DNS queries for arduino.cc are dropped by IPS

Hi,

running an OpenSuSE machine behind IPFire as well, I just tried to reproduce the issue with www.arduino.cc (while I did not experience notable DNS issues on that operating system combination before).

Did not work tough…

$ dig soa www.arduino.cc

; <<>> DiG 9.16.6 <<>> soa www.arduino.cc
;; global options: +cmd
;; connection timed out; no servers could be reached

… but for a different reason:

[root@maverick ~]# grep ".cc TLD" /var/log/suricata/fast.log
02/21/2022-23:15:43.594855  [Drop] [**] [1:2027758:5] ET DNS Query for .cc TLD [**] [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} x:37883 -> x:53
02/21/2022-23:15:48.588608  [Drop] [**] [1:2027758:5] ET DNS Query for .cc TLD [**] [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} x:37883 -> x:53
02/21/2022-23:15:53.590232  [Drop] [**] [1:2027758:5] ET DNS Query for .cc TLD [**] [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} x:37883 -> x:53

While this might be a bit off-topic, I think it makes sense to double-check the IPS configuration, to avoid it to drop DNS queries (in addition to the actual bug we are trying to track down here). Just thought I’d mention that… :slight_smile:

Thanks, and best regards,
Peter Müller

3 Likes