- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Server Issue within network
nslookup www.lasercutlawncare.com resolves to the correct IP address only when we are not in the office. it shows a different IP when we are behind the firewall. the correct address is 159.203.72.7 but inside the network it resolves to 104.225.8.29 regardless of the DNS server queried. there are no rules on the firewall, and there is no internal network DNS server.
When looking into it further, Meraki stated: As discussed on the call, the wireshark packet capture shows that DNS Query for the mentioned website is reaching to the DNS server and its the server that is responding back from the incorrect IP address i.e., 104.225.8.29 and 104.225.8.28. I have also attached the pcap file for you to investigate further."
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree with Meraki. If the pcap shows that your DNS server did respond to the query with the '104.225.8.29'.
I would check on the DNS server that is responding to the queries.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I replied below to cmr.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@jfuller347 when you go to a command line and type nslookup, then change the server by typing server 8.8.8.8, what do you get if you then type www.lasercutlawncare.com?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So we had changed the DNS to 1.1.1.1 and to 8.8.8.8 in Meraki>>Security & SD-WAN>>Appliance Status>>Tools>>DNS Lookup and still got the discrepancy. Unfortunately I am not behind the network or can utilize a VPN to test remotely.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The packet capture shows 1.1.1.1 / 8.8.8.8 responding to the query ?
On google public dig box :
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That's what I get at home too. However, behind the network of the client it is not what we get.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Same here:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yep. its just in the client's network itself. There are no firewall rules or anything out of the ordinary. We can't figure it out.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you checked to make sure your ISP isn't doing anything weird with your DNS traffic?
Do you live in a country line China that restricts certain traffic?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I was thinking of reaching out to the ISP. It is comcast and in the United States.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If they have internal DNS servers what forwarders are they using (if any)?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As another person said, check with Comcast. I just ran into this on another site: click.skillpreceptor.info. All DNS requests for it to any DNS server are getting intercepted somewhere beyond my router (not even a Meraki), and replaced with the same IP address:
104.225.8.29
104.225.8.28
Testing with other connections (even Comcast at other sites!) shows the correct IP of 13.110.204.15.
Going to the site in a browser shows a generic block page, and some source investigation shows references to Akamai's Nominum DNS blocking service. So, sounds like Comcast is doing DNS blocking, though not sure I ever asked them to.
On a side note, for your mentioned website, MBAM throws a ransomware warning and blocks it, so clearly there's some kind of website issue going on for multiple security providers to start blocking it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you ever figure this out. We are having the exact same issue with the same 2 104.x.x.28 and 29 IPs. For us, its the sites click.mailer.clubhouseonline-e3.com, click.emailcampaigns.net, and trk.cp20.com. They all resolve to the above IPs. If I change the dns servers on my machine, it works. If I leave our internal network, it works. It's been driving me crazy.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In our case, we were able to confirm it was Comcast's SecurityEdge feature, and the issues cleared up once we worked with Comcast to disable that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you ever figure this out? W have the exact same issue currently with the site you posted and another site.
