Weird DNS issues with 10.6.7 Server
Hi, been having a problem with my DNS server, clients are able to resolve some hosts, but not others.
For example, If I run a dig search on one of the affected hosts I get:
dig www.yahoo.com
; <<>> DiG 9.6.0-APPLE-P2 <<>> www.yahoo.com
;; global options: +cmd
;; connection timed out; no servers could be reached
But running tcpdump at the same time, I can see that the server is responding, but the client is somehow not receiving it.
tcpdump -tttt -n -s 1500 -i en0 udp port 53
2011-08-02 12:48:35.749381 IP 192.168.2.108.58221 > 192.168.2.1.53: 46224+ A? www.yahoo.com. (31)
2011-08-02 12:48:35.873716 IP 192.168.2.1.53 > 192.168.2.108.58221: 46224 4/2/0 CNAME fp3.wg1.b.yahoo.com., CNAME any-fp3-lfb.wa1.b.yahoo.com., CNAME any-fp3-real.wa1.b.yahoo.com., A 209.191.122.70 (164)
2011-08-02 12:48:40.749482 IP 192.168.2.108.58221 > 192.168.2.1.53: 46224+ A? www.yahoo.com. (31)
2011-08-02 12:48:40.750136 IP 192.168.2.1.53 > 192.168.2.108.58221: 46224 4/2/0 CNAME fp3.wg1.b.yahoo.com., CNAME any-fp3-lfb.wa1.b.yahoo.com., CNAME any-fp3-real.wa1.b.yahoo.com., A 209.191.122.70 (164)
2011-08-02 12:48:45.749678 IP 192.168.2.108.58221 > 192.168.2.1.53: 46224+ A? www.yahoo.com. (31)
2011-08-02 12:48:45.750116 IP 192.168.2.1.53 > 192.168.2.108.58221: 46224 4/2/0 CNAME fp3.wg1.b.yahoo.com., CNAME any-fp3-lfb.wa1.b.yahoo.com., CNAME any-fp3-real.wa1.b.yahoo.com., A 209.191.122.70 (164)
And if I try to resolve to another DNS server I do get an answer
dig www.yahoo.com @8.8.8.8
; <<>> DiG 9.6.0-APPLE-P2 <<>> www.yahoo.com @8.8.8.8
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 49432
;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;www.yahoo.com. IN A
;; ANSWER SECTION:
www.yahoo.com. 280 IN CNAME fp3.wg1.b.yahoo.com.
fp3.wg1.b.yahoo.com. 41 IN CNAME any-fp3-lfb.wa1.b.yahoo.com.
any-fp3-lfb.wa1.b.yahoo.com. 281 IN CNAME any-fp3-real.wa1.b.yahoo.com.
any-fp3-real.wa1.b.yahoo.com. 41 IN A 69.147.125.65
any-fp3-real.wa1.b.yahoo.com. 41 IN A 209.191.122.70
any-fp3-real.wa1.b.yahoo.com. 41 IN A 67.195.160.76
;; Query time: 46 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Tue Aug 2 12:51:40 2011
;; MSG SIZE rcvd: 160
tcpdump -tttt -n -s 1500 -i en0 udp port 53
2011-08-02 12:51:40.377033 IP 192.168.2.108.60998 > 8.8.8.8.53: 49432+ A? www.yahoo.com. (31)
2011-08-02 12:51:40.423394 IP 8.8.8.8.53 > 192.168.2.108.60998: 49432 6/0/0 CNAME fp3.wg1.b.yahoo.com., CNAME any-fp3-lfb.wa1.b.yahoo.com., CNAME any-fp3-real.wa1.b.yahoo.com., A 69.147.125.65, A 209.191.122.70, A 67.195.160.76 (160)
When I run dig with a host that resolves I get the following:
dig www.google.com
; <<>> DiG 9.6.0-APPLE-P2 <<>> www.google.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 28956
;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 4, ADDITIONAL: 0
;; QUESTION SECTION:
;www.google.com. IN A
;; ANSWER SECTION:
www.google.com. 535755 IN CNAME www.l.google.com.
www.l.google.com. 65 IN A 74.125.47.106
www.l.google.com. 65 IN A 74.125.47.147
www.l.google.com. 65 IN A 74.125.47.99
www.l.google.com. 65 IN A 74.125.47.103
www.l.google.com. 65 IN A 74.125.47.104
www.l.google.com. 65 IN A 74.125.47.105
;; AUTHORITY SECTION:
google.com. 103690 IN NS ns4.google.com.
google.com. 103690 IN NS ns1.google.com.
google.com. 103690 IN NS ns2.google.com.
google.com. 103690 IN NS ns3.google.com.
;; Query time: 1 msec
;; SERVER: 192.168.2.1#53(192.168.2.1)
;; WHEN: Tue Aug 2 12:53:40 2011
;; MSG SIZE rcvd: 220
and while running tcpdump -tttt -n -s 1500 -i en0 udp port 53 i get:
2011-08-02 12:53:40.434780 IP 192.168.2.108.58569 > 192.168.2.1.53: 28956+ A? www.google.com. (32)
2011-08-02 12:53:40.435239 IP 192.168.2.1.53 > 192.168.2.108.58569: 28956 7/4/0 CNAME www.l.google.com., A 74.125.47.106, A 74.125.47.147, A 74.125.47.99, A 74.125.47.103, A 74.125.47.104, A 74.125.47.105 (220)
Any help would be appreciated, this is driving me crazy.
Intel Xserve, Mac OS X (10.6.7)