• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

tcp error for address xxxx port 853

Scheduled Pinned Locked Moved DHCP and DNS
29 Posts 4 Posters 4.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    chudak
    last edited by chudak Feb 12, 2019, 6:01 PM Feb 12, 2019, 6:01 PM

    I see lots of posts but no conclusive solution, so asking experts here.

    I am using SSL/TLS for outgoing DNS Queries and see errors:

    unbound 67011:3 debug: tcp error for address xxxx port 853

    It's the same for 8.8.8.8, 9.9.9.9 and 1.1.1.1

    Anybody knows how to fix it ?

    Thx

    1 Reply Last reply Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator
      last edited by Feb 12, 2019, 6:47 PM

      Where are these posts with no solutions exactly?

      And lets set your setup.. What version of pfsense are you using exactly? Do you have some vpn setup where all your traffic is going over a vpn, what other packages if any are you running.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      C 1 Reply Last reply Feb 12, 2019, 8:29 PM Reply Quote 0
      • C
        chudak @johnpoz
        last edited by Feb 12, 2019, 8:29 PM

        @johnpoz

        2.4.4-RELEASE-p2

        DNS server(s)
        127.0.0.1
        9.9.9.9
        149.112.112.112

        Resolver setup https://snag.gy/6MoRP1.jpg

        I run OpenVNP server but no clients and don't think have traffic l going over.

        Thx

        1 Reply Last reply Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator
          last edited by johnpoz Feb 12, 2019, 8:47 PM Feb 12, 2019, 8:46 PM

          So clearly your running pfblocker - which I asked about any packages. That for sure can cause a wrench to be thrown into unbound..

          2nd you have dnssec enabled in forwarding mode - zero reason to do that.. whole thread about it recently where someone put together guide on setting up dns and tls.. When you forwarder to a resolver, if it supports dnssec its already doing it.. So you do not have to click that check box.

          Do you have uncheck to let dhcp override your dns?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          C 1 Reply Last reply Feb 12, 2019, 8:52 PM Reply Quote 0
          • C
            chudak @johnpoz
            last edited by Feb 12, 2019, 8:52 PM

            @johnpoz

            Unchecked "Enable DNSSEC Support"

            "Do you have uncheck to let dhcp override your dns?"
            what do you mean ^ ?

            Not sure what I can do about pfBNG

            Thx!

            1 Reply Last reply Reply Quote 0
            • J
              johnpoz LAYER 8 Global Moderator
              last edited by Feb 12, 2019, 9:01 PM

              @chudak said in tcp error for address xxxx port 853:

              Not sure what I can do about pfBNG

              Turn it OFF, uninstall it - do your errors go away? If so it has something to do with your configuration of pfblocker.

              0_1550005313851_dnsoverride.png

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              C 1 Reply Last reply Feb 12, 2019, 9:49 PM Reply Quote 0
              • C
                chudak @johnpoz
                last edited by Feb 12, 2019, 9:49 PM

                @johnpoz

                My "Allow DNS server list to be overridden by DHCP/PPP on WAN" is unchecked

                I turned OFF pfBNG and still see errors in Resolver log:

                Feb 12 13:48:38	unbound	79932:3	debug: tcp error for address 9.9.9.9 port 853
                Feb 12 13:48:38	unbound	79932:3	debug: tcp error for address 149.112.112.112 port 853
                
                1 Reply Last reply Reply Quote 0
                • B
                  BBcan177 Moderator
                  last edited by Feb 13, 2019, 4:07 AM

                  Not sure if its related to this:
                  https://forum.netgate.com/topic/138274/unbound-1-8-1-only-single-thread-processing-dns-requests

                  To disable this option, you need to add the following to: pfSense Resolver Adv. Custom options: (and save)

                  server:so-reuseport: no
                  

                  Otherwise, try with pfSense 2.4.5 as it has Unbound 1.9.0

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  C 1 Reply Last reply Feb 13, 2019, 4:16 AM Reply Quote 0
                  • C
                    chudak @BBcan177
                    last edited by Feb 13, 2019, 4:16 AM

                    @bbcan177

                    Does not seem to make any difference:(

                    I wonder if this issue is easy reproducible...

                    My setup is pretty much out of the box

                    1 Reply Last reply Reply Quote 0
                    • B
                      BBcan177 Moderator
                      last edited by BBcan177 Feb 13, 2019, 4:20 AM Feb 13, 2019, 4:19 AM

                      In Unbound Adv. Settings, increase the "Log Level" to "2" and "Save". Then review the resolver.log for any other clues.... And as a test disable OpenVPN and see if the error stops.

                      "Experience is something you don't get until just after you need it."

                      Website: http://pfBlockerNG.com
                      Twitter: @BBcan177  #pfBlockerNG
                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                      C 1 Reply Last reply Feb 13, 2019, 4:29 AM Reply Quote 0
                      • C
                        chudak @BBcan177
                        last edited by chudak Feb 13, 2019, 4:30 AM Feb 13, 2019, 4:29 AM

                        @bbcan177

                        Done
                        Not sure what is suspicious in it, maybe insecured

                        Feb 12 20:27:32 unbound 80650:3 info: resolving myvisualiq.net. DS IN
                        Feb 12 20:27:32 unbound 80650:3 info: query response was ANSWER
                        Feb 12 20:27:32 unbound 80650:3 info: reply from <.> 9.9.9.9#853
                        Feb 12 20:27:32 unbound 80650:3 info: response for t.myvisualiq.net. A IN
                        Feb 12 20:27:32 unbound 80650:3 info: Verified that unsigned response is INSECURE
                        Feb 12 20:27:32 unbound 80650:3 info: NSEC3s for the referral proved no DS.
                        Feb 12 20:27:32 unbound 80650:3 info: resolving akamaiedge.net. DS IN
                        Feb 12 20:27:32 unbound 80650:3 info: Verified that unsigned response is INSECURE
                        Feb 12 20:27:32 unbound 80650:3 info: NSEC3s for the referral proved no DS.

                        1 Reply Last reply Reply Quote 0
                        • J
                          johnpoz LAYER 8 Global Moderator
                          last edited by johnpoz Feb 13, 2019, 5:24 AM Feb 13, 2019, 5:13 AM

                          Thought you turned off dnssec?

                          You sure you don't have multiple copies running of unbound, and your config never got updated? Pfblocker can leave some hanging when it tries to update, etc.

                          Also that
                          server:so-reuseport: no

                          would have to do with how many threads, would not cause a tcp error...

                          I can not reproduce this problem... Enabling dns over tls is clickity clickity..

                          What other packages you have? Sorry but installing pfblocker is NOT OUT OF THE BOX... And when asked what packages you didn't even list that.. I only knew you were running it from its entry in your unbound screenshot.

                          So what else is not out of the box??

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          C 1 Reply Last reply Feb 13, 2019, 5:24 AM Reply Quote 0
                          • C
                            chudak @johnpoz
                            last edited by chudak Feb 13, 2019, 5:25 AM Feb 13, 2019, 5:24 AM

                            @johnpoz

                            Ack on so-reuseport: no, and remover it

                            I’m sure I run one pfsense, how can it be confirmed?
                            Would it help if I send you my config xml file?

                            “Enabling dns over tls is clickity clickity..”. Btw how do you test that it actually works fine?

                            1 Reply Last reply Reply Quote 0
                            • J
                              johnpoz LAYER 8 Global Moderator
                              last edited by Feb 13, 2019, 5:25 AM

                              sorry that was "typo" I changed it - meant unbound :) can not run multiple copies of pfsense ;) hehehe

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              C 1 Reply Last reply Feb 13, 2019, 5:26 AM Reply Quote 0
                              • C
                                chudak @johnpoz
                                last edited by Feb 13, 2019, 5:26 AM

                                @johnpoz said in tcp error for address xxxx port 853:

                                sorry that was "typo" I changed it - meant unbound :) can not run multiple copies of pfsense ;) hehehe

                                Too late :)

                                1 Reply Last reply Reply Quote 0
                                • J
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by Feb 13, 2019, 5:27 AM

                                  what is output of this

                                  sockstat | grep unbound

                                  Also again going to ask are you running anything else?? Any other packages?

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  C 1 Reply Last reply Feb 13, 2019, 5:32 AM Reply Quote 0
                                  • C
                                    chudak @johnpoz
                                    last edited by chudak Feb 13, 2019, 5:33 AM Feb 13, 2019, 5:32 AM

                                    @johnpoz said in tcp error for address xxxx port 853:

                                    sockstat | grep unbound

                                    sockstat | grep unbound
                                    unbound  unbound    94103 3  udp4   192.168.90.1:53       *:*
                                    unbound  unbound    94103 4  tcp4   192.168.90.1:53       *:*
                                    unbound  unbound    94103 5  udp4   192.168.90.1:853      *:*
                                    unbound  unbound    94103 6  tcp4   192.168.90.1:853      *:*
                                    unbound  unbound    94103 7  udp4   192.168.70.1:53       *:*
                                    unbound  unbound    94103 8  tcp4   192.168.70.1:53       *:*
                                    unbound  unbound    94103 9  udp4   192.168.70.1:853      *:*
                                    unbound  unbound    94103 10 tcp4   192.168.70.1:853      *:*
                                    unbound  unbound    94103 11 udp4   127.0.0.1:53          *:*
                                    unbound  unbound    94103 12 stream /var/run/php-fpm.socket
                                    unbound  unbound    94103 13 stream /var/run/php-fpm.socket
                                    unbound  unbound    94103 14 tcp4   127.0.0.1:53          *:*
                                    unbound  unbound    94103 15 udp4   127.0.0.1:853         *:*
                                    unbound  unbound    94103 16 tcp4   127.0.0.1:853         *:*
                                    unbound  unbound    94103 17 udp4   192.168.90.1:53       *:*
                                    unbound  unbound    94103 18 tcp4   192.168.90.1:53       *:*
                                    unbound  unbound    94103 19 udp4   192.168.90.1:853      *:*
                                    unbound  unbound    94103 20 tcp4   192.168.90.1:853      *:*
                                    unbound  unbound    94103 21 udp4   192.168.70.1:53       *:*
                                    unbound  unbound    94103 22 tcp4   192.168.70.1:53       *:*
                                    unbound  unbound    94103 23 udp4   192.168.70.1:853      *:*
                                    unbound  unbound    94103 24 tcp4   192.168.70.1:853      *:*
                                    unbound  unbound    94103 25 udp4   127.0.0.1:53          *:*
                                    unbound  unbound    94103 26 tcp4   127.0.0.1:53          *:*
                                    unbound  unbound    94103 27 udp4   127.0.0.1:853         *:*
                                    unbound  unbound    94103 28 tcp4   127.0.0.1:853         *:*
                                    unbound  unbound    94103 29 udp4   192.168.90.1:53       *:*
                                    unbound  unbound    94103 30 tcp4   192.168.90.1:53       *:*
                                    unbound  unbound    94103 31 udp4   192.168.90.1:853      *:*
                                    unbound  unbound    94103 32 tcp4   192.168.90.1:853      *:*
                                    unbound  unbound    94103 33 udp4   192.168.70.1:53       *:*
                                    unbound  unbound    94103 34 tcp4   192.168.70.1:53       *:*
                                    unbound  unbound    94103 35 udp4   192.168.70.1:853      *:*
                                    unbound  unbound    94103 36 tcp4   192.168.70.1:853      *:*
                                    unbound  unbound    94103 37 udp4   127.0.0.1:53          *:*
                                    unbound  unbound    94103 38 tcp4   127.0.0.1:53          *:*
                                    unbound  unbound    94103 39 udp4   127.0.0.1:853         *:*
                                    unbound  unbound    94103 40 tcp4   127.0.0.1:853         *:*
                                    unbound  unbound    94103 41 udp4   192.168.90.1:53       *:*
                                    unbound  unbound    94103 42 tcp4   192.168.90.1:53       *:*
                                    unbound  unbound    94103 43 udp4   192.168.90.1:853      *:*
                                    unbound  unbound    94103 44 tcp4   192.168.90.1:853      *:*
                                    unbound  unbound    94103 45 udp4   192.168.70.1:53       *:*
                                    unbound  unbound    94103 46 tcp4   192.168.70.1:53       *:*
                                    unbound  unbound    94103 47 udp4   192.168.70.1:853      *:*
                                    unbound  unbound    94103 48 tcp4   192.168.70.1:853      *:*
                                    unbound  unbound    94103 49 udp4   127.0.0.1:53          *:*
                                    unbound  unbound    94103 50 tcp4   127.0.0.1:53          *:*
                                    unbound  unbound    94103 51 udp4   127.0.0.1:853         *:*
                                    unbound  unbound    94103 52 tcp4   127.0.0.1:853         *:*
                                    unbound  unbound    94103 53 tcp4   127.0.0.1:953         *:*
                                    unbound  unbound    94103 54 dgram  -> /var/run/logpriv
                                    unbound  unbound    94103 55 stream -> ??
                                    unbound  unbound    94103 56 stream -> ??
                                    unbound  unbound    94103 57 stream -> ??
                                    unbound  unbound    94103 58 stream -> ??
                                    unbound  unbound    94103 59 stream -> ??
                                    unbound  unbound    94103 60 stream -> ??
                                    unbound  unbound    94103 61 stream -> ??
                                    unbound  unbound    94103 62 stream -> ??
                                    

                                    I run several packages - https://snag.gy/CRfoFM.jpg

                                    Unfortunately I can't easily disable vpn ATM

                                    1 Reply Last reply Reply Quote 0
                                    • J
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by johnpoz Feb 13, 2019, 5:40 AM Feb 13, 2019, 5:38 AM

                                      That looks normal..

                                      Here I just turned with clickity clickity and ZERO errors..

                                      Feb 12 23:34:40 	unbound 	95989:0 	info: query response was ANSWER
                                      Feb 12 23:34:40 	unbound 	95989:0 	info: reply from <.> 9.9.9.9#853
                                      Feb 12 23:34:40 	unbound 	95989:0 	info: response for checkip.synology.com. A IN
                                      Feb 12 23:34:40 	unbound 	95989:0 	info: resolving checkip.synology.com. A IN
                                      Feb 12 23:34:40 	unbound 	95989:0 	info: query response was CNAME
                                      Feb 12 23:34:40 	unbound 	95989:0 	info: reply from <.> 149.112.112.112#853
                                      Feb 12 23:34:40 	unbound 	95989:0 	info: response for checkip.synology.com. A IN
                                      Feb 12 23:34:40 	unbound 	95989:0 	info: resolving checkip.synology.com. A IN
                                      Feb 12 23:34:40 	unbound 	95989:0 	info: query response was CNAME
                                      Feb 12 23:34:40 	unbound 	95989:0 	info: reply from <.> 9.9.9.9#853
                                      Feb 12 23:34:40 	unbound 	95989:0 	info: response for checkip.synology.com. A IN
                                      Feb 12 23:34:40 	unbound 	95989:0 	info: resolving checkip.synology.com. A IN
                                      Feb 12 23:34:35 	unbound 	95989:3 	info: query response was ANSWER
                                      Feb 12 23:34:35 	unbound 	95989:3 	info: reply from <.> 9.9.9.9#853
                                      Feb 12 23:34:35 	unbound 	95989:3 	info: response for t.myvisualiq.net. A IN
                                      Feb 12 23:34:35 	unbound 	95989:3 	info: resolving t.myvisualiq.net. A IN
                                      Feb 12 23:34:35 	unbound 	95989:3 	info: query response was CNAME
                                      Feb 12 23:34:35 	unbound 	95989:3 	info: reply from <.> 9.9.9.9#853
                                      Feb 12 23:34:35 	unbound 	95989:3 	info: response for t.myvisualiq.net. A IN
                                      Feb 12 23:34:34 	unbound 	95989:3 	info: resolving t.myvisualiq.net. A IN
                                      Feb 12 23:33:56 	unbound 	95989:3 	info: query response was ANSWER
                                      Feb 12 23:33:56 	unbound 	95989:3 	info: reply from <.> 9.9.9.9#853
                                      Feb 12 23:33:56 	unbound 	95989:3 	info: response for conemu.github.io. A IN
                                      Feb 12 23:33:56 	unbound 	95989:0 	info: query response was ANSWER
                                      Feb 12 23:33:56 	unbound 	95989:0 	info: reply from <.> 9.9.9.9#853
                                      Feb 12 23:33:56 	unbound 	95989:0 	info: response for conemu.github.io. A IN
                                      Feb 12 23:33:56 	unbound 	95989:2 	info: query response was ANSWER
                                      Feb 12 23:33:56 	unbound 	95989:2 	info: reply from <.> 9.9.9.9#853
                                      Feb 12 23:33:56 	unbound 	95989:2 	info: response for conemu.github.io. A IN
                                      Feb 12 23:33:56 	unbound 	95989:3 	info: resolving conemu.github.io. A IN
                                      Feb 12 23:33:56 	unbound 	95989:0 	info: resolving conemu.github.io. A IN
                                      Feb 12 23:33:56 	unbound 	95989:2 	info: resolving conemu.github.io. A IN
                                      Feb 12 23:33:54 	unbound 	95989:1 	info: query response was nodata ANSWER
                                      Feb 12 23:33:54 	unbound 	95989:1 	info: reply from <.> 149.112.112.112#853
                                      Feb 12 23:33:54 	unbound 	95989:1 	info: response for us.pool.ntp.org. AAAA IN
                                      Feb 12 23:33:53 	unbound 	95989:1 	info: resolving us.pool.ntp.org. AAAA IN
                                      Feb 12 23:33:53 	unbound 	95989:3 	info: query response was ANSWER
                                      Feb 12 23:33:53 	unbound 	95989:3 	info: reply from <.> 149.112.112.112#853
                                      Feb 12 23:33:53 	unbound 	95989:3 	info: response for us.pool.ntp.org. A IN
                                      Feb 12 23:33:53 	unbound 	95989:3 	info: resolving us.pool.ntp.org. A IN
                                      Feb 12 23:33:07 	unbound 	95989:0 	info: start of service (unbound 1.8.1). 
                                      

                                      I even did a query for that entry you posted up.. Notice nothing about insecure... No errors about tcp errors, etc..

                                      Post up your dns servers you set - you didn't set a gateway did you?
                                      0_1550036284770_forwardingdnstls.png

                                      Again for what possible reason or you running TLS local for??? That is just pointless!!! Who would be sniffing your dns traffic locally???
                                      unbound unbound 94103 52 tcp4 127.0.0.1:853 :

                                      Turn that OFF!!! Does that remove your errors?

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                                      C 1 Reply Last reply Feb 13, 2019, 5:43 AM Reply Quote 0
                                      • C
                                        chudak @johnpoz
                                        last edited by chudak Feb 13, 2019, 5:43 AM Feb 13, 2019, 5:43 AM

                                        @johnpoz ok ok done :)

                                        DNS Server Settings =>
                                        https://snag.gy/g3bnED.jpg

                                        "clickity clickity and ZERO errors.." that's in logs Resolver, what Log Level do you have set ?

                                        1 Reply Last reply Reply Quote 0
                                        • J
                                          johnpoz LAYER 8 Global Moderator
                                          last edited by johnpoz Feb 13, 2019, 5:45 AM Feb 13, 2019, 5:44 AM

                                          2! It wouldn't show that info not at least that.

                                          And Yes its the resolver log.... Where else would it be?

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                                          C 1 Reply Last reply Feb 13, 2019, 5:45 AM Reply Quote 0
                                          20 out of 29
                                          • First post
                                            20/29
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received