2015. július 28., kedd

Ugly bug in Draytek Vigor firewall?

One day I came across a unique error. A client reported that they were unable to query any nameserver outside their network, except for the case they query standard A records. So, A records worked fine but, e.g. NS or MX records failed with timeout. Local DNS servers was properly set with valid forwarders.
So, we experienced:
nslookup    
Default Server:  dc01.hq.local           
Address:  192.168.80.248                                                                 

> google.org
Server:  dc01.hq.local                   
Address:  192.168.80.248

Non-authoritative answer:                       
Name:    google.org                             
Address:  216.239.32.27                                                                         

> set type=mx 
> google.org                                 
Server:  dc01.hq.local                   
Address:  192.168.80.248                                                                       

DNS request timed out.                              
timeout was 2 seconds.                      
*** Request to dc01.hq.local timed-out   

> server 8.8.8.8                                   
Default Server:  google-public-dns-a.google.com           
Address:  8.8.8.8        

> google.org                            
Server:  google-public-dns-a.google.com        
Address:  8.8.8.8

DNS request timed out.                              
timeout was 2 seconds.                      
*** Request to google-public-dns-a.google.com timed-out      

What a riddle! Guess that! :)
After three hours it turned out that in their Vigor 2925 firewall router there was a built-in rule called "xNETBios > DNS" in the section called "Data filter" (very informative names by Draytek guys, phuhh). That blocked such special DNS queries - even if it was DISABLED!
Default factory settings

Factory settings


In the end I had to disable the entire Data Filter section - in that way, external DNS queries got to work as expected. I'm still unable to find any explanation for this.

Model Name : Vigor2925n
Firmware Version : 3.7.6
Build Date/Time : Nov 17 2014 17:20:57
Working

Nincsenek megjegyzések:

Megjegyzés küldése