LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 02-11-2009, 11:29 AM   #1
brandon@rhiamet.com
LQ Newbie
 
Registered: Jan 2009
Posts: 20

Rep: Reputation: Disabled
named FORMERR errors


I'm getting errors like the following in /var/log/messages from named:

Feb 11 11:20:31 foo.domain.com named[15446]: FORMERR resolving 'approvaltruthful.com/NS/IN': 59.63.157.212#53
Feb 11 11:20:48 foo.domain.com named[15446]: FORMERR resolving 'pt1.oceaninterdependent.com/AAAA/IN': 61.147.117.225#53

I believe these are malformed queries, but where are they coming from. This is on an internal nameserver where the address space is 192.168.1.0/24 and there is no access to port 53 tcp or udp from the outside. I'm assuming the IP addresses listed in the error message is where the request is coming from, but that doesn't make sense given that it's behind a firewall.

Any ideas?
 
Old 02-11-2009, 04:33 PM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,165
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Quote:
Feb 11 11:20:31 foo.domain.com named[15446]: FORMERR resolving 'approvaltruthful.com/NS/IN': 59.63.157.212#53
...
I believe these are malformed queries, but where are they coming from.
These are indeed malformed dns queries (FORMat ERRor). They come from your dns server (foo.domain.com) trying to resolve a domain e.g. approvaltruthful.com For this, it queries the dns authoritative for that domain, or a forwarder if you have defined one in named.conf (that's the dns server 59.63.157.212). The reason the query is bad, could be a network problem, a misconfigured firewall in between or other similar problem.
The requests are coming from hosts using your dns. You can use tcpdump to find the host asking your dns for these domains and for what reason.
 
Old 02-11-2009, 04:49 PM   #3
brandon@rhiamet.com
LQ Newbie
 
Registered: Jan 2009
Posts: 20

Original Poster
Rep: Reputation: Disabled
So, it sounds like there's not much I can do about it if the problem is on a device beyond my network, correct?
 
Old 02-11-2009, 05:31 PM   #4
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,165
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Quote:
So, it sounds like there's not much I can do about it if the problem is on a device beyond my network, correct?
I run nslookup for the domain approvaltruthful.com and it came out without error. So if you're sure the problem is not on your side, then there nothing you can do.
You can use tcpdump to see from where the queries are coming just to be sure that there is nothing suspicious (like a spam bot) in one of your clients.
I also get tons of FORMERR and using tcpdump I've discovered that they are originating from spamassassin trying to resolve the domains that appear in email addresses or bodies in order to determine if the mail is spam or not. All I do is to filter out these errors from /var/log/messages.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
chown -R named:named /var/named crash the system? joangopan Fedora 2 09-09-2007 02:46 AM
Named errors and stuck in a bind! sir-lancealot Linux - Server 1 08-11-2007 06:34 PM
FORMERR from named after ISP change dguy Linux - Networking 2 04-06-2007 03:04 PM
Red Hat: named daemon errors dsschanze Red Hat 2 01-29-2005 10:45 AM
named errors kik Linux - Networking 5 01-23-2002 11:04 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:05 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration