TT Lab
Get started
Learn Learning paths Courses

Network Troubleshooting

Digging Into DNS With dig

Continue in TT Lab

Goal

You do lookups by record type with dig, read the TTL and the negative cache, and build for yourself the point where the answers of getent and dig diverge.

Why it matters

You must read dig output starting from status and flags. NXDOMAIN (the name itself does not exist) and NOERROR + ANSWER 0 (the name exists but only that type does not) are completely different situations and call for different responses. Without the aa flag, the answer came from a cache, which is why the TTL decreases. And because dig does not look at /etc/hosts, it can give an answer different from getent for the same name — that difference is the location of the cause.

Steps

  1. Create the /root/dns directory and save only the lines starting with nameserver in /etc/resolv.conf to /root/dns/nameserver.txt.
  2. Save only the A record value of example.com to /root/dns/a.txt. The file must have at least one IPv4 address line.
  3. Save the MX, NS, and TXT of google.com to /root/dns/mx.txt, /root/dns/ns.txt, and /root/dns/txt.txt respectively. None of the three files may be empty.
  4. Print only the answer section of example.com and save it to /root/dns/ttl1.txt, and after waiting 5 seconds or more, make /root/dns/ttl2.txt the same way. The second TTL must not be larger than the first.
  5. Save the reverse lookup result of 8.8.8.8 to /root/dns/ptr.txt.
  6. Look up labhub-does-not-exist-9137.example.com and save the full output to /root/dns/nxdomain.txt. The file must contain both status: NXDOMAIN and an SOA record.
  7. After adding 10.77.0.1 www.example.com to /etc/hosts, save the getent hosts www.example.com result to /root/dns/getent-www.txt and the dig +short www.example.com result to /root/dns/dig-www.txt. The two results must differ.
  8. Make /root/dns/report.txt with the following 5 lines. NAMESERVERS=<1번 파일의 줄 수> / A_COUNT=<2번 파일의 줄 수> / PTR=<5번에서 얻은 이름, 끝의 점 제외> / HOSTS_WINS=<7번 getent 결과의 IP> / DNS_SAYS=<7번 dig 결과의 첫 번째 IP> (that is, the number of lines in the step 1 file, the number of lines in the step 2 file, the name obtained in step 5 without the trailing dot, the IP of the step 7 getent result, and the first IP of the step 7 dig result)

Notes

Reading the resolver configuration

Create the /root/dns directory and save only the lines starting with nameserver in /etc/resolv.conf to /root/dns/nameserver.txt.

You need only the lines in resolv.conf that start with nameserver. There may be several.

Forward lookup

Save only the A record value of example.com to /root/dns/a.txt. The file must have at least one IPv4 address line.

If you need only the value, there is a short output option. An A record must be in IPv4 address format.

Lookups by record type

Save the MX, NS, and TXT of google.com to /root/dns/mx.txt, /root/dns/ns.txt, and /root/dns/txt.txt respectively. None of the three files may be empty.

With dig you can specify the type with -t, or simply attach the type after the name. An MX value is a pair of a priority number and a host name.

Observing the TTL decrease

Print only the answer section of example.com and save it to /root/dns/ttl1.txt, and after waiting 5 seconds or more, make /root/dns/ttl2.txt the same way. The second TTL must not be larger than the first.

If you print only the answer section, the TTL comes out in the second column. Run the same query twice with a short interval in between.

Reverse lookup

Save the reverse lookup result of 8.8.8.8 to /root/dns/ptr.txt.

dig has a dedicated option that finds the PTR when you put in an IP. The result is a name ending in a dot.

A nonexistent name and the negative cache

Look up labhub-does-not-exist-9137.example.com and save the full output to /root/dns/nxdomain.txt. The file must contain both status: NXDOMAIN and an SOA record.

The status is on the header line. The SOA comes in the AUTHORITY section, and the last number is the MINIMUM.

The point where getent and dig diverge

After adding 10.77.0.1 www.example.com to /etc/hosts, save the getent hosts www.example.com result to /root/dns/getent-www.txt and the dig +short www.example.com result to /root/dns/dig-www.txt. The two results must differ.

This step has meaning only if the IP you put in hosts differs from the IP DNS gives. Save the two results separately.

There is one trap. getent hosts <이름> asks first for IPv6 and asks for IPv4 again only when there is no answer (the placeholder is the name). But the line you put in hosts is IPv4 only, so if that name has an AAAA record, the v6 lookup passes over hosts and goes out to DNS, and the IPv6 address comes out first. It looks as if hosts were ignored, but that is not so — if you ask only the v4 family with getent ahostsv4 <이름>, the hosts value comes out as it is. Use that in this step.

Lookup summary report

Make /root/dns/report.txt with the following 5 lines. NAMESERVERS=<1번 파일의 줄 수> / A_COUNT=<2번 파일의 줄 수> / PTR=<5번에서 얻은 이름, 끝의 점 제외> / HOSTS_WINS=<7번 getent 결과의 IP> / DNS_SAYS=<7번 dig 결과의 첫 번째 IP> (that is, the number of lines in the step 1 file, the number of lines in the step 2 file, the name obtained in step 5 without the trailing dot, the IP of the step 7 getent result, and the first IP of the step 7 dig result)

Just gather the earlier results as key=value. For the items that count, counting by number of lines is enough.