John W. Blue
john.blue at rrcic.com
Thu Sep 6 21:55:32 UTC 2018
So that file is full of nothing but queries and no responses which, sadly, is useless.
tcpdump -s0 -n -i eth0 port domain -w /tmp/domaincapture.pcap
You don't need all of the extra stuff because -s0 captures the full packet.
From: bind-users [mailto:bind-users-bounces at lists.isc.org] On Behalf Of Alex
Sent: Thursday, September 06, 2018 2:54 PM
To: bind-users at lists.isc.org
Subject: Re: Frequent timeout
On Thu, Sep 6, 2018 at 3:05 PM John W. Blue <john.blue at rrcic.com> wrote:
> Have you uploaded this pcap with the SERVFAIL's? I didn't have time to look at your first upload but can review this one.
Thanks very much. I've uploaded the pcap file here. It's about ~100MB compressed, and represents about 4hrs of data, I believe.
More information about the bind-users