Page 1 of 1

EDNS errors / stopped Internet response

Posted: Thu Mar 18, 2010 5:27 pm
by andyser
Periodically my Internet connection stops on multiple machines. When I check the HDA logs I consistently see similar entries:

Mar 18 20:09:53 localhost named[12570]: success resolving 'news.blogs.cnn.com/A' (in '.'?) after disabling EDNS
Mar 18 20:09:52 localhost named[12570]: success resolving 'www.msnbc.msn.com/AAAA' (in '.'?) after disabling EDNS
Mar 18 20:09:52 localhost named[12570]: success resolving 'www.msnbc.msn.com/A' (in '.'?) after disabling EDNS
Mar 18 20:09:52 localhost named[12570]: success resolving 'www.wayneindependent.com/AAAA' (in '.'?) after reducing the advertised EDNS UDP packet size to 512 octets
Mar 18 20:09:52 localhost named[12570]: success resolving 'www.wayneindependent.com/A' (in '.'?) after reducing the advertised EDNS UDP packet size to 512 octets
Mar 18 20:09:51 localhost named[12570]: success resolving 'www.usnews.com/AAAA' (in '.'?) after disabling EDNS
Mar 18 20:09:51 localhost named[12570]: success resolving 'www.usnews.com/A' (in '.'?) after disabling EDNS
Mar 18 20:09:51 localhost named[12570]: success resolving 'www.chicagobreakingsports.com/AAAA' (in '.'?) after disabling EDNS
Mar 18 20:09:51 localhost named[12570]: success resolving 'www.chicagobreakingsports.com/A' (in '.'?) after disabling EDNS

These errors only show in the log as lasting 10-20 seconds, but my Internet connection will be unusable for 1-2 minutes - then everything clears up and runs fine. I haven't been able to determine what triggers the errors, but there's definitely a connection between the loss of Internet and when these errors get listed.

The URL's are also strange in that I don't even recognize some of the sites and when I cut and pasted these errors I was the only one accessing the Internet and I wasn't on any of these sites.

Any thoughts or insights?

Aside from this random glitch I love AMAHI and have had it running for ~1.5 years - keep up the great work! BTW - love the apps too!

Re: EDNS errors / stopped Internet response

Posted: Fri Mar 19, 2010 5:25 am
by cpg
i researched this a while ago, and if you look that up, it's an "enhanced" dns or somesuch, and it was harmless. it happens to me all the time, but i do not have "freezups".

for the freezes, try changing your DNS provider to your ISP or the Google public DNS.

Re: EDNS errors / stopped Internet response

Posted: Fri Mar 19, 2010 4:31 pm
by andyser
Carlos,

Thanks for the quick reply. Yes, I did see the earlier post and wanted to think it was harmless, but the errors seemed related to my dropped Internet connection.

This has been an intermittent problem for several months, but at this point I'm not blaming Amahi. I had an usual problem with my router where I was unable to change anything on the port forwarding screen and after a hard reset my "EDNS" problem cropped up again - coincidence? I'm not sure, but for now I'm hoping it's a router quirk and I've swapped out my router with another to test.

Next I'll try changing DNS's, but I like OpenDNS for their filtering feature.

I'll be back for more ideas if these don't cure my issue.

Thanks,
-Andy

Re: EDNS errors / stopped Internet response

Posted: Tue Apr 20, 2010 4:55 pm
by andyser
Carlos,

My "EDNS" problem resurfaced after a couple trouble free weeks (back on my original router), so I'm going on the theory that my router has gone flaky and I ordered a new one - hopefully that will fix it.

However, I did run across something else in the router's security log that I wanted to get some input on. There are numerous entries like the following:

2010-04-20 15:07:46 Lan->Wan [UDP]|[From:192.168.1.75 Port:55151 To:208.67.220.220 Port:53] Block UDP Flood
2010-04-20 15:08:51 Lan->Wan [UDP]|[From:192.168.1.75 Port:46806 To:208.67.220.220 Port:53] Block UDP Flood
2010-04-20 15:22:46 Lan->Wan [UDP]|[From:192.168.1.75 Port:44715 To:208.67.220.220 Port:53] Block UDP Flood
2010-04-20 15:23:59 Lan->Wan [UDP]|[From:192.168.1.75 Port:23508 To:208.67.222.222 Port:53] Block UDP Flood
2010-04-20 15:37:47 Lan->Wan [UDP]|[From:192.168.1.75 Port:7904 To:208.67.220.220 Port:53] Block UDP Flood
2010-04-20 15:38:57 Lan->Wan [UDP]|[From:192.168.1.75 Port:47403 To:208.67.220.220 Port:53] Block UDP Flood
2010-04-20 15:40:07 Lan->Wan [UDP]|[From:192.168.1.75 Port:11139 To:208.67.222.222 Port:53] Block UDP Flood
2010-04-20 15:52:47 Lan->Wan [UDP]|[From:192.168.1.75 Port:64101 To:208.67.220.220 Port:53] Block UDP Flood
2010-04-20 15:53:56 Lan->Wan [UDP]|[From:192.168.1.75 Port:4626 To:208.67.220.220 Port:53] Block UDP Flood

192.168.1.75 is my Amahi server. I found some references to P2P clients causing these port 53 UDP floods and I do occasionally use Transmission, but I made sure Transmission was closed, rebooted Amahi and I'm still getting these entries. Any ideas?

Thanks,
-Andy