Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times

    Scheduled Pinned Locked Moved DHCP and DNS
    176 Posts 6 Posters 20.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      RickyBaker @RickyBaker
      last edited by

      @SteveITS said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

      re: pfBlocker, it is in the Firewall menu, or would be an installed package.

      0fe9ea5e-707b-49c9-8180-f5d6492178b2-image.png

      So... no right?

      I've been googling Kea and ISC and i found that the option to switch is System->Advanced->Networking but I can't seem to find anything about it in there. I'm on pfSense 2.7.0 if that helps...

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @RickyBaker
        last edited by

        @RickyBaker said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

        pfSense 2.7.0

        Kea wasn't in 2.7.0. You are two versions behind though.
        https://docs.netgate.com/pfsense/en/latest/releases/2-7-1.html#kea-dhcp-server-feature-preview-now-available

        this was the fix in 2.7.2:
        https://docs.netgate.com/pfsense/en/latest/releases/2-7-2.html#dhcp-ipv4
        However I think that started in 2.7.1.

        And no you don't seem to have pfBlocker installed.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        R 1 Reply Last reply Reply Quote 1
        • R
          RickyBaker @SteveITS
          last edited by

          @SteveITS said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

          you have a large amount of logging going on somewhere, and a log is rotating every 3 minutes.

          any suggestions for tracing this?

          S 1 Reply Last reply Reply Quote 0
          • R
            RickyBaker @SteveITS
            last edited by

            @SteveITS to be clear, you aren't necessarily recommending I update, right?

            GertjanG 1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @RickyBaker
              last edited by

              any suggestions for tracing this?

              Take a look at the various log files in the pfSense GUI and see if any have high activity. Or "ls -l /var/log" and see if that shows any logs with close-together timestamps.

              It could be benign, for instance some people leave the dashboard open all day and pfSense logs all the web requests to update that.

              to be clear, you aren't necessarily recommending I update, right?

              2.7.2 is better than 2.7.1, is all. Is there a reason you're not updating? There were patches (via System Patches package) just released for 2.7.2 (and 23.09.1).

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote ๐Ÿ‘ helpful posts!

              R 1 Reply Last reply Reply Quote 0
              • R
                RickyBaker @SteveITS
                last edited by RickyBaker

                @SteveITS said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                Is there a reason you're not updating?

                cause everything was working great and I didn't want anything to break lololol

                @SteveITS said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                "ls -l /var/log"

                this just returned a list of the logs...did i do it wrong?
                18ed3635-2be8-4f01-8f11-70662cfc8e85-image.png

                @SteveITS said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                Take a look at the various log files in the pfSense GUI

                i flipped through every log and submenu log in the gui and nothing even closely matched up with the regular 3 minute interval of the sshguard "Exiting on signal" and "Now Monitoring Attacks"

                S 1 Reply Last reply Reply Quote 0
                • S
                  SteveITS Galactic Empire @RickyBaker
                  last edited by

                  @RickyBaker said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                  returned a list of the logs

                  Right but if you can't see timestamps indicating they are rotating every few minutes, it's not any of those logs.

                  In System Logs/Settings is Log Rotation Size (Bytes) set low?

                  Ultimately the logs are likely not related to your symptom.

                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                  Upvote ๐Ÿ‘ helpful posts!

                  R 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @RickyBaker
                    last edited by

                    @RickyBaker said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                    to be clear, you aren't necessarily recommending I update, right?

                    Boils down to the question : what do 'we' remember about 2.7.0 (years ago ?)
                    Maybe you and we are looking for an issue that was resolved long time, but we don't remember. The forum can tell you of course. For me, I'm just human, and I focus on the current version, and use the Form search button for the ancient issues.

                    Also, keep in mind : ok to use old version but when deciding to do so you become basically your own tech supporter because of what I've outlined above.

                    I get it, when we started to talk about 'kea' you didn't understand what we were talking about ... ๐Ÿ˜Š

                    Btw : you should only install and update pfSense packages (always build against the latest pfSense version) with an up to date pfSense version.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    R 1 Reply Last reply Reply Quote 1
                    • R
                      RickyBaker @SteveITS
                      last edited by RickyBaker

                      @SteveITS said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                      In System Logs/Settings is Log Rotation Size (Bytes) set low?

                      I don't believe I've ever changed these settings:
                      56728f71-0290-4407-8d64-3efb95e264e2-image.png
                      Is this low?

                      1 Reply Last reply Reply Quote 0
                      • R
                        RickyBaker @Gertjan
                        last edited by

                        @Gertjan said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                        so you become basically your own tech supporter

                        Happy to update if it helps troubleshooting. Why does this say i'm up to date but also say I'm on 2.7.0 and 2.7.2 is the latest stable release?
                        660b994b-0fe9-4a90-8244-98ceff06cd92-image.png

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          SteveITS Galactic Empire @RickyBaker
                          last edited by

                          @RickyBaker said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                          Why does this say i'm up to date but also say I'm on 2.7.0 and 2.7.2 is the latest stable release?

                          https://docs.netgate.com/pfsense/en/latest/releases/2-7-1.html#troubleshooting

                          Your log size field is grayed out so is the default.

                          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                          Upvote ๐Ÿ‘ helpful posts!

                          R 2 Replies Last reply Reply Quote 1
                          • R
                            RickyBaker @SteveITS
                            last edited by

                            @SteveITS said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                            Your log size field is grayed out so is the default.

                            is that good/what you'd want to see?

                            1 Reply Last reply Reply Quote 0
                            • R
                              RickyBaker @SteveITS
                              last edited by

                              @SteveITS I messaged my wife to ask her if any internet events had happened today and said, literally this second. I was connected to the VPN and working on the pfsense AS i texted her. I immediately refreshed the DNS Resolver log and pasted them here:

                              https://pastebin.com/jDipsG94

                              nothing interesting in the General or DHCP logs that i could tell. After pasting I raced to open a webpage to see if I was having issues. I typed 2 random words into google and opened the first link and it opened fine. I'm so perplexed.

                              In the meantime, since I'm so stumped. I'm working on updating to 2.7.2. I found this post @Gertjan referenced at some point. the command line suggestions early on the post seem to have gotten me in the right direction cause I'm now seeing this instead of "up to date", but clicking on update within the GUI or option 13 while ssh'ed into the pfsense both result in failure. I'm now realizing there's a bit more to the thread so I'm gonna see if there was anything further I missed but just want to document my current efforts. If anyone has any idea what this failure means, i'd love to know, thanks!
                              ac168ec7-f09e-4eb4-8dd4-5b94b216322e-image.png

                              GertjanG 1 Reply Last reply Reply Quote 0
                              • GertjanG
                                Gertjan @RickyBaker
                                last edited by Gertjan

                                @RickyBaker said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                                https://pastebin.com/jDipsG94

                                One thing :

                                a44f9ce6-ca83-429c-83da-56f3778bd2b6-image.png

                                The DNS log was being bombarded (you use the debug mode 3 or higher, that's ok but be aware that that creates a lot of log activity, and log files can get rotated fast as they tend to get filled up fast.
                                Up until April 28, 09h23 ..... and then it stops - nothing anymore.
                                Some shut the device down ? (power switch ? that's very bad)

                                Then at April 29, 14h00, unbound starts, but the first part of start log sequence is missing.

                                Was the pfSense switched of during April 28, 09h23 and April 29, 14h00 ?
                                Keep an eye on free disk space.
                                Disable level 3+ resolver (unbound) logging as soon as possible.

                                No "help me" PM's please. Use the forum, the community will thank you.
                                Edit : and where are the logs ??

                                R 2 Replies Last reply Reply Quote 0
                                • R
                                  RickyBaker @Gertjan
                                  last edited by

                                  @Gertjan said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                                  Was the pfSense switched of during April 28, 09h23 and April 29, 14h00 ?

                                  umm not at 2pm on Monday April 29th but I do believe that I reset the pfsense from the GUI on Sunday Apr 28 in the morning. I didn't think this was this instance but I know that I tried to reboot from the GUI before and it just wouldn't reboot (waited 10 minutes or so) so i pushed the power button (I know I'm not supposed to, but i wasn't sure what else to do). I can say pretty confidently that it wasn't, at least purposely, turned off at 2pm on Monday. That time seems awfully specific as well (i.e. 14:00:01) like some kind of schedule?

                                  @Gertjan said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                                  Disable level 3+ resolver (unbound) logging as soon as possible.

                                  Yes i turned on debugging to try to troubleshoot it, i understand to change it back asap, but I need to identify this problem first....thank you for pointing that out though...

                                  1 Reply Last reply Reply Quote 0
                                  • R
                                    RickyBaker @Gertjan
                                    last edited by

                                    @Gertjan said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                                    Up until April 28, 09h23 ..... and then it stops - nothing anymore.
                                    Some shut the device down ? (power switch ? that's very bad)

                                    looking at your paste though...it def wasn't down from sunday at 9 to monday at 2pm...? It was down for the amt of time it takes to reboot. that is perplexing?

                                    R 1 Reply Last reply Reply Quote 0
                                    • R
                                      RickyBaker @RickyBaker
                                      last edited by RickyBaker

                                      @RickyBaker I think i misunderstood, apologies. I had another weird internet event last night at 17:18 in the evening and when i went to go paste the logs I discovered what you were alluding too. the DNS Resolver log seems to have stopped updating yesterday at 14;00. what gives? I didn't discover til this morning the "restart log" button so i tried to change the log level to 2 as a bootleg way to "restart" it. Well the DNS NX DOMAIN event happened again on mutliple devices between 6:09 and 6:15 but I couldn't get to a computer til 6:42 and the DNS Resolver log set to 2000 entries didn't go past 6:42. So my question is which log level is appropriate to troubleshoot this? Any other logs I should change the logging level on? This issueis becoming very problematic.

                                      I've also added about 6 IP address to the blacklist of various LANs, waiting to see what, if anything, breaks. All the mac addresses were "no vendor" results on a mac address lookup, anything to look into that?

                                      johnpozJ GertjanG 2 Replies Last reply Reply Quote 0
                                      • johnpozJ
                                        johnpoz LAYER 8 Global Moderator @RickyBaker
                                        last edited by

                                        @RickyBaker said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                                        All the mac addresses were "no vendor" results on a mac address lookup

                                        If I were to guess - those would be mobile devices, apple or android - they love to use made up mac address - you know for your privacy ;) You can turn it off on the device.. So it uses its actual mac

                                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                                        If you get confused: Listen to the Music Play
                                        Please don't Chat/PM me for help, unless mod related
                                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                        1 Reply Last reply Reply Quote 1
                                        • GertjanG
                                          Gertjan @RickyBaker
                                          last edited by Gertjan

                                          @RickyBaker

                                          As probably already said above (I didn't check) : you don't want unbound to get restarted every xx seconds (minutes).
                                          So : uncheck this one :

                                          8bfbc4d1-407c-4404-82ec-3602c8648aa0-image.png

                                          From now on, you should see very few :

                                          750c297d-584a-44de-8adc-632c913b37d1-image.png

                                          Maybe once a day ?

                                          And remember : under pfBlockerng control, unbound can also get restarted.

                                          To see unbound (DNS) activity, I use this :

                                          tail -f /var/unbound/var/log/pfblockerng/dns_reply.log
                                          

                                          as I have pfBlocker already running.
                                          You can set unbound logging back to "Level 1 basic operations".

                                          What you also can try is : use the unbound settings as pre initialized by Netgate.
                                          De activate forwarding.
                                          Ditch 8.8.8.8 8 etc.
                                          You'll be using the default resolving.

                                          This is what I'm using :

                                          8f9b646a-92f0-4d43-acfc-a9f987daf43a-image.png

                                          and is rock solid for close to a decade.
                                          Don't worry about 8.8.8.8 etc, they will get over it ;)

                                          No "help me" PM's please. Use the forum, the community will thank you.
                                          Edit : and where are the logs ??

                                          johnpozJ R 3 Replies Last reply Reply Quote 1
                                          • johnpozJ
                                            johnpoz LAYER 8 Global Moderator @Gertjan
                                            last edited by

                                            @Gertjan said in DNS_PROBE_FINISHED_NXDOMAIN sporadically for anywhere from 30secs to 10min. works flawlessly at all other times:

                                            Don't worry about 8.8.8.8 etc, they will get over it ;)

                                            hahaha - made me laugh.. Oh man they are going to wonder why Ricky stopped asking for dns..

                                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                                            If you get confused: Listen to the Music Play
                                            Please don't Chat/PM me for help, unless mod related
                                            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.