DNS seems completely broken on my netgear r9000 router

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Goto page 1, 2  Next
Author Message
elyograg
DD-WRT User


Joined: 11 Jul 2021
Posts: 56

PostPosted: Fri May 26, 2023 6:57    Post subject: DNS seems completely broken on my netgear r9000 router Reply with quote
My DD-WRT router (build on 2023-05-24, hardware is netgear r9000) is failing all DNS lookups. I noticed it first when I saw that the date was January 3rd 1970, and looking at syslog, it is not able to resolve pool.ntp.org.

Using nslookup via ssh, it's not even able to resolve a name when pointed at working DNS servers in my network or on the Internet. If I run the exact same nslookup commands on a desktop system, they work.

I am not sure how long this problem has been going on. I found it on the 2023-05-23 release and just upgraded it to 2023-05-24 with no change.
Sponsor
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6439
Location: UK, London, just across the river..

PostPosted: Fri May 26, 2023 7:13    Post subject: Reply with quote
there is a positive post about the last update 52671
so the problem is either in your set up or ISP...update and reset via button (do not reset when update option via GUI) and than rebuild your settings manually..do not load ot settings file...
for NTP time use either IP or just select your time zone or capital...
216.239.35.4 google NTP time server
162.159.200.123 cloudflare NTP time server

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1938

PostPosted: Fri May 26, 2023 7:26    Post subject: Reply with quote
Why is there a local DNS server set to a local subnet IP?
Why are two of your static DNS entries set to local subnet IPs?
Why do you not have Forced DNS Redirection and Forced DNS Redirection and DoT checked?
Are those local subnet IPs Pi-Holes? Looks like an overly unnecessarily complicated setup.

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6439
Location: UK, London, just across the river..

PostPosted: Fri May 26, 2023 10:15    Post subject: Reply with quote
dale_gribble39 wrote:
Why is there a local DNS server set to a local subnet IP?
Why are two of your static DNS entries set to local subnet IPs?
Why do you not have Forced DNS Redirection and Forced DNS Redirection and DoT checked?
Are those local subnet IPs Pi-Holes? Looks like an overly unnecessarily complicated setup.


yep i didn't see those...fix those live happy life ...

Alozaros wrote:
....so the problem is either in your set up or....
...for NTP time use either IP or just select your time zone or capital...

216.239.35.4 google NTP time server
162.159.200.123 cloudflare NTP time server

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
jtbr
DD-WRT User


Joined: 09 Mar 2017
Posts: 100

PostPosted: Fri May 26, 2023 22:12    Post subject: Re: DNS seems completely broken on my netgear r9000 router Reply with quote
elyograg wrote:
Using nslookup via ssh, it's not even able to resolve a name when pointed at working DNS servers in my network or on the Internet. If I run the exact same nslookup commands on a desktop system, they work.


Even if his dns settings are all wrong and his local servers are broken, the use of the google servers should have worked. Did you try looking up other addresses? Maybe there was something wrong with ntp.org at that time (works for me now on 5/15 build r52569). Is there anywhere where the firewall is blocking or re-routing DNS requests or requests for particular servers?
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1938

PostPosted: Fri May 26, 2023 22:32    Post subject: Reply with quote
Use of Google's DNS server IP should have worked, and did not. Why? We don't
know because we don't have the full picture. In short, "l33t $h1t bR0k3n"....

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
blkt
DD-WRT Guru


Joined: 20 Jan 2019
Posts: 5700

PostPosted: Fri May 26, 2023 22:40    Post subject: Reply with quote
NTP Client Settings -> Server IP / Name -> see the "blank" settings, and understand the reasons for IP addresses.
If choosing to specify an ntp pool it is now expected to add two or three NTP server IP or just leave the field blank.

https://www.ntppool.org/en/use.html
https://www.pool.ntp.org/zone/@
https://www.ntppool.org/scores/
https://servertest.online/ntp
elyograg
DD-WRT User


Joined: 11 Jul 2021
Posts: 56

PostPosted: Fri May 26, 2023 23:36    Post subject: Re: DNS seems completely broken on my netgear r9000 router Reply with quote
dale_gribble39 wrote:
Use of Google's DNS server IP should have worked, and did not. Why? We don't
know because we don't have the full picture. In short, "l33t $h1t bR0k3n"....


Do you need anything more than this screenshot shows? Those lookups are made from the shell on the router. Even if I had DD-WRT's DNS settings all wrong for my network, that shouldn't affect these requests from the router itself using nslookup pointed at a public DNS server on the Internet.

DNS lookups made by my dd-wrt don't work no matter where the request is sent.

All these nslookup commands work if I try them on anything else in my network. All those machines are using this router to get to the Internet.

FYI, DNS works just fine on all my hosts, it's just broken on DD-WRT itself. Internal hosts are given the IP addresses of my servers by DHCP.

Also, I used to be able to send DNS requests to the router from internal hosts and it would work. Now it doesn't.
elyograg
DD-WRT User


Joined: 11 Jul 2021
Posts: 56

PostPosted: Fri May 26, 2023 23:44    Post subject: Reply with quote
Aside from DNS everything betwork-related to be working on dd-wrt. If I don't use the -n on traceroute then it hangs forever on each line trying and failing to look up reverse DNS.
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1938

PostPosted: Sat May 27, 2023 0:35    Post subject: Reply with quote
Aside from Setup -> Basic Setup that you've shown, what are your other DNS / dnsmasq related configurations in DD-WRT? It is quite obvious that reverse DNS lookup is broken because of your configuration (which breaks nslookup, too). No previous questions successfully answered yet. Your configured DNS servers, we need further information to troubleshoot your problem. So many details still a mystery. Have you tried removing your local DNS server, and local IP static entries and entering known good public DNS servers?
_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6439
Location: UK, London, just across the river..

PostPosted: Sat May 27, 2023 9:37    Post subject: Reply with quote
as blkt noted above check if your configuration is able to reach NTP time..as some ISP's are blocking those requests or firewall misconfiguration may happen too...so, yes we need more details...
As well, what commands you have in your firewall, that my prevent from NTP time to be obtained...(common mistake)..
So, no NTP time no fun..no more details, help will go down to 0 (zero), as nobody can guess the reason..

My R9000 is up and running so, no firmware error..

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
elyograg
DD-WRT User


Joined: 11 Jul 2021
Posts: 56

PostPosted: Sat May 27, 2023 19:49    Post subject: Reply with quote
dale_gribble39 wrote:
Aside from Setup -> Basic Setup that you've shown, what are your other DNS / dnsmasq related configurations in DD-WRT? It is quite obvious that reverse DNS lookup is broken because of your configuration (which breaks nslookup, too). No previous questions successfully answered yet. Your configured DNS servers, we need further information to troubleshoot your problem. So many details still a mystery. Have you tried removing your local DNS server, and local IP static entries and entering known good public DNS servers?


Can you be much more specific about exactly where I need to go to get what you want to see? I've added DNS settings from the Services tab.

Is there anything in the DD-WRT config that can affect nslookup working from the commandline?

Alozaros talked about a firewall... the only firewall in play is DD-WRT itself. I cannot remember doing anything to the firewall other than some port forwarding, and none of the firewall settings have changed at all recently. Definitely not since the last time accessed things by name from the router shell. Not that I can remember when that was...
elyograg
DD-WRT User


Joined: 11 Jul 2021
Posts: 56

PostPosted: Sat May 27, 2023 19:54    Post subject: Reply with quote
I just upgraded to DD-WRT v3.0-r52720 std (05/27/23).

I did not expect that to help, and it didn't.

There must be some setting that I changed and either don't remember doing it, or at the time I thought it was the right change.
SurprisedItWorks
DD-WRT Guru


Joined: 04 Aug 2018
Posts: 1447
Location: Appalachian mountains, USA

PostPosted: Sat May 27, 2023 20:44    Post subject: Reply with quote
DNSMasq can pretty easily break completely if you get setup stuff wrong, so it's really a bad idea to "smoke test" a pile of DNS-related stuff all at one time. So were I you, I'd for the moment remove all the local-network IPs for DNS servers, in both places, and I'd leave the NTP server field empty, as dd-wrt defaults it well. DNS 1 and DNS 2 you can set to known solid external servers like 1.1.1.1 (Cloudflare), 8.8.8.8 (Google), or 9.9.9.9 (Quad9). Get that basic config working, then start twiddling things one at a time if you need something special. Then at least you'll know what setting broke things!

I also agree with the earlier comment that Forced DNS Redirection is basic and should be checked for most people, but it's not going to make or break things either way.

_________________
2x Netgear XR500 and 3x Linksys WRT1900ACSv2 on 53544: VLANs, VAPs, NAS, station mode, OpenVPN client (AirVPN), wireguard server (AirVPN port forward) and clients (AzireVPN, AirVPN, private), 3 DNSCrypt providers via VPN.
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14222
Location: Texas, USA

PostPosted: Sat May 27, 2023 20:53    Post subject: Reply with quote
You have DNSSEC configured, but no check of unsigned replies. Do your configured DNS servers support DNSSEC? Not sure why you have No DNS rebind disabled, nor why no query in strict order. Also, you do not need to pass option 6 to clients as that sends the static entries by default - but there is the use of a non-local server entry, so there is that. The problem is multi-fold, and I agree with what @SurprisedItWorks suggested.
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
Goto page 1, 2  Next Display posts from previous:    Page 1 of 2
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum