: Resource Record: BE. of type Auth. NS on class INET addr.
              DNS: Resource Name: BE.
              DNS: Resource Type = Authoritative Name Server
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)
              DNS: Resource Data Length = 12 (0xC)
              DNS: Authoritative Name Server: NS.BELNET.BE.
          DNS: Resource Record: BE. of type Auth. NS on class INET addr.
              DNS: Resource Name: BE.
              DNS: Resource Type = Authoritative Name Server
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)
              DNS: Resource Data Length = 14 (0xE)
              DNS: Authoritative Name Server: MAILSERV.CC.KULEUVEN.AC.BE.
          DNS: Resource Record: BE. of type Auth. NS on class INET addr.
              DNS: Resource Name: BE.
              DNS: Resource Type = Authoritative Name Server
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)
              DNS: Resource Data Length = 11 (0xB)
              DNS: Authoritative Name Server: NS.EU.NET.
      DNS: Additional Records Section: NS.CS.KULEUVEN.AC.BE. of type Host Addr on class INET addr.(8 records present)
          DNS: Resource Record: NS.CS.KULEUVEN.AC.BE. of type Host Addr on class INET addr.
              DNS: Resource Name: NS.CS.KULEUVEN.AC.BE.
              DNS: Resource Type = Host Address
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)
              DNS: Resource Data Length = 4 (0x4)
              DNS: IP address = 134.58.40.4
          DNS: Resource Record: NS.CS.KULEUVEN.AC.BE. of type Host Addr on class INET addr.
              DNS: Resource Name: NS.CS.KULEUVEN.AC.BE.
              DNS: Resource Type = Host Address
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)
              DNS: Resource Data Length = 4 (0x4)
              DNS: IP address = 134.58.41.7
          DNS: Resource Record: NS.CS.KULEUVEN.AC.BE. of type Host Addr on class INET addr.
              DNS: Resource Name: NS.CS.KULEUVEN.AC.BE.
              DNS: Resource Type = Host Address
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)
              DNS: Resource Data Length = 4 (0x4)
              DNS: IP address = 134.58.45.30
          DNS: Resource Record: NS.EUNET.BE. of type Host Addr on class INET addr.
              DNS: Resource Name: NS.EUNET.BE.
              DNS: Resource Type = Host Address
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)
              DNS: Resource Data Length = 4 (0x4)
              DNS: IP address = 192.92.130.1
          DNS: Resource Record: NS.BELNET.BE. of type Host Addr on class INET addr.

page 20


Network Monitor trace  Thu 02/06/97 14:58:42  U:\cab.txt

              DNS: Resource Name: NS.BELNET.BE.
              DNS: Resource Type = Host Address
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)
              DNS: Resource Data Length = 4 (0x4)
              DNS: IP address = 193.190.198.10
          DNS: Resource Record: NS.BELNET.BE. of type Host Addr on class INET addr.
              DNS: Resource Name: NS.BELNET.BE.
              DNS: Resource Type = Host Address
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)
              DNS: Resource Data Length = 4 (0x4)
              DNS: IP address = 193.190.198.2
          DNS: Resource Record: MAILSERV.CC.KULEUVEN.AC.BE. of type Host Addr on class INET addr.
              DNS: Resource Name: MAILSERV.CC.KULEUVEN.AC.BE.
              DNS: Resource Type = Host Address
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)
              DNS: Resource Data Length = 4 (0x4)
              DNS: IP address = 134.58.8.44
          DNS: Resource Record: NS.EU.NET. of type Host Addr on class INET addr.
              DNS: Resource Name: NS.EU.NET.
              DNS: Resource Type = Host Address
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 172800 (0x2A300)
              DNS: Resource Data Length = 4 (0x4)
              DNS: IP address = 192.16.202.11

00000:  00 00 F8 22 CD 22 AA 00 04 00 05 D6 08 00 45 00   ..."."........E.
00010:  01 3E AE DD 40 00 F0 11 E5 AD C0 21 04 0C 10 B7   .>..@......!....
00020:  20 3F 00 35 00 35 01 2A 45 1E 00 06 80 00 00 01    ?.5.5.*E.......
00030:  00 00 00 05 00 08 03 77 77 77 07 69 6E 66 6F 62   .......www.infob
00040:  65 6C 02 62 65 00 00 01 00 01 02 42 45 00 00 02   el.be......BE...

************************************************************************************************************************************************************
Frame   Time    Src MAC Addr   Dst MAC Addr   Protocol  Description                                                       Src Other Addr  Dst Other Addr  Type Other Addr
12      26.663  DEC   22CD22   AA00040037D5   DNS       0x7:Std Qry for www.infobel.be. of type Host Addr on class INET a fwright         134.58.41.7     IP

  FRAME: Base frame properties
      FRAME: Time of capture = Feb 6, 1997 14:51:16.278
      FRAME: Time delta from previous physical frame: 9 milliseconds
      FRAME: Frame number: 12
      FRAME: Total frame length: 74 bytes
      FRAME: Capture frame length: 74 bytes
      FRAME: Frame data: Number of data bytes remaining = 74 (0x004A)
  ETHERNET: ETYPE = 0x0800 : Protocol = IP:  DOD Internet Protocol
      ETHERNET: Destination address : AA00040037D5
          ETHERNET: .......0 = Individual address
          ETHERNET: ......1. = Locally administered address
      ETHERNET: Source address : 0000F822CD22
          ETHERNET: .......0 = No routing information present
          ETHERNET: ......0. = Universally administered address
      ETHERNET: Frame Length : 74 (0x004A)

page 21


Network Monitor trace  Thu 02/06/97 14:58:42  U:\cab.txt

      ETHERNET: Ethernet Type : 0x0800 (IP:  DOD Internet Protocol)
      ETHERNET: Ethernet Data: Number of data bytes remaining = 60 (0x003C)
  IP: ID = 0x88EC; Proto = UDP; Len: 60
      IP: Version = 4 (0x4)
      IP: Header Length = 20 (0x14)
      IP: Service Type = 0 (0x0)
          IP: Precedence = Routine
          IP: ...0.... = Normal Delay
          IP: ....0... = Normal Throughput
          IP: .....0.. = Normal Reliability
      IP: Total Length = 60 (0x3C)
      IP: Identification = 35052 (0x88EC)
      IP: Flags Summary = 0 (0x0)
          IP: .......0 = Last fragment in datagram
          IP: ......0. = May fragment datagram if necessary
      IP: Fragment Offset = 0 (0x0) bytes
      IP: Time to Live = 32 (0x20)
      IP: Protocol = UDP - User Datagram
      IP: Checksum = 0x318E
      IP: Source Address = 16.183.32.63
      IP: Destination Address = 134.58.41.7
      IP: Data: Number of data bytes remaining = 40 (0x0028)
  UDP: Src Port: DNS, (53); Dst Port: DNS (53); Length = 40 (0x28)
      UDP: Source Port = DNS
      UDP: Destination Port = DNS
      UDP: Total length = 40 (0x28) bytes
      UDP: UDP Checksum = 0xF103
      UDP: Data: Number of data bytes remaining = 32 (0x0020)
  DNS: 0x7:Std Qry for www.infobel.be. of type Host Addr on class INET addr.
      DNS: Query Identifier = 7 (0x7)
      DNS: DNS Flags = Query, OpCode - Std Qry, RD Bits Set, RCode - No error
          DNS: 0............... = Query
          DNS: .0000........... = Standard Query
          DNS: .....0.......... = Server not authority for domain
          DNS: ......0......... = Message complete
          DNS: .......1........ = Recursive query desired
          DNS: ........0....... = No recursive queries
          DNS: .........000.... = Reserved
          DNS: ............0000 = No error
      DNS: Question Entry Count = 1 (0x1)
      DNS: Answer Entry Count = 0 (0x0)
      DNS: Name Server Count = 0 (0x0)
      DNS: Additional Records Count = 0 (0x0)
      DNS: Question Section: www.infobel.be. of type Host Addr on class INET addr.
          DNS: Question Name: www.infobel.be.
          DNS: Question Type = Host Address
          DNS: Question Class = Internet address class

00000:  AA 00 04 00 37 D5 00 00 F8 22 CD 22 08 00 45 00   ....7...."."..E.
00010:  00 3C 88 EC 00 00 20 11 31 8E 10 B7 20 3F 86 3A   .<.... .1... ?.:
00020:  29 07 00 35 00 35 00 28 F1 03 00 07 01 00 00 01   )..5.5.(........
00030:  00 00 00 00 00 00 03 77 77 77 07 69 6E 66 6F 62   .......www.infob
00040:  65 6C 02 62 65 00 00 01 00 01                     el.be.....      

page 22


Network Monitor trace  Thu 02/06/97 14:58:42  U:\cab.txt


************************************************************************************************************************************************************
Frame   Time    Src MAC Addr   Dst MAC Addr   Protocol  Description                                                       Src Other Addr  Dst Other Addr  Type Other Addr
13      30.669  DEC   22CD22   AA00040037D5   DNS       0x7:Std Qry for www.infobel.be. of type Host Addr on class INET a fwright         134.58.45.30    IP

  FRAME: Base frame properties
      FRAME: Time of capture = Feb 6, 1997 14:51:20.284
      FRAME: Time delta from previous physical frame: 4006 milliseconds
      FRAME: Frame number: 13
      FRAME: Total frame length: 74 bytes
      FRAME: Capture frame length: 74 bytes
      FRAME: Frame data: Number of data bytes remaining = 74 (0x004A)
  ETHERNET: ETYPE = 0x0800 : Protocol = IP:  DOD Internet Protocol
      ETHERNET: Destination address : AA00040037D5
          ETHERNET: .......0 = Individual address
          ETHERNET: ......1. = Locally administered address
      ETHERNET: Source address : 0000F822CD22
          ETHERNET: .......0 = No routing information present
          ETHERNET: ......0. = Universally administered address
      ETHERNET: Frame Length : 74 (0x004A)
      ETHERNET: Ethernet Type : 0x0800 (IP:  DOD Internet Protocol)
      ETHERNET: Ethernet Data: Number of data bytes remaining = 60 (0x003C)
  IP: ID = 0x8CEC; Proto = UDP; Len: 60
      IP: Version = 4 (0x4)
      IP: Header Length = 20 (0x14)
      IP: Service Type = 0 (0x0)
          IP: Precedence = Routine
          IP: ...0.... = Normal Delay
          IP: ....0... = Normal Throughput
          IP: .....0.. = Normal Reliability
      IP: Total Length = 60 (0x3C)
      IP: Identification = 36076 (0x8CEC)
      IP: Flags Summary = 0 (0x0)
          IP: .......0 = Last fragment in datagram
          IP: ......0. = May fragment datagram if necessary
      IP: Fragment Offset = 0 (0x0) bytes
      IP: Time to Live = 32 (0x20)
      IP: Protocol = UDP - User Datagram
      IP: Checksum = 0x2977
      IP: Source Address = 16.183.32.63
      IP: Destination Address = 134.58.45.30
      IP: Data: Number of data bytes remaining = 40 (0x0028)
  UDP: Src Port: DNS, (53); Dst Port: DNS (53); Length = 40 (0x28)
      UDP: Source Port = DNS
      UDP: Destination Port = DNS
      UDP: Total length = 40 (0x28) bytes
      UDP: UDP Checksum = 0xEDEC
      UDP: Data: Number of data bytes remaining = 32 (0x0020)
  DNS: 0x7:Std Qry for www.infobel.be. of type Host Addr on class INET addr.
      DNS: Query Identifier = 7 (0x7)
      DNS: DNS Flags = Query, OpCode - Std Qry, RCode - No error
          DNS: 0............... = Query
          DNS: .0000........... = Standard Query

page 23


Network Monitor trace  Thu 02/06/97 14:58:42  U:\cab.txt

          DNS: .....0.......... = Server not authority for domain
          DNS: ......0......... = Message complete
          DNS: .......0........ = Iterative query desired
          DNS: ........0....... = No recursive queries
          DNS: .........000.... = Reserved
          DNS: ............0000 = No error
      DNS: Question Entry Count = 1 (0x1)
      DNS: Answer Entry Count = 0 (0x0)
      DNS: Name Server Count = 0 (0x0)
      DNS: Additional Records Count = 0 (0x0)
      DNS: Question Section: www.infobel.be. of type Host Addr on class INET addr.
          DNS: Question Name: www.infobel.be.
          DNS: Question Type = Host Address
          DNS: Question Class = Internet address class

00000:  AA 00 04 00 37 D5 00 00 F8 22 CD 22 08 00 45 00   ....7...."."..E.
00010:  00 3C 8C EC 00 00 20 11 29 77 10 B7 20 3F 86 3A   .<.... .)w.. ?.:
00020:  2D 1E 00 35 00 35 00 28 ED EC 00 07 00 00 00 01   -..5.5.(........
00030:  00 00 00 00 00 00 03 77 77 77 07 69 6E 66 6F 62   .......www.infob
00040:  65 6C 02 62 65 00 00 01 00 01                     el.be.....      

************************************************************************************************************************************************************
Frame   Time    Src MAC Addr   Dst MAC Addr   Protocol  Description                                                       Src Other Addr  Dst Other Addr  Type Other Addr
14      34.670  DEC   22CD22   AA00040037D5   DNS       0x7:Std Qry for www.infobel.be. of type Host Addr on class INET a fwright         192.92.130.1    IP

  FRAME: Base frame properties
      FRAME: Time of capture = Feb 6, 1997 14:51:24.285
      FRAME: Time delta from previous physical frame: 4001 milliseconds
      FRAME: Frame number: 14
      FRAME: Total frame length: 74 bytes
      FRAME: Capture frame length: 74 bytes
      FRAME: Frame data: Number of data bytes remaining = 74 (0x004A)
  ETHERNET: ETYPE = 0x0800 : Protocol = IP:  DOD Internet Protocol
      ETHERNET: Destination address : AA00040037D5
          ETHERNET: .......0 = Individual address
          ETHERNET: ......1. = Locally administered address
      ETHERNET: Source address : 0000F822CD22
          ETHERNET: .......0 = No routing information present
          ETHERNET: ......0. = Universally administered address
      ETHERNET: Frame Length : 74 (0x004A)
      ETHERNET: Ethernet Type : 0x0800 (IP:  DOD Internet Protocol)
      ETHERNET: Ethernet Data: Number of data bytes remaining = 60 (0x003C)
  IP: ID = 0x90EC; Proto = UDP; Len: 60
      IP: Version = 4 (0x4)
      IP: Header Length = 20 (0x14)
      IP: Service Type = 0 (0x0)
          IP: Precedence = Routine
          IP: ...0.... = Normal Delay
          IP: ....0... = Normal Throughput
          IP: .....0.. = Normal Reliability
      IP: Total Length = 60 (0x3C)
      IP: Identification = 37100 (0x90EC)
      IP: Flags Summary = 0 (0x0)

page 24


Network Monitor trace  Thu 02/06/97 14:58:42  U:\cab.txt

          IP: .......0 = Last fragment in datagram
          IP: ......0. = May fragment datagram if necessary
      IP: Fragment Offset = 0 (0x0) bytes
      IP: Time to Live = 32 (0x20)
      IP: Protocol = UDP - User Datagram
      IP: Checksum = 0x9671
      IP: Source Address = 16.183.32.63
      IP: Destination Address = 192.92.130.1
      IP: Data: Number of data bytes remaining = 40 (0x0028)
  UDP: Src Port: DNS, (53); Dst Port: DNS (53); Length = 40 (0x28)
      UDP: Source Port = DNS
      UDP: Destination Port = DNS
      UDP: Total length = 40 (0x28) bytes
      UDP: UDP Checksum = 0x5EE7
      UDP: Data: Number of data bytes remaining = 32 (0x0020)
  DNS: 0x7:Std Qry for www.infobel.be. of type Host Addr on class INET addr.
      DNS: Query Identifier = 7 (0x7)
      DNS: DNS Flags = Query, OpCode - Std Qry, RCode - No error
          DNS: 0............... = Query
          DNS: .0000........... = Standard Query
          DNS: .....0.......... = Server not authority for domain
          DNS: ......0......... = Message complete
          DNS: .......0........ = Iterative query desired
          DNS: ........0....... = No recursive queries
          DNS: .........000.... = Reserved
          DNS: ............0000 = No error
      DNS: Question Entry Count = 1 (0x1)
      DNS: Answer Entry Count = 0 (0x0)
      DNS: Name Server Count = 0 (0x0)
      DNS: Additional Records Count = 0 (0x0)
      DNS: Question Section: www.infobel.be. of type Host Addr on class INET addr.
          DNS: Question Name: www.infobel.be.
          DNS: Question Type = Host Address
          DNS: Question Class = Internet address class

00000:  AA 00 04 00 37 D5 00 00 F8 22 CD 22 08 00 45 00   ....7...."."..E.
00010:  00 3C 90 EC 00 00 20 11 96 71 10 B7 20 3F C0 5C   .<.... ..q.. ?.\
00020:  82 01 00 35 00 35 00 28 5E E7 00 07 00 00 00 01   ...5.5.(^.......
00030:  00 00 00 00 00 00 03 77 77 77 07 69 6E 66 6F 62   .......www.infob
00040:  65 6C 02 62 65 00 00 01 00 01                     el.be.....      

************************************************************************************************************************************************************
Frame   Time    Src MAC Addr   Dst MAC Addr   Protocol  Description                                                       Src Other Addr  Dst Other Addr  Type Other Addr
15      38.500  AA00040005D6   DEC   22CD22   DNS       0x7:Std Qry Resp. for www.infobel.be. of type Host Addr on class  192.92.130.1    fwright         IP

  FRAME: Base frame properties
      FRAME: Time of capture = Feb 6, 1997 14:51:28.115
      FRAME: Time delta from previous physical frame: 3830 milliseconds
      FRAME: Frame number: 15
      FRAME: Total frame length: 187 bytes
      FRAME: Capture frame length: 187 bytes
      FRAME: Frame data: Number of data bytes remaining = 187 (0x00BB)
  ETHERNET: ETYPE = 0x0800 : Protocol = IP:  DOD Internet Protocol

page 25


Network Monitor trace  Thu 02/06/97 14:58:42  U:\cab.txt

      ETHERNET: Destination address : 0000F822CD22
          ETHERNET: .......0 = Individual address
          ETHERNET: ......0. = Universally administered address
      ETHERNET: Source address : AA00040005D6
          ETHERNET: .......0 = No routing information present
          ETHERNET: ......1. = Locally administered address
      ETHERNET: Frame Length : 187 (0x00BB)
      ETHERNET: Ethernet Type : 0x0800 (IP:  DOD Internet Protocol)
      ETHERNET: Ethernet Data: Number of data bytes remaining = 173 (0x00AD)
  IP: ID = 0x878C; Proto = UDP; Len: 173
      IP: Version = 4 (0x4)
      IP: Header Length = 20 (0x14)
      IP: Service Type = 0 (0x0)
          IP: Precedence = Routine
          IP: ...0.... = Normal Delay
          IP: ....0... = Normal Throughput
          IP: .....0.. = Normal Reliability
      IP: Total Length = 173 (0xAD)
      IP: Identification = 34700 (0x878C)
      IP: Flags Summary = 0 (0x0)
          IP: .......0 = Last fragment in datagram
          IP: ......0. = May fragment datagram if necessary
      IP: Fragment Offset = 0 (0x0) bytes
      IP: Time to Live = 41 (0x29)
      IP: Protocol = UDP - User Datagram
      IP: Checksum = 0x9660
      IP: Source Address = 192.92.130.1
      IP: Destination Address = 16.183.32.63
      IP: Data: Number of data bytes remaining = 153 (0x0099)
  UDP: Src Port: DNS, (53); Dst Port: DNS (53); Length = 153 (0x99)
      UDP: Source Port = DNS
      UDP: Destination Port = DNS
      UDP: Total length = 153 (0x99) bytes
      UDP: UDP Checksum = 0x20D4
      UDP: Data: Number of data bytes remaining = 145 (0x0091)
  DNS: 0x7:Std Qry Resp. for www.infobel.be. of type Host Addr on class INET addr.
      DNS: Query Identifier = 7 (0x7)
      DNS: DNS Flags = Response, OpCode - Std Qry, RA Bits Set, RCode - No error
          DNS: 1............... = Response
          DNS: .0000........... = Standard Query
          DNS: .....0.......... = Server not authority for domain
          DNS: ......0......... = Message complete
          DNS: .......0........ = Iterative query desired
          DNS: ........1....... = Recursive queries supported by server
          DNS: .........000.... = Reserved
          DNS: ............0000 = No error
      DNS: Question Entry Count = 1 (0x1)
      DNS: Answer Entry Count = 1 (0x1)
      DNS: Name Server Count = 2 (0x2)
      DNS: Additional Records Count = 2 (0x2)
      DNS: Question Section: www.infobel.be. of type Host Addr on class INET addr.
          DNS: Question Name: www.infobel.be.
          DNS: Question Type = Host Address

page 26


Network Monitor trace  Thu 02/06/97 14:58:42  U:\cab.txt

          DNS: Question Class = Internet address class
      DNS: Answer section: www.infobel.be. of type Host Addr on class INET addr.
          DNS: Resource Name: www.infobel.be.
          DNS: Resource Type = Host Address
          DNS: Resource Class = Internet address class
          DNS: Time To Live = 4557 (0x11CD)
          DNS: Resource Data Length = 4 (0x4)
          DNS: IP address = 194.183.224.12
      DNS: Authority Section: infobel.be. of type Auth. NS on class INET addr.(2 records present)
          DNS: Resource Record: infobel.be. of type Auth. NS on class INET addr.
              DNS: Resource Name: infobel.be.
              DNS: Resource Type = Authoritative Name Server
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 604800 (0x93A80)
              DNS: Resource Data Length = 17 (0x11)
              DNS: Authoritative Name Server: ns.perceval.net.
          DNS: Resource Record: infobel.be. of type Auth. NS on class INET addr.
              DNS: Resource Name: infobel.be.
              DNS: Resource Type = Authoritative Name Server
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 604800 (0x93A80)
              DNS: Resource Data Length = 14 (0xE)
              DNS: Authoritative Name Server: ns.perceval.be.
      DNS: Additional Records Section: ns.perceval.net. of type Host Addr on class INET addr.(2 records present)
          DNS: Resource Record: ns.perceval.net. of type Host Addr on class INET addr.
              DNS: Resource Name: ns.perceval.net.
              DNS: Resource Type = Host Address
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 165624 (0x286F8)
              DNS: Resource Data Length = 4 (0x4)
              DNS: IP address = 194.183.224.1
          DNS: Resource Record: ns.perceval.be. of type Host Addr on class INET addr.
              DNS: Resource Name: ns.perceval.be.
              DNS: Resource Type = Host Address
              DNS: Resource Class = Internet address class
              DNS: Time To Live = 604800 (0x93A80)
              DNS: Resource Data Length = 4 (0x4)
              DNS: IP address = 194.183.227.1

00000:  00 00 F8 22 CD 22 AA 00 04 00 05 D6 08 00 45 00   ..."."........E.
00010:  00 AD 87 8C 00 00 29 11 96 60 C0 5C 82 01 10 B7   ......)..`.\....
00020:  20 3F 00 35 00 35 00 99 20 D4 00 07 80 80 00 01    ?.5.5.. .......
00030:  00 01 00 02 00 02 03 77 77 77 07 69 6E 66 6F 62   .......www.infob
00040:  65 6C 02 62 65 00 00 01 00 01 C0 0C 00 01 00 01   el.be...........

***********************************************************************************************************************************************************
/sbin/named debug info
----------------------

datagram from [10.0.2.1].53, fd 12, len 119; now Thu Feb  6 13:41:52 1997
ns_req(from=[10.0.2.1].53)
HEADER:
	opcode = QUERY, id = 3, rcode = NOERROR
	header flags:  qr aa rd ra
	qdcount = 1, ancount = 1, nscount = 2, arcount = 2

QUESTIONS:
	www.infobel.be, type = A, class = IN

ANSWERS:
	www.infobel.be
	type = A, class = IN, ttl = 2 hours, dlen = 4
	internet address = 194.183.224.12

NAME SERVERS:
	infobel.be
	type = NS, class = IN, ttl = 2 hours, dlen = 17
	domain name = ns.perceval.net

	infobel.be
	type = NS, class = IN, ttl = 2 hours, dlen = 14
	domain name = ns.perceval.be

ADDITIONAL RECORDS:
	ns.perceval.net
	type = A, class = IN, ttl = 1 day, dlen = 4
	internet address = 194.183.224.1

	.
	type = 43200, class = 0, ttl = 0 secs, dlen = 0
	???

qfindid(3)
Response (USER NORMAL -) nsid=3 id=9
resp: ancount 1, aucount 2, arcount 2
dovalidate(zone 0, flags 19)
dovalidate: dname www.infobel.be type 1 class 1 ttl 7200
validate(), d:www.infobel.be, s:[10.0.2.1], t:1, c:1
validation succeeded d:www.infobel.be, t:1, c:1
dovalidate(zone 0, flags 19)
dovalidate: dname infobel.be type 2 class 1 ttl 7200
validate(), d:infobel.be, s:[10.0.2.1], t:2, c:1
validation succeeded d:infobel.be, t:2, c:1
dovalidate(zone 0, flags 19)
dovalidate: dname infobel.be type 2 class 1 ttl 7200
validate(), d:infobel.be, s:[10.0.2.1], t:2, c:1
validation succeeded d:infobel.be, t:2, c:1
dovalidate(zone 0, flags 19)
dovalidate: dname ns.perceval.net type 1 class 1 ttl 86400
validate(), d:ns.perceval.net, s:[10.0.2.1], t:1, c:1
validation succeeded d:ns.perceval.net, t:1, c:1
FORMERR resp() from [10.0.2.1].53 size err 32, msglen 119
retry(x14001b860) id=9
give up
send_msg -> [10.0.2.1] (UDP 12 2931) id=9
qp 14001b860 q_id: 2304  q_nsid: 768 q_msglen: 32 q_naddr: 11 q_curaddr: 0
q_next: 0 q_link: 0
qremove(x14001b860)
unsched(0x14001b860, 9 )
Qfree( x14001b860 )
qfree: ns aos.arl.army.mil rcnt 2
qfree: nsdata 52043F80 rcnt 1
qfree: ns aos.arl.army.mil rcnt 1
qfree: nsdata 521905C0 rcnt 1
qfree: ns c.psi.net rcnt 1
qfree: nsdata 0C0421C0 rcnt 1
qfree: ns terp.umd.edu rcnt 1
qfree: nsdata 5A0A0880 rcnt 1
qfree: ns ns.nic.ddn.mil rcnt 1
qfree: nsdata 042470C0 rcnt 1
qfree: ns ns.nasa.gov rcnt 2
qfree: nsdata 0A106680 rcnt 1
qfree: ns ns.internic.net rcnt 1
qfree: nsdata 040029C6 rcnt 1
qfree: ns ns.nasa.gov rcnt 1
qfree: nsdata 0AC334C0 rcnt 1
qfree: ns nic.nordu.net rcnt 1
qfree: nsdata 119424C0 rcnt 1
qfree: ns ns1.isi.edu rcnt 1
qfree: nsdata 6B000980 rcnt 1
qfree: ns ns.isc.org rcnt 1
qfree: nsdata F10505C0 rcnt 1
    
T.RTitleUserPersonal
Name
DateLines
1778.1BIGUN::nessus.cao.dec.com::MayneWake up, time to dieThu Feb 06 1997 23:2612
> The global phenomene is that people in the internal network, doing
> web-access, alsways get an error the first time...

That's interesting: I always assumed that the internal browsers just send the 
URL to the proxy server and let it do the name lookups, therefore, web browsing 
on the internal network shouldn't involve name lookups from the clients. (This 
is backed up by a site I know that doesn't allow Internet name lookups from the 
internal network, but they can browse the Web just fine.)

Are the internal Web browsers configured fo a proxy?

PJDM
1778.2the problem stays the sameNETRIX::&quot;[email protected]&quot;Chris RoetsMon Feb 10 1997 03:139
Actually, the problem stays the same :

the internal machine does the nslookup pointing to the internal
dns server, who in turn contact the AFWNT server who give the problem
record back to the internal dns-server. The internal dns puts it in his 
cache, but returns an error.

Chris
[Posted by WWW Notes gateway]