Re: Warning: ID mismatch:

This is a discussion on Re: Warning: ID mismatch: within the Bind Users forums, part of the DNS and Related Forums category; Thank you for getting back to me on this. In this case, I don't think it is the firewall, ...


Go Back   Usenet Forums > DNS and Related Forums > Bind Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 09-07-2004
Maria Iano
 
Posts: n/a
Default Re: Warning: ID mismatch:

Thank you for getting back to me on this. In this case, I don't think it is the firewall, for two reasons. First of all, res1 and res2 are both inside the firewall and on the same network segment. So they send packets directly to eachother. Secondly, restarting named has fixed the issue.

I didn't have dynamic debugging available :( I have set it up now, but that involved restarting named, which also resolved the issue. Hopefully this won't happen again, but if it does at least this time I can turn on debugging...

Any further ideas you have would be most appreciated!

Thanks,
Maria

On Tue, Sep 07, at 04:33%P so wrote Jim Reid (jim@rfc1035.com):

> >>>>> "Maria" == Maria Iano <maria@iano.org> writes:

>
> Maria> I have two caching servers, res1 and res2, running BIND
> Maria> 9.2.3 on Red Hat Linux release 8.0 (Psyche). They sit
> Maria> inside a firewall, and forward queries to four different
> Maria> caching servers on the outside, as well as some internal
> Maria> servers authoritative for internal zones. Last week res2
> Maria> starting being slow and failing resolution
> Maria> intermittently. Dig queries sent from res2 to the outside
> Maria> resolvers worked correctly. Dig queries sent from res2 to
> Maria> res1 worked correctly. However, dig queries from res1 to
> Maria> res2 produced error messages like this:
>
> Maria> ;; Warning: ID mismatch: expected ID 3325, got 34596
>
> Maria> I suspect that if I reboot it the error will clear up
> Maria> again, but before I do that I want to try and work out what
> Maria> is going on.
>
> Maria> Any advice?
>
> Your firewall is probably broken. A DNS query includes a (random)
> query ID. This is to help a name server match an answer with the
> questions it has asked. The log messages indicate some answers your
> server is getting have different query IDs from the ones it used when
> the queries were made. This is almost certainly caused by your
> firewall messing with the DNS packets as they go by.


Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:11 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0