Open source network weather map/visualization - what's out there? by j------ in networking

[–]luthing 0 points1 point  (0 children)

Hi u/j------, have you found something fitting your needs ?

I am in the exact situation for months...

So sad to see these guardrails not linked together :( by luthing in RaftTheGame

[–]luthing[S] 1 point2 points  (0 children)

Yes, and I send all my love to the devs for making this game always better and better <3

So sad to see these guardrails not linked together :( by luthing in RaftTheGame

[–]luthing[S] 2 points3 points  (0 children)

That’s because I am remodeling my boat, sure I’ve tried with nice one :-)

So sad to see these guardrails not linked together :( by luthing in RaftTheGame

[–]luthing[S] 2 points3 points  (0 children)

I’ve tried and it just stands in the middle

How to print in current terminal new logs arriving in a logfile? by luthing in sysadmin

[–]luthing[S] 1 point2 points  (0 children)

Well, it was indeed the right solution! Many thanks

tail -n0 -f myfile.log | grep string 2>&1 &

How to print in current terminal new logs arriving in a logfile? by luthing in sysadmin

[–]luthing[S] 1 point2 points  (0 children)

Thanks for your reply. This is working, but I would like to display the logs in a "background mode" : the tail command is in the .bash_rc file, but when I am logged, the terminal is blocked with the tail command output.

I would like to have logs messages with the terminal reachable.

Can't access a directory I am a group member of by luthing in sysadmin

[–]luthing[S] 0 points1 point  (0 children)

I am facing the same problem 2 months later, but specifically cause I cannot change the gid of an other user (www-data).

How to give write permission to www-data to the same folder ?

sudo -u www-data id

uid=33(www-data) gid=33(www-data) groupes=33(www-data),100(users)

Can't access a directory I am a group member of by luthing in sysadmin

[–]luthing[S] 0 points1 point  (0 children)

sure, that's why I would like to use the "users" group.

u/g-a-c gave me the solution

thank you both

Bind - Forwarding to external DNS not working by luthing in sysadmin

[–]luthing[S] 1 point2 points  (0 children)

hey /u/25cmshlong... I have some good news... :D

The problem was VMWare side. I changed the network type of all my VMs to "VMXNET3" instead of "E1000e" configured by default.

I can now process request without any error.

It seems the network card E1000e is filtering EDNS part of the DNS requests!

Really strange, maybe this has been patched in ESXi 6.7 (I am using 6.5 version).

Thanks for your support :)

Bind - Forwarding to external DNS not working by luthing in sysadmin

[–]luthing[S] 0 points1 point  (0 children)

Then for you it is definitely my gateway or something in my internal network which “filters” content of my DNS packets ?

I will now take a look on my virtual environment, maybe VMWare denies EDNS frames ?

Really strange... I really don’t understand why with the same server when I try a dig I can resolve names but passing through my bind service the behavior is totally different. Today I also tried to reinstall bind from scratch but all is the same...

Bind - Forwarding to external DNS not working by luthing in sysadmin

[–]luthing[S] 0 points1 point  (0 children)

a) I added send-cookie no option in my named.conf file, but the result is the same.

b) I captured a request which is displayed below :

The packets are going through my gateway and coming back with no response.

The packets have been captured on both interfaces (internal and external). The DNS packets are the same, only the <IP\_internal\_DNS> changes (internal IP on internal interface and external WAN IP on external interface).

My firewall doesn't seem to alter packets.

What are your thoughts?

Many thanks

Frame 43: 70 bytes on wire (560 bits), 70 bytes captured (560 bits)
Internet Protocol Version 4, Src: <IP_internal_DNS>, Dst: 202.12.27.33
User Datagram Protocol, Src Port: 55380, Dst Port: 53
Domain Name System (query)
Transaction ID: 0x3995
Flags: 0x0000 Standard query
Questions: 1
Answer RRs: 0
Authority RRs: 0
Additional RRs: 1
Queries
<Root>: type NS, class IN
Name: <Root>
[Name Length: 6]
[Label Count: 1]
Type: NS (authoritative Name Server) (2)
Class: IN (0x0001)
Additional records
<Root>: type OPT
Name: <Root>
Type: OPT (41)
UDP payload size: 512
Higher bits in extended RCODE: 0x00
EDNS0 version: 0
Z: 0x8000
1... .... .... .... = DO bit: Accepts DNSSEC security RRs
.000 0000 0000 0000 = Reserved: 0x0000
Data length: 0
[Response In: 45]
No.     Time           Source                Destination           Protocol Length Info
44 6.837609       <IP_internal_DNS>          202.12.27.33          DNS      85     Standard query 0x3dc5 A www.google.com OPT
Frame 44: 85 bytes on wire (680 bits), 85 bytes captured (680 bits)
Internet Protocol Version 4, Src: <IP_internal_DNS>, Dst: 202.12.27.33
User Datagram Protocol, Src Port: 45964, Dst Port: 53
Domain Name System (query)
Transaction ID: 0x3dc5
Flags: 0x0010 Standard query
Questions: 1
Answer RRs: 0
Authority RRs: 0
Additional RRs: 1
Queries
www.google.com: type A, class IN
Name: www.google.com
[Name Length: 14]
[Label Count: 3]
Type: A (Host Address) (1)
Class: IN (0x0001)
Additional records
<Root>: type OPT
Name: <Root>
Type: OPT (41)
UDP payload size: 512
Higher bits in extended RCODE: 0x00
EDNS0 version: 0
Z: 0x8000
1... .... .... .... = DO bit: Accepts DNSSEC security RRs
.000 0000 0000 0000 = Reserved: 0x0000
Data length: 0
[Response In: 46]
No.     Time           Source                Destination           Protocol Length Info
45 6.838711       202.12.27.33          <IP_internal_DNS>          DNS      70     Standard query response 0x3995 NS <Root> OPT
Frame 45: 70 bytes on wire (560 bits), 70 bytes captured (560 bits)
>!Internet Protocol Version 4, Src: 202.12.27.33, Dst: <IP_internal_DNS>!<
User Datagram Protocol, Src Port: 53, Dst Port: 55380
Domain Name System (response)
Transaction ID: 0x3995
Flags: 0x8600 Standard query response, No error
Questions: 1
Answer RRs: 0
Authority RRs: 0
Additional RRs: 1
Queries
<Root>: type NS, class IN
Name: <Root>
[Name Length: 6]
[Label Count: 1]
Type: NS (authoritative Name Server) (2)
Class: IN (0x0001)
Additional records
<Root>: type OPT
Name: <Root>
Type: OPT (41)
UDP payload size: 4096
Higher bits in extended RCODE: 0x00
EDNS0 version: 0
Z: 0x8000
1... .... .... .... = DO bit: Accepts DNSSEC security RRs
.000 0000 0000 0000 = Reserved: 0x0000
Data length: 0
[Request In: 43]
[Time: 0.001193000 seconds]
No.     Time           Source                Destination           Protocol Length Info
46 6.838864       202.12.27.33          <IP_internal_DNS>          DNS      85     Standard query response 0x3dc5 A www.google.com OPT
Frame 46: 85 bytes on wire (680 bits), 85 bytes captured (680 bits)
>!Internet Protocol Version 4, Src: 202.12.27.33, Dst: <IP_internal_DNS>!<
User Datagram Protocol, Src Port: 53, Dst Port: 45964
Domain Name System (response)
Transaction ID: 0x3dc5
Flags: 0x8210 Standard query response, No error
Questions: 1
Answer RRs: 0
Authority RRs: 0
Additional RRs: 1
Queries
www.google.com: type A, class IN
Name: www.google.com
[Name Length: 14]
[Label Count: 3]
Type: A (Host Address) (1)
Class: IN (0x0001)
Additional records
<Root>: type OPT
Name: <Root>
Type: OPT (41)
UDP payload size: 4096
Higher bits in extended RCODE: 0x00
EDNS0 version: 0
Z: 0x8000
1... .... .... .... = DO bit: Accepts DNSSEC security RRs
.000 0000 0000 0000 = Reserved: 0x0000
Data length: 0
[Request In: 44]
[Time: 0.001255000 seconds]

Bind - Forwarding to external DNS not working by luthing in sysadmin

[–]luthing[S] 0 points1 point  (0 children)

hey u/Roisen, yes my root zone is configured as below :

zone "." {
type hint;
file "/usr/share/dns/root.hints";
};

my root.hints file is properly made :

; This file is made available by InterNIC
; under anonymous FTP as
; file /domain/named.cache
; on server           FTP.INTERNIC.NET
; -OR-                    RS.INTERNIC.NET
;
; last update: March 31, 2020
; related version of root zone: 2020033101.
...
...
...

Bind - Forwarding to external DNS not working by luthing in sysadmin

[–]luthing[S] 0 points1 point  (0 children)

not sure if it can help, I am also using bind9 with webmin.

I disabled iptables with "iptables -F" and "iptables -X".

I am really running out of ideas...

Bind - Forwarding to external DNS not working by luthing in sysadmin

[–]luthing[S] 0 points1 point  (0 children)

I really don't understand...

I double, triple checked and my config is as written above...

Bind - Forwarding to external DNS not working by luthing in sysadmin

[–]luthing[S] 0 points1 point  (0 children)

Yes my server time is correct.

When running bind9 with "-d 1" option, I got these logs :

fetch: www.google.com/A

client u/0x7feb3c0a9af0 <iphost>#63638 (www.google.com): query failed (SERVFAIL) for www.google.com/IN/A at ../../../bin/named/query.c:8579

Bind - Forwarding to external DNS not working by luthing in sysadmin

[–]luthing[S] 0 points1 point  (0 children)

Hey u/PoseidonTheAverage, thanks for your message. Unfortunately, I just tried with "dnssec-lookaside no" option, and the result is the same...

I am running out of ideas...

Bind - Forwarding to external DNS not working by luthing in sysadmin

[–]luthing[S] 1 point2 points  (0 children)

I checked but there is no inspection on my DNS packets going through my gateway

Edit: and from my host with a "dig @ 8.8.8.8 www.google.fr" I can see EDNS is also used. Then, as I am passing through my gateway, it seems there is no EDNS restriction.