LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 01-04-2004, 02:04 PM   #1
BigSkyCub
LQ Newbie
 
Registered: Jan 2004
Location: Portland. OR
Distribution: SuSE
Posts: 9

Rep: Reputation: 0
slow resolving host behind DI-604 router


I put my linux box running SuSE 8.1 behind a D-Link DI-604 router/firewall, which is connected to ADSL. Before putting the machine behind the router, all my network connection (i.e., web, email, etc.) were quite quite quick. After setting up the DI-604, I can successfully connect to outside addresses, but resolving host names is terribly slow. However, when I use nslookup I get a very fast response. If I run Win NT though vmware, the response is also very quick! The problem does not seem to be browser or software related--the slow down occurs with different browsers (mozilla, galeon, konqueror) as well as with my email retrieval (sylpheed).

Any help to resolving this problem would be greatly appreciated! I've included my host.conf, hosts, and resolv.conf for reference.

Thanks.





host.conf:

#
# /etc/host.conf - resolver configuration file
#
# Please read the manual page host.conf(5) for more information.
#
#
# The following option is only used by binaries linked against
# libc4 or libc5. This line should be in sync with the "hosts"
# option in /etc/nsswitch.conf.
#
order hosts, bind
#
# The following options are used by the resolver library:
#
multi on



hosts:

#
# hosts This file describes a number of hostname-to-address
# mappings for the TCP/IP subsystem. It is mostly
# used at boot time, when no name servers are running.
# On small systems, this file can be used instead of a
# "named" name server.
# Syntax:
#
# IP-Address Full-Qualified-Hostname Short-Hostname
#

127.0.0.1 localhost

# special IPv6 addresses
::1 localhost ipv6-localhost ipv6-loopback

fe00::0 ipv6-localnet

ff00::0 ipv6-mcastprefix
ff02::1 ipv6-allnodes
ff02::2 ipv6-allrouters
ff02::3 ipv6-allhosts

192.168.0.100 mycomp.pacifier.com mycomp


resolv.conf:

domain pacifier.com
nameserver 64.255.237.242
nameserver 64.255.237.243
 
Old 01-04-2004, 02:50 PM   #2
g-rod
Member
 
Registered: Dec 2003
Location: Long Island, NY USA
Distribution: RedHat, SUSE
Posts: 336

Rep: Reputation: 30
What does you /etc/resolv.conf look like?
 
Old 01-04-2004, 04:22 PM   #3
BigSkyCub
LQ Newbie
 
Registered: Jan 2004
Location: Portland. OR
Distribution: SuSE
Posts: 9

Original Poster
Rep: Reputation: 0
resolv.conf:

domain pacifier.com
nameserver 64.255.237.242
nameserver 64.255.237.243
 
Old 01-04-2004, 05:30 PM   #4
g-rod
Member
 
Registered: Dec 2003
Location: Long Island, NY USA
Distribution: RedHat, SUSE
Posts: 336

Rep: Reputation: 30
Sorry I guess I didn't see the resolv.conf in you original post.
What is you hostname of this computer? It probably is not localhost. You need to put that name and ip into the hosts file.
 
Old 01-04-2004, 11:39 PM   #5
BigSkyCub
LQ Newbie
 
Registered: Jan 2004
Location: Portland. OR
Distribution: SuSE
Posts: 9

Original Poster
Rep: Reputation: 0
Isn't that the last line in my hosts file?

192.168.0.100 mycomp.pacifier.com mycomp

The IP is static from the DI-604 router. The hostname is "mycomp" and my ISP is pacifier.com.

Thanks for taking a look at this. I appreciate it.
 
Old 01-04-2004, 11:45 PM   #6
BigSkyCub
LQ Newbie
 
Registered: Jan 2004
Location: Portland. OR
Distribution: SuSE
Posts: 9

Original Poster
Rep: Reputation: 0
Could the IPv6 be causing problems? I've seen references from Google searches to its causing problems. However, I discounted the idea initially because the response is fine if I put it outside the router/firewall. At this point I'm at a loss as to what the problem is.
 
Old 01-05-2004, 07:13 AM   #7
g-rod
Member
 
Registered: Dec 2003
Location: Long Island, NY USA
Distribution: RedHat, SUSE
Posts: 336

Rep: Reputation: 30
Sorry agian. Guess I had my eyes wide shut last night. I don't know much, about IPV6.
Putting you machine outside the router would give you a public IP for your isp, putting it inside the router lan gives you a private IP. That private ip is not in you ISP's doamin. Try changing the domain name of you machine to say mycomp.home instead of mycomp.pacifer.com in /etc/HOSTNAME and domainname home and update /etc/hosts.

Last edited by g-rod; 01-05-2004 at 07:17 AM.
 
Old 01-05-2004, 11:31 PM   #8
BigSkyCub
LQ Newbie
 
Registered: Jan 2004
Location: Portland. OR
Distribution: SuSE
Posts: 9

Original Poster
Rep: Reputation: 0
Thanks again for the idea. Still a no go. Ultimately, this will be a good learning experience.
 
Old 01-06-2004, 06:10 PM   #9
g-rod
Member
 
Registered: Dec 2003
Location: Long Island, NY USA
Distribution: RedHat, SUSE
Posts: 336

Rep: Reputation: 30
I am grasping here but is it possible that you something else on the network with same ip?
 
Old 01-27-2004, 11:23 AM   #10
Llamaman
LQ Newbie
 
Registered: Jan 2004
Posts: 4

Rep: Reputation: 0
Any resolution to this issue? This is now my problem ...
 
Old 01-27-2004, 11:46 PM   #11
BigSkyCub
LQ Newbie
 
Registered: Jan 2004
Location: Portland. OR
Distribution: SuSE
Posts: 9

Original Poster
Rep: Reputation: 0
Unfortunately, no. The last piece of advice that I received was to hire someone to look at the packet flow. I find the poor response annoying and will get it resolved, but it's taken a back burner to other projects.

Please let me know if you learn anything or how you resolve the issue.
 
Old 01-28-2004, 02:28 AM   #12
ezra143
Member
 
Registered: Aug 2003
Location: NY
Distribution: RH9, RH8, Slack, Vector
Posts: 497

Rep: Reputation: 32
ok, try two things...

restart the router/firewall. I hade a firewall that had been up for a year and a half just stop responding one day, a quick restart brought everything back up to speed.

try setting your dns to you friewalls ip addy. if no joy, change it back....
 
Old 01-28-2004, 10:32 AM   #13
BigSkyCub
LQ Newbie
 
Registered: Jan 2004
Location: Portland. OR
Distribution: SuSE
Posts: 9

Original Poster
Rep: Reputation: 0
I've attempted both of those fixes without any success. I still need to look at seeing what effect turning on and off the firewall in SuSE has.

Thanks.
 
Old 02-18-2004, 11:24 AM   #14
dbcr
LQ Newbie
 
Registered: Feb 2004
Location: castle rock, colorado
Distribution: suse, solaris, irix, hpux, redhat
Posts: 3

Rep: Reputation: 0
DI-604 and BIND (DNS) failure

Hello,

You are having a legitimate problem with the DI-604. I have analyzed the packets on both sides of the unit...

My configuration:

multiple hosts. One of them is a cobalt qube2 running BIND, another one is a Linux Redhat 6.2 box running BIND 9.2.1, another is a Solaris 8 box running BIND 9.2.1. Additionally there are several other systems including irix 6.5, windows 2k pro, nt 4., xp, macintosh, hp-ux, multiple xbox, wifi, etc.


My DI-604 h/w: E1, f/w: 3.20 (July 15 2003). It came with July 1, 2003 3.20 firmware but I u/g'd hoping it would fix this problem.

This is the problem: If you are querying DNS on an external nameserver it works fine. If you query DNS on the DI-604 itself it works fine. If you query DNS on an internal nameserver the internal nameservers check their root-hints (root.ca or named.ca) file to get the root-name-server list and IP addresses. When they attempt to query the root nameservers the request goes out but the response is blocked by the DI-604 firewall.

I have debugging turned on, on the firewall and it does not show this but will indicate when various filters/rules are denying.

I put a sniffer on both sides of the connection and I can see the packets go out, the packets come back and when they come back they appear on the outside of the DI-604 but not on the inside.

I spoke with the folks at DLINK and they are very nice but over their heads. It is impossible to actually get to an engineer. The support people don't really know what I am talking about. I have emailed them hoping they send to an engineer.

I think it is a problem with the packet inspection on their firewall but cannot see any more detail than this.

YOU ARE HAVING A LEGITIMATE PROBLEM with the DI-604. I also had problems with the DI-604 hanging during configuration/boot if it was getting WAN and/or LAN traffic other than the workstation I was using to configure it.

I am returning the DI-604. I did not have this problem with the 804U, 704, 804, or DI-614+.

I was very surprised. I have used numerous dlink's over the years and they have been awesome (imho).

I have not had the same experience with linksys. Their code revisisons are inconsistent. Problems fixed in a prior release reappear in a later release. Unsupported beta code often solves problems but is, ahem, unsupported. I am back to the store today to return this DI-604 and hopefully find a dlink that works better. Sometimes the store selection for DLINK is limited and they appear to be a much better unit than linksys. It figures that cisco would by linksys.

I wish you the very best, good luck. I hope this helps.
Dave
 
Old 02-18-2004, 04:56 PM   #15
BigSkyCub
LQ Newbie
 
Registered: Jan 2004
Location: Portland. OR
Distribution: SuSE
Posts: 9

Original Poster
Rep: Reputation: 0
Was your delay problem consistent with all your systems behind the DI-604?

I do not have the problem with a Mac or Win box--it's only with my Linux box. Moreover, if I run Win NT with VMWare from within Linux it's not a problem.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
connecting to the net using di-604 router ftcnt Linux - Newbie 14 07-11-2005 04:46 PM
Resolving <www.some remote host>.... failed: Host not found. koodoo Linux - Newbie 2 06-27-2005 08:48 AM
Very slow host resolving (Speedtouch?) hudy_rob Linux - Networking 1 04-18-2005 07:36 AM
D-Link 604 router w/ DHCP chbin Linux - Networking 4 03-26-2005 11:37 PM
Dlink DI-604 router set up help. iamzzzzleeping Linux - Networking 6 10-17-2003 11:51 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:54 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration