Core203 DNS Check - Error

Hello

I updated to Core 203 today and received many error messages during the Pakfire update.

When I switched to the DNS section of ipfire, this is what I saw.

I then removed the entry for 9.9.9.9 and added it back after a few minutes. The DNS server check was then successful. After a while, the entry was marked with an error again, and the same thing happened when I tried adding 8.8.8.8.

When I only have the entry for recursor01.dns.lightningwirelabs.com, the search in Pakfire works fine.

The DNS firewall is active with the following lists.

That’s active for me, too

What else can I check, or what could be causing this behavior?

Paul

What error message does it show when you place your mouse pointer over the red Fehler status?

TLS, peer took too long to respond

The time on the system and in ipfire is correct and has no delay

What are your settings under the firewall option?

That indicates that knot tried to get a response but it took too long. The communication for peer tls validation was occurring but it just took too long.

That error message from my searching is an indication that either their server was overloaded at that time and therefore taking longer than it should do to respond or that there was some traffic bottleneck between yourself and their server. The message means that it took too long for the quad9 server to respond to the tls request

I just tried that dns server in my CU203 and it shows as a green OK. I will leave it in for an hour or so and see if it still shows the same status as you mentioned that for you it started okay but then stopped after a while. Can you say how long that while was?

Hello

When I enable 9.9.9.9 and then click “Check,” it shows green. If I run another check shortly afterward (within a minute), an error appears that persists even after further checks.

This also happens with 8.8.8.8 and 1.1.1.1.

Could it be that the providers are throttling this to a specific interval.

Even after restarting the knot-resolver, the behavior remains the same.

/etc/init.d/knot-resolver restart

Why am I having no problems with recursor01.dns.lightningwirelabs.com but do have problems with the other providers/entries?

Perhaps it would be worth trying kresctl cache clear after making several DNS configuration changes.

It seems that the DNS cache may persist even after restarting Knot Resolver or rebooting the system.

Edit : try dns.quad9.net instead dns9.quad9.net for DoT
Service Addresses & Features | Quad9

On my system, I had dns.quad9.net but the rDNS shows up as dns9.quad9.net

I ended up leaving my system for 1.5 hours as I was busy elsewhere. quad9 is still showing a green OK.

I have no idea.

It might be worth showing the Logs - System Logs and choosing Domain Name System in the drop down box labelled Section: and showing the logs for the period from when you enabled 9.9.9.9 till after you had the red Fehler response from the status. Maybe there is a bit more info available than in just the mouse pointer message.

I can’t see anything in the logs either.

As there is nothing in the knot logs then the issue is not with knot but most likely from either the dns server itself or some issue with the route from the dns server to your system.