DNS-server broken after update Core 199 random for 2-3 hours per day

Hello,

after the core 199 update I notice regular problems with resolving local DNS names, once or two times per day i get DNS-Server Status broken. All Services a working. After two or 3 reboots, which are now taking up to 5 minutes the system sometimes is working again. Sometimes after 3 hours, without reboot the DNS-Server status comes up again working. No configuration changes has been done. It almost appears after 22-24 hours after the DNS-Server status working has appeared. I have also no longer acces via ssh with putty due to no availble ssh keys negotiation, which also started with last core update.

Does anyone see similar problems? I have no idea what the problem could be? i pretend to a bug with DNSSEC for the DNS-Server problem

@newbie71 Welcome to the community.

To answer your question, it would be nice to know your unchanged configuration.
Sometimes a config may work for years, but some corrections to programs can change the behaviour.
Do you have system logs which document what’s going on?

What do you need?

here is the screenshot from the DNS Section, since i have no ssh access due to issues since the update i cannot extract logs via cli.

Press the button marked Check DNS Servers or in your case DNS-Server prufen.

If each of the servers has a green OK then they are working fine.

When no problems are occurring then you will see

If they have a red Error label then place your mouse pointer over the Error label and wait for a few seconds and then you will get a short message indicating what the problem is.


The error message was longer but was cut short by the screenshot software as I didn’t select a large enough region but it gives you the idea.

More details of any issues can be found in the WUI menu Logs - System Logs and then in the drop down box labelled Section: select DNS: Unbound and then press the Update button and you will get the logs for the DNS for the selected date.

2 Likes

currently it works. But i had now the last week every day an outage. No changes have been made. I did the DNS-Server “check again” prüfen, it remains broken, server cannor be reached or resolved

So you are saying that it currently works.

By this do you mean that when it was not working you then got this message or that you also have that message now? Was this message from holding the mouse pointer over the red Error Message. Do all 10 of your DNS servers you have listed all show a red Error?
Do you also at this time get a red Broken at the top left hand part of the DNS Server WUI page?

If the above is the situation when you have the problem to use DNS then it could be that you are having some connection issue from your red interface to your ISP.

Next time you have the problem and it shows a red Broken label at the top left hand side of your DNS server page then go to the Logs - System Logs and select RED in the drop down box and press Update and then see if there are any messages about the connection being lost or losing the carrier signal.

1 Like

currently it works, my prediction is, that probably at 10:30 a.m. -10:45 a.m. the DNS-Server status will turn from working to broken. All Services in the Dashboard will be working. When i do a re-check all my DNS-Server (10 of them) will be broken after the re-check, i can do as many recheck as i want always messages “cannot be reached or resolved” after approx 3 hours suddenly the DNS-Server status is turning back working. I tried it with rebooting the firewall sometimes it helped sometimes not, sometimes it takes 5 shoots, or i leaved it for hours before it return working again. I do not make any changes, it worked for last 4 years without problems

When the problem occurs and I connect directly via LAN parallel to IPfire, it works without any problems. IPfire is connected to the WAN interface (Red) on port 2 of the Fritzbox 7950 and my notebook is then connected to port 3. I never have an ISP DNS problem, so I can rule that out.

When it next happens then look at the logs for the RED connection as I mentioned earlier to see what messages it shows. You might be able to connect in parallel but that does not mean that IPFire is staying connected on red.

Can you confirm what CU version you upgraded from?

The fact that all DNS servers show an Error Status and the overall DNS server page shows a Broken status suggests that unbound is unable to access any of the DNS servers.

1 Like

Hello,

I have upgraded from core 198 to core 199. I will Check the logs. I tried but i did not found the Red Interface i Had ipfire, unbound dns, system