Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




43 posts

Geek
+1 received by user: 3


# 250619 19-May-2019 10:09
Send private message quote this post

Recently I changed my Mikrotik Edge router out for another one.  Setup the pppoe connection, but found only Android devices had internet.

 

As a stop gap I disabled the peer DNS setting and am now using Google DNS 8.8.8.8 & 8.8.4.4 for everything, now non Android machines have internet.

 

The 2Degrees server when queried gives this response -

 

dig @202.37.101.1 www.stuff.co.nz

 

; <<>> DiG 9.11.3-1ubuntu1.7-Ubuntu <<>> @202.37.101.1 www.stuff.co.nz
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: REFUSED, id: 58919
;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

 

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;www.stuff.co.nz. IN A

 

;; Query time: 5 msec
;; SERVER: 202.37.101.1#53(202.37.101.1)
;; WHEN: Sun May 19 09:57:42 NZST 2019
;; MSG SIZE rcvd: 44

 

 

 

Google gives me this-

 

dig @8.8.8.8 www.stuff.co.nz

 

; <<>> DiG 9.11.3-1ubuntu1.7-Ubuntu <<>> @8.8.8.8 www.stuff.co.nz
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 18081
;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1

 

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;www.stuff.co.nz. IN A

 

;; ANSWER SECTION:
www.stuff.co.nz. 3230 IN CNAME fairfaxmedia.co.nz.edgekey.net.
fairfaxmedia.co.nz.edgekey.net. 134 IN CNAME e14449.dsce2.akamaiedge.net.
e14449.dsce2.akamaiedge.net. 19 IN A 23.43.156.140

 

;; Query time: 166 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Sun May 19 10:03:23 NZST 2019
;; MSG SIZE rcvd: 142

 

 

 

It looks like my new router is not in their whitelist or similar

 

When ringing the 2 Degrees helpdesk I get the standard "plug in your FritzBox" line which isn't helpful.

 

I would prefer to be able to use 2D DNS.  Can anyone here from 2 Degrees offer some help?

 

 

 

Kind Regards

 

Graeme

 

 

 

 


Create new topic
449 posts

Ultimate Geek
+1 received by user: 98


  # 2241055 19-May-2019 23:29
Send private message quote this post

You could try telling the new router to spoof the MAC address of your FritzBox.


449 posts

Ultimate Geek
+1 received by user: 249

Subscriber

  # 2241101 20-May-2019 00:35
One person supports this post
Send private message quote this post

There's no need to spoof MAC. I can use 2deg DNS, and my router is a custom box with pfsense.

 
 
 
 


6761 posts

Uber Geek
+1 received by user: 630

Trusted
Subscriber

  # 2241105 20-May-2019 06:45
Send private message quote this post

Hi Graeme, have you checked if your new router is undesirably responding to DNS requests on its WAN port, if so you might need to adjust the firewall rules.

 

From an outside connection use nmap or from in or outside use openresolver.com to test.

 

Only reason I mention that is the Warning in the first dig request.

 

Cyril




43 posts

Geek
+1 received by user: 3


  # 2241139 20-May-2019 08:55
Send private message quote this post

Hi

 

Thanks for the replies.

 

I've run GRC Shields up and all ports up to 1055 are stealth including port 53.

 

I'd prefer not to change the MAC of my PPPOE client unless I really have to.

 

I'll see if I can get hold of Nick Mack.

 

Graeme

 

 

 

 


3885 posts

Uber Geek
+1 received by user: 1757

Subscriber

  # 2241214 20-May-2019 11:21
quote this post

Have you actually tried testing with a Fritzbox? As that would be the easiest way to see if it actually is a router issue or not.

No point in spoofing the MAC address, as they are only visible at layer 2.

Maybe you have triggered the DDOS mitigation system that 2degrees have? Try accessing Google.com







43 posts

Geek
+1 received by user: 3


  # 2241241 20-May-2019 11:52
Send private message quote this post

Hi

 

I didn't try the Fritzbox.  I sort of knew that because I could use Google DNS it was most likely a trust relationship that had been broken by swapping hardware.

 

In the meantime Nick from 2 Degrees has made a change at their end and dig now returns the expected result.

 

Will do some re-configuration when I have a moment to make sure things are really fixed, but looks good so far

 

Thanks

 

Graeme


27989 posts

Uber Geek
+1 received by user: 7469

Moderator
Trusted
Biddle Corp
Lifetime subscriber

  # 2241243 20-May-2019 11:56
Send private message quote this post

Swapping hardware won't do it. You've potentially done something that has triggered DDOS mitigation or similar.

 

 


 
 
 
 




43 posts

Geek
+1 received by user: 3


# 2241385 20-May-2019 13:19
Send private message quote this post

Quite possibly triggered something like that.  I know enough about networks to get myself into trouble. 😮

 

I love the flexibility of the mikrotik gear, but it can be pretty unforgiving when you get it wrong.

 

Nick didn't mention what had happened, just that it should be resolved.


Create new topic



Twitter and LinkedIn »



Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Dunedin selects Telensa to deliver smart street lighting for 15,000 LEDs
Posted 18-Jul-2019 10:21


Sprint announces a connected wallet card with built-in IoT support
Posted 18-Jul-2019 08:36


Educational tool developed at Otago makes international launch
Posted 17-Jul-2019 21:57


Symantec introduces cloud access security solution
Posted 17-Jul-2019 21:48


New Zealand government unveils new digital service to make business easier
Posted 16-Jul-2019 17:35


Scientists unveil image of quantum entanglement
Posted 13-Jul-2019 06:00


Hackers to be challenged at University of Waikato
Posted 12-Jul-2019 21:34


OPPO Reno Z now available in New Zealand
Posted 12-Jul-2019 21:28


Sony introduces WF-1000XM3 wireless headphones with noise cancellation
Posted 8-Jul-2019 16:56


Xero announces new smarter tools, push into the North American market
Posted 19-Jun-2019 17:20


New report by Unisys shows New Zealanders want action by social platform companies and police to monitor social media sites
Posted 19-Jun-2019 17:09


ASB adds Google Pay option to contactless payments
Posted 19-Jun-2019 17:05


New Zealand PC Market declines on the back of high channel inventory, IDC reports
Posted 18-Jun-2019 17:35


Air New Zealand uses drones to inspect aircraft
Posted 17-Jun-2019 15:39


TCL Electronics launches its first-ever 8K TV
Posted 17-Jun-2019 15:18



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.