Nenavadno veliko AAAA poizvedb
Malo prej sem se vrnil od našega hostmastra, ki je na mojo prošnjo napisal en grep “IN AAAA ” |wc -l po LOG-ih našega glavnega DNS strežnika. Rezultat je bil presenetljiv! Število AAAA poizvedb je mnogo večje, kot sem pričakoval. Razmerje med številom A in AAAA poizvedb je bilo pribl. 10:1 !?
Morda pa nam je IPv6 bližje, kot si mislimo?
Matjaž6
Vaš IP naslov (ali ste na IPv6 ?):
3.15.143.18
To je to!!! Great news 🙂
A lahko to omenim v mojem predavanju na INFOSEKU v Novi Gorici?
/jan
Zakaj pa ne. Ravno gledam DNS loge, saj mi je prav fascinantno, da je “IN AAAA” poizvedb toliko. Ampak “grep” in “wc” ne lažeta…
Meni pa tole vsaj že od leta 2001 ni prav nič fascinantno:
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
D:\Documents and Settings\Administrator>ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : server
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter NIC_LAN:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : ULi PCI Fast Ethernet Controller
Physical Address. . . . . . . . . : 00-15-F2-D7-10-EE
Dhcp Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.10
Subnet Mask . . . . . . . . . . . : 255.255.255.0
IP Address. . . . . . . . . . . . : fe80::215:f2ff:fed7:10ee%4
Default Gateway . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 84.20.224.10
84.20.224.11
fec0:0:0:ffff::1%1
fec0:0:0:ffff::2%1
fec0:0:0:ffff::3%1
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-FB-60-AB-EB-05-92
Dhcp Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 2001:0:d5c7:a2ca:0:fb60:abeb:592
IP Address. . . . . . . . . . . . : fe80::ffff:ffff:fffd%5
Default Gateway . . . . . . . . . : ::
NetBIOS over Tcpip. . . . . . . . : Disabled
Tunnel adapter Automatic Tunneling Pseudo-Interface:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Automatic Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : C0-A8-01-0A
Dhcp Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : fe80::5efe:192.168.1.10%2
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
fec0:0:0:ffff::2%1
fec0:0:0:ffff::3%1
NetBIOS over Tcpip. . . . . . . . : Disabled
D:\Documents and Settings\Administrator>netstat -s
IPv4 Statistics
Packets Received = 3532346
Received Header Errors = 5
Received Address Errors = 1313
Datagrams Forwarded = 0
Unknown Protocols Received = 0
Received Packets Discarded = 4786
Received Packets Delivered = 3527559
Output Requests = 4236477
Routing Discards = 0
Discarded Output Packets = 20
Output Packet No Route = 0
Reassembly Required = 0
Reassembly Successful = 0
Reassembly Failures = 0
Datagrams Successfully Fragmented = 0
Datagrams Failing Fragmentation = 0
Fragments Created = 0
IPv6 Statistics
Packets Received = 3882
Received Header Errors = 0
Received Address Errors = 0
Datagrams Forwarded = 0
Unknown Protocols Received = 0
Received Packets Discarded = 0
Received Packets Delivered = 0
Output Requests = 108
Routing Discards = 0
Discarded Output Packets = 0
Output Packet No Route = 0
Reassembly Required = 0
Reassembly Successful = 0
Reassembly Failures = 0
Datagrams Successfully Fragmented = 0
Datagrams Failing Fragmentation = 0
Fragments Created = 0
ICMPv4 Statistics
Received Sent
Messages 7 17
Errors 0 0
Destination Unreachable 2 12
Time Exceeded 0 0
Parameter Problems 0 0
Source Quenches 0 0
Redirects 0 0
Echos 5 0
Echo Replies 0 5
Timestamps 0 0
Timestamp Replies 0 0
Address Masks 0 0
Address Mask Replies 0 0
ICMPv6 Statistics
Received Sent
Messages 3774 3856
Errors 0 0
MLD Reports 0 8
Router Solicitations 0 3844
Router Advertisements 3774 0
Neighbor Solicitations 0 4
TCP Statistics for IPv4
Active Opens = 693019
Passive Opens = 299
Failed Connection Attempts = 27
Reset Connections = 687648
Current Connections = 7
Segments Received = 3238289
Segments Sent = 3979897
Segments Retransmitted = 7776
TCP Statistics for IPv6
Active Opens = 18
Passive Opens = 0
Failed Connection Attempts = 18
Reset Connections = 0
Current Connections = 0
Segments Received = 108
Segments Sent = 72
Segments Retransmitted = 36
UDP Statistics for IPv4
Datagrams Received = 288869
No Ports = 28
Receive Errors = 0
Datagrams Sent = 248754
UDP Statistics for IPv6
Datagrams Received = 0
No Ports = 0
Receive Errors = 0
Datagrams Sent = 0
D:\Documents and Settings\Administrator>
In kaj ti tukaj ni vsec? Imas link-local address, katero po defaultu XP skreira iz random-a in ne iz MAC naslova (to lahko spremenis nekje), imas DNS server iz site-local naslovnega prostora, nimas stateless autoconfigurationa na networku in zato nimas gw-a.
Ce mi malo namignes, kaj ti ni vsec, si lahko zadevo malo bolj podrobno ogledam in kaj pokomentiram. Je pa res, da v6 na XP-jih ne pozna DNS prometa preko v6 protokol 🙂