[dns-operations] Blackhole IANA question

Alberto García Moyano alberto.garciamoyano at gmail.com
Thu Aug 5 14:05:34 UTC 2010


Thank you very much for your help. Traceroute from my DNS server is blocked:

traceroute blackhole-1.iana.org
traceroute: Warning: Multiple interfaces found; using 213.4.132.1 @ qfe0
traceroute to blackhole-1.iana.org (192.175.48.6), 30 hops max, 40 byte
packets
 1  * * *
 2  * * *
 3  * * *
 4  * * *
 5  * * *
 6  * * *
 7  * * *
 8  * * *
 9  * * *
10  * * *
11  * * *
12  * * *
13  * * *
14  * * *
15  * * *
16  * * *
17  * * *
18  * * *
19  * * *
20  * * *
21  * * *
22  * * *
23  * * *
24  * * *
25  * * *
26  * * *
27  * * *
28  * * *
29  * * *
30  * * *
tdns1d:/#


And dig command give me another timeout:

dig @blackhole-1.iana.org -x 192.168.1.1
; <<>> DiG 8.4 <<>> @blackhole-1.iana.org -x
; (1 server found)
;; res options: init recurs defnam dnsrch
;; res_nsend: Connection timed out
tdns1d:/# dig @blackhole-2.iana.org -x 192.168.1.1
; <<>> DiG 8.4 <<>> @blackhole-2.iana.org -x
; (1 server found)
;; res options: init recurs defnam dnsrch
;; res_nsend: Connection timed out

But i can ping them and ,also, i can open a tcp session.So ip connectivity
exists.

tdns1d:/# ping blackhole-1.iana.org
blackhole-1.iana.org is alive
tdns1d:/# telnet blackhole-1.iana.org 53
Trying 192.175.48.6...
Connected to blackhole-1.iana.org.

This is a trace from one of our routers to blackhole-1.iana.org

Tracing the route to blackhole-1.iana.org (192.175.48.6)
  1 22.213.4.128.22 0 msec 0 msec 4 msec
  2 234.Red-80-58-81.staticIP.rima-tde.net (80.58.81.234) 0 msec 0 msec 0
msec
  3 134.Red-80-58-80.staticIP.rima-tde.net (80.58.80.134) 4 msec 0 msec 4
msec
  4 129.Red-80-58-80.staticIP.rima-tde.net (80.58.80.129) 0 msec 0 msec 4
msec
  5 98.Red-80-58-86.staticIP.rima-tde.net (80.58.86.98) 0 msec 0 msec 4 msec
  6 193.149.1.170 0 msec 0 msec 4 msec
  7 ae2-0.mil-cal-score-2-re0.interoute.net (89.202.161.26) 48 msec 64 msec
48 msec
  8 ae0-0.mil-cal-score-1-re0.interoute.net (89.202.146.85) 56 msec 52 msec
52 msec
  9 ae2-0.vie-per-score-2-re1.interoute.net (212.23.43.29) 52 msec 48 msec
52 msec
 10 ae1-0.bts-001-score-1-re0.interoute.net (84.233.147.13) 52 msec 52 msec
52 msec
 11 ae0-0.bts-001-score-2-re0.interoute.net (84.233.147.2) 52 msec 48 msec
52 msec
 12 ae1-0.bud-001-score-2-re0.interoute.net (84.233.147.113) 52 msec 52 msec
64 msec
 13 84.233.171.4 52 msec 52 msec 48 msec
 14 gi1-0-2.c3750-border-1.atw.hu (88.151.96.173) 44 msec 44 msec 44 msec
 15 gi3-4-2.c6509-core-1.atw.hu (88.151.96.178) 44 msec 88 msec 40 msec
 16 88.151.96.2 44 msec 48 msec 44 msec
 17  *  *  *
 18  *  *  *
 19  *  *  *
 20  *  *  *
 21  *  *  *
 22  *  *  *
 23  *  *  *
 24  *  *  *
 25  *  *  *
 26  *  *  *
 27  *  *  *
 28  *  *  *
 29  *  *  *
 30  *  *  *


Again, thank you very much for your help.



2010/8/5 Florian Weimer <fweimer at bfk.de>

> * Alberto García Moyano:
>
> > I am Alberto Garcia, Coms admin in a ISP. I dont really know if you can
> > answer this question, but IANA has sent me to you... so this is my
> problem:
> >
> > we are sending inverse queries to these blackhole servers:
> >
> > "blackhole-1.iana.org" and "blackhole-2.iana.org",
>
> These servers are in a special netblock announced by AS112 and are
> essentially operated as public anycast (that is, anybody can run those
> servers).
>
> So you need to provide traceroutes and "show ip bgp" (Quagga, IOS) or
> "show route" (JUNOS) output, or we can't help you.
>
> --
> Florian Weimer                <fweimer at bfk.de>
> BFK edv-consulting GmbH       http://www.bfk.de/
> Kriegsstraße 100              tel: +49-721-96201-1
> D-76133 Karlsruhe             fax: +49-721-96201-99
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20100805/8796ea6a/attachment.html>


More information about the dns-operations mailing list