[dns-operations] ip id from servers

sthaug at nethelp.no sthaug at nethelp.no
Thu Mar 11 08:05:57 UTC 2010


> I can only confirm a few of these from here (Oslo, Norway). What I see
> is pretty bad. *All* of the DNS answers I receive from these 3 servers
> have IP ID 0:
> 
> > 193.0.0.195   ns-pri.ripe.net.
> > 192.54.112.30 h.gtld-servers.net.
> > 202.12.28.140 sec3.apnic.net.

Let me modify that slightly for h.gtld-servers.net. I see mostly IP ID
0, with the occasional non-zero value. A quick guess would be a load
balancing cluster where the servers are using different TCP/IP stacks.

Steinar Haug, Nethelp consulting, sthaug at nethelp.no
----------------------------------------------------------------------
09:02:19.575216 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 169) 192.54.112.30.53 > 193.75.110.74.50336: 62976- 0/3/3 (141)
09:02:19.589577 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 109) 192.54.112.30.53 > 193.75.110.74.40515: 60879- 0/2/0 (81)
09:02:19.606187 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 139) 192.54.112.30.53 > 193.75.110.74.60128: 7906- 0/2/2 (111)
09:02:19.693003 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 152) 192.54.112.30.53 > 193.75.110.74.25234: 53553- 0/2/2 (124)
09:02:19.705121 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 155) 192.54.112.30.53 > 193.75.110.74.65015: 22165- 0/2/2 (127)
09:02:19.724611 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 148) 192.54.112.30.53 > 193.75.110.74.37388: 22994- 0/4/0 (120)
09:02:19.930999 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 104) 192.54.112.30.53 > 193.75.110.74.19197: 53- 0/2/0 (76)
09:02:19.934983 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 136) 192.54.112.30.53 > 193.75.110.74.59487: 48008- 0/2/2 (108)
09:02:19.987453 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 133) 192.54.112.30.53 > 193.75.110.74.16736: 57894- 0/2/2 (105)
09:02:20.012226 IP (tos 0x0, ttl 246, id 18220, offset 0, flags [DF], proto UDP (17), length 123) 192.54.112.30.53 > 193.75.110.74.61602: 10997- 0/3/0 (95)
09:02:20.026806 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 246) 192.54.112.30.53 > 193.75.110.74.49638: 41128- 0/5/5 (218)
09:02:20.041549 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 146) 192.54.112.30.53 > 193.75.110.74.31436: 41603- 0/2/2 (118)
09:02:20.042672 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 173) 192.54.112.30.53 > 193.75.110.74.48625: 22003- 0/3/3 (145)
09:02:20.088160 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 132) 192.54.112.30.53 > 193.75.110.74.48846: 17123- 0/3/1 (104)
09:02:20.134503 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 164) 192.54.112.30.53 > 193.75.110.74.63041: 38921- 0/2/2 (136)
09:02:20.195706 IP (tos 0x0, ttl 246, id 24919, offset 0, flags [DF], proto UDP (17), length 251) 192.54.112.30.53 > 193.75.110.74.23162: 21760- 0/5/5 (223)
09:02:20.200958 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 142) 192.54.112.30.53 > 193.75.110.74.31613: 19185- 0/2/2 (114)
09:02:20.224062 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 130) 192.54.112.30.53 > 193.75.110.74.57075: 38051- 0/2/2 (102)
09:02:20.589719 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 214) 192.54.112.30.53 > 193.75.110.74.33430: 19329- 0/4/4 (186)
09:02:20.710770 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 143) 192.54.112.30.53 > 193.75.110.74.31075: 20151- 0/2/2 (115)
09:02:20.720642 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 143) 192.54.112.30.53 > 193.75.110.74.62784: 23482- 0/2/2 (115)
09:02:20.771743 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 143) 192.54.112.30.53 > 193.75.110.74.56270: 62685- 0/2/2 (115)
09:02:20.810712 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 117) 192.54.112.30.53 > 193.75.110.74.34620: 14332- 0/2/0 (89)
09:02:20.866301 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 178) 192.54.112.30.53 > 193.75.110.74.37543: 43045- 0/3/3 (150)
09:02:21.013338 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto UDP (17), length 109) 192.54.112.30.53 > 193.75.110.74.47085: 1247- 0/2/0 (81)



More information about the dns-operations mailing list