Hello,
i have a strange problem with DNS unbound: IPFire 2.27 (x86_64) - Core Update 168
Static IP configuration via TV cable Modem to vodafone
If i call some Websites, here eg “disapo.de” , i get the error “site not found”
If i refresh the DNS server configuration by clicking “save” in the web-gui, the sites will be found.
If i wait 5 to 10 minutes and call the site again, i again get the error “site not found”
This happens only on very few, but always the same, sites.
The problem persists with other DNS servers.
Is there any idea, what to do?
thanks a lot for your help.
Vodafone have something called “SECURE DNS” or similar how impossibilite to use another DNSs. I think is in Router mode. If You have in this mode, You need unable this. If that is not the case, maybe another guy can help you.
as i wrote, TV cable modem with multiple fixed IP’s.
Next query, a few minutes later
|11:00:41|unbound: [1814:0]|error: SERVFAIL <www.disapo.de. A IN>: all the configured stub or forward serve rs failed, at zone . from (inet_ntop_error) upstream server timeout|
At this time mark ( |10:15:52 ) the query works
10:15:52
unbound: [1814:0]
info: generate keytag query _ta-4a5c-4f66. NULL IN
This is saying that unbound had a timeout waiting for a response from the upstream DNS server.
Unbound then won’t use that server for a short while and will try one of the other dns servers from the list you have defined and enabled. Sometimes servers can timeout because they are very busy but will be able to respond again after a short while. Alternatively if the dns server has had some form of outage then it will have repetitive fails. Unbound will then mark that dns server down in terms of using it.
It could be that the specific website(s) you are trying to access have some problem with their dns records and it is taking too long to resolve. I am not familiar enough with the DNS system to be sure on that.
Do you have multiple dns servers listed and enabled in the IPFire DNS Server page?
If yes then I don’t understand why the timeout would persist across other dns servers unless there is some problem with the dns records for that website.
When unbound fails to get the dns info and you get a site not found error, does that stay with that error when you repetitively try and access it until you re-select the dns servers on the IPFire wui page. If yes, then when you have the problem try running a dig or kdig command on the website to see what messages come back. There might be a bit more info than what unbound shows.
i finally found thr cause, since my Mega-Account stopt working as well.
Disabeling the intrusion-detection on the green interface fixed tht problem.
As described here: