DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Draytek 2860 DNS interception
- phyber
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 22
- Thank yous received: 0
15 Jan 2014 16:29 #78735
by phyber
Draytek 2860 DNS interception was created by phyber
So, the issue that was documented on the
Vigor 2830
is happening on the 2860 with firmware 3.7.3.
In addition to the issue with TXT records, I am also unable to lookup SOA records. It's possible that there is also an issue with EDNS0, but with these other issues happening it's hard to tell. Why the 2860 is filtering DNS when the DNS Filter is turned off, I do not know.
I've been in contact with Draytek UK support for a separate IPv6 firewall issue* and have now mentioned this DNS issue in the same ticket to them, but I thought I'd post here too, since they're very slow to reply.
I don't expect anyone here to be able to help with these issues, but I felt it was worth putting here for other people that are considering buying the 2860. If they ever reply, I'll update this with new info.
*Internal router services exposed on public IP addresses, with no way to disable it. The services in question were the LDP (port 515, printer) service and the management interface. Printer should never be public and Remote Management and SSL VPN (port 443) are disabled, so those ports should not show up on a public address.
In addition to the issue with TXT records, I am also unable to lookup SOA records. It's possible that there is also an issue with EDNS0, but with these other issues happening it's hard to tell. Why the 2860 is filtering DNS when the DNS Filter is turned off, I do not know.
I've been in contact with Draytek UK support for a separate IPv6 firewall issue* and have now mentioned this DNS issue in the same ticket to them, but I thought I'd post here too, since they're very slow to reply.
I don't expect anyone here to be able to help with these issues, but I felt it was worth putting here for other people that are considering buying the 2860. If they ever reply, I'll update this with new info.
*Internal router services exposed on public IP addresses, with no way to disable it. The services in question were the LDP (port 515, printer) service and the management interface. Printer should never be public and Remote Management and SSL VPN (port 443) are disabled, so those ports should not show up on a public address.
Please Log in or Create an account to join the conversation.
- phyber
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 22
- Thank yous received: 0
17 Jan 2014 11:09 #78753
by phyber
Replied by phyber on topic Re: Draytek 2860 DNS interception
So, for anyone using IPv6 on this router or having issues with the router filtering DNS (which cannot be turned off) firmware 3.7.3.3 addresses some of the issues.
My next step is probably going to be to setup a resolver on a VPS somewhere so that I can see what the packets look like after they have passed through the Vigor 2860. I'm expecting to see one of a few outcomes.
I'll update this thread again when I have more to report.
My next step is probably going to be to setup a resolver on a VPS somewhere so that I can see what the packets look like after they have passed through the Vigor 2860. I'm expecting to see one of a few outcomes.
I'll update this thread again when I have more to report.
Please Log in or Create an account to join the conversation.
- phyber
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 22
- Thank yous received: 0
17 Jan 2014 15:45 #78761
by phyber
Replied by phyber on topic Re: Draytek 2860 DNS interception
So after capturing some more packets with tshark on boths sides (DNS client behind the Vigor 2860, recursive resolver on the Internet) and looking over them with wireshark it appears that:
So, the Vigor 2860 is just dropping the replies for certain RR queries for an unknown reason without logging why.
So, the Vigor 2860 is just dropping the replies for certain RR queries for an unknown reason without logging why.
Please Log in or Create an account to join the conversation.
- babis3g
- Offline
- Dedicated Contributor
Less
More
- Posts: 1686
- Thank yous received: 0
17 Jan 2014 16:30 #78763
by babis3g
Replied by babis3g on topic Re: Draytek 2860 DNS interception
Have not involved with VPN & all that apart adsl/vdsl parts but are you aware about this note ?
http://www.draytek.net.nz/draytek/support/vigor2830-upgrading-to-3-6-4/
http://www.draytek.co.uk/archive/kb/kb_sslvpn_troubleshooting.html
Another way which may worth to try for dns at LAN >> General Setup>>details page>>dns server ip ... to add manually your isp's or the ones you prefer, in that section if will help
Another way which may worth to try for dns at LAN >> General Setup>>details page>>dns server ip ... to add manually your isp's or the ones you prefer, in that section if will help
Please Log in or Create an account to join the conversation.
- phyber
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 22
- Thank yous received: 0
29 Jan 2014 09:46 #78879
by phyber
Replied by phyber on topic Re: Draytek 2860 DNS interception
I'm not sure how much I'm really allowed to say about this, but there was no NDA thing in the email so I'm guessing it's OK.
Draytek provided me with a beta firmware for testing which seems to fix the DNS interception issues. This means that resolvers behind the Vigor 2860 can now properly receive answers for any DNS query that they perform. In the cases I was testing this means that my resolvers behind the 2860 can now properly query for SOA records and perform DNSSEC validation.
DNS queries directed at the 2860 itself (so, queries that use the 2860's DNS proxy/resolver) are still subject to this filtering. Hopefully this will be fixed soon too.
Draytek provided me with a beta firmware for testing which seems to fix the DNS interception issues. This means that resolvers behind the Vigor 2860 can now properly receive answers for any DNS query that they perform. In the cases I was testing this means that my resolvers behind the 2860 can now properly query for SOA records and perform DNSSEC validation.
DNS queries directed at the 2860 itself (so, queries that use the 2860's DNS proxy/resolver) are still subject to this filtering. Hopefully this will be fixed soon too.
Please Log in or Create an account to join the conversation.
- mattstephenson
- Offline
- New Member
Less
More
- Posts: 1
- Thank yous received: 0
29 Mar 2014 16:45 #79502
by mattstephenson
Replied by mattstephenson on topic Re: Draytek 2860 DNS interception
I am experiencing this problem too.
Our Active Directory servers which run Windows Server 2012 have always forwarded to Google DNS 8.8.8.8 and 8.8.4.4.
Since changing the router to DrayTek, it intercepts DNS queries often making them fail and setting a low TTL of 60 seconds which is creating ongoing DNS issues.
DNS Filter is off in the router admin, so why does it not butt out of interfering with queries I do not want it to.
Reported to support but have heard nothing for a week.
Hopefully a fix soon, or I will have to roll back to an ancient firmware before they invented this 'feature'.
Our Active Directory servers which run Windows Server 2012 have always forwarded to Google DNS 8.8.8.8 and 8.8.4.4.
Since changing the router to DrayTek, it intercepts DNS queries often making them fail and setting a low TTL of 60 seconds which is creating ongoing DNS issues.
DNS Filter is off in the router admin, so why does it not butt out of interfering with queries I do not want it to.
Reported to support but have heard nothing for a week.
Hopefully a fix soon, or I will have to roll back to an ancient firmware before they invented this 'feature'.
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek