My Introduction and current issues -

Michael De Roover isc at nixmagic.com
Fri May 9 23:53:21 UTC 2025


On Saturday, 10 May 2025 01:35:28 CEST Greg Choules via bind-users wrote:
> Third, use tcpdump to capture port 53. Do this to a file, then look at it
> offline in Wireshark. (Michael just beat me to that tip). Check how queries
> are arriving into BIND and what it does with them. Particularly look at the
> timings of packets and for errors, such as packet loss or ICMP.

We were close, I'm impressed at your perception for having caught it in time! 
As for logging it to a file, yes, this is what logs it into a PCAP format. That 
can then be opened in Wireshark for further analysis.

-- 
Met vriendelijke groet,
Michael De Roover

Mail: isc at nixmagic.com
Web: michael.de.roover.eu.org




More information about the bind-users mailing list