5nowman Posted May 18 Posted May 18 8 minutes ago, toffee_paul said: Following a call with Smoothwall they believe it to be an issue with DNS. Upon changing the DNS forwarders to Google's (8.8.8.8 / 8.8.4.4) on our on-prem appliance, access to Arbor is now working fine. May be worth changing yours temporarily and see if it makes a difference. @5nowman you mentioned you're on BT Fibre so maybe your issue is different as you mentioned slowness rather than an out-and-out inability the resource itself. Thanks to Alan @ Smoothwall for highlighting this. Thank you for your reply. 8.8.8.8 tested already. Is 8.8.4.4 another google DNS? Infact smoothwall redirects to that.
tom_newton Posted May 18 Posted May 18 There's nothing we have particularly changed. One of our 3rd line support engineers suggests there's an issue with virgin's DNS (he referenced this thread, I presume he's working on that ticket, I have been in meetings all aft and not looked jsut yet). I also have a whatsapp from one of our more technically adept partners who suggest that they had a similar issue, and that was down to using cloudflare's DNS over google's.
tom_newton Posted May 18 Posted May 18 @5nowman Smoothwall doesnt redirect to anything - it will use the DNS resolvers you tell it to use. 8.8.4.4 is the secondary to 8.8.8.8. You can also try quad9s (9.9.9.9) as an alternative, although that's a PDNS so will sometimes block stuff Edit - if you have a ticket # I can ask one of our engineers to take a look at yours in the same way as Alan did for @toffee_paul
tom_newton Posted May 18 Posted May 18 FWIW I get a minimum 5 second delay getting to gb6.behaviourwatch.co.uk - this is through a non-smoothwall connection, and consistent over multiple runs
tom_newton Posted May 18 Posted May 18 Unlikely to be a DNS issue with that one - as here you can see a range of servers give the same answer, and quickly
SeeFights Posted May 18 Posted May 18 13 minutes ago, tom_newton said: There's nothing we have particularly changed. One of our 3rd line support engineers suggests there's an issue with virgin's DNS (he referenced this thread, I presume he's working on that ticket, I have been in meetings all aft and not looked jsut yet). I also have a whatsapp from one of our more technically adept partners who suggest that they had a similar issue, and that was down to using cloudflare's DNS over google's. see i have a ticket open currently about this issue referencing this thread in the ticket. is there a fix for it yet?
tom_newton Posted May 18 Posted May 18 @SeeFights there isn't a Smoothwall problem in this thread as I see it so far: happy for you to DM me your ticket number. The arbor/raven issue is 100% DNS. The behaviourwatch issue is, to my mind, a behaviourwatch problem. I am seeing ~15 seconds to download a tiny gif from their site.
SeeFights Posted May 18 Posted May 18 Just now, tom_newton said: @SeeFights there isn't a Smoothwall problem in this thread as I see it so far: happy for you to DM me your ticket number. The arbor/raven issue is 100% DNS. The behaviourwatch issue is, to my mind, a behaviourwatch problem. I am seeing ~15 seconds to download a tiny gif from their site. with it being a dns issue it sounds like its my bosses issue *insert devious smile* im fine waiting for whoever at smoothwall gets to me its eod for us now
tom_newton Posted May 18 Posted May 18 OK, I find from different ISPs behaviourwatch has no issue. My home Andrews and Arnold is horror, from one of our boxes in google cloud, no worries. Suspect they have routing issues
tom_newton Posted May 18 Posted May 18 If you could lay out your exact issue here @SeeFights or DM me a ticket I might take a stab at working out the issue
SeeFights Posted May 18 Posted May 18 (edited) 4 minutes ago, tom_newton said: If you could lay out your exact issue here @SeeFights or DM me a ticket I might take a stab at working out the issue So its pretty much the same issue as the start. Arbor on some machines tries to contact https://cdn.ravenjs.com/3.16.1/raven.min.js - Fails then returns a 403. I have tried forcing a chrome refresh, i have reinstalled windows and that wont work, i have tried it on a different wifi (one that bypasses smoothwall) and that doesnt work, i have tried it with the proxy off and that doesnt work. even uninstalling chrome and reinstalling doesnt work. Edge also doesnt work, im not permitted to try firefox so not sure with that. oh and not to mention, it only affects a handful of people - if it was dns it would affect everyone no? Edited May 18 by SeeFights
toffee_paul Posted May 18 Author Posted May 18 No, DNS queries can be cached just like the JavaScript files and other content can be cached locally on machines.
tom_newton Posted May 18 Posted May 18 Additionally different people use different DNS servers (most folk just use their ISP) and you get to a different DNS server based on your location due to the anycast nature of their IPs (8.8.8.8 for me is not the same endpoint as it is for you). I would strongly suggest going to 8.8.8.8 in your Smoothwall's DNS page, see if that sorts it. Or it might be upstream DNS in your AD if you are AD and transparent proxy.
SeeFights Posted May 18 Posted May 18 1 minute ago, tom_newton said: Additionally different people use different DNS servers (most folk just use their ISP) and you get to a different DNS server based on your location due to the anycast nature of their IPs (8.8.8.8 for me is not the same endpoint as it is for you). I would strongly suggest going to 8.8.8.8 in your Smoothwall's DNS page, see if that sorts it. Or it might be upstream DNS in your AD if you are AD and transparent proxy. sorry guys so much of that made no sense to me. im not trained in network troubleshooting
tom_newton Posted May 18 Posted May 18 OK, we are almost certainly at that level - is there someone who is a DNS wrangler in your school?
SeeFights Posted May 18 Posted May 18 1 minute ago, tom_newton said: OK, we are almost certainly at that level - is there someone who is a DNS wrangler in your school? my network manager (my boss) just walked in and is going to change the dns to googles. 1
SeeFights Posted May 18 Posted May 18 (edited) 12 minutes ago, tom_newton said: OK, we are almost certainly at that level - is there someone who is a DNS wrangler in your school? its dns. it makes no sense but it works. Edited May 18 by SeeFights 1
5nowman Posted May 18 Posted May 18 1 hour ago, tom_newton said: FWIW I get a minimum 5 second delay getting to gb6.behaviourwatch.co.uk - this is through a non-smoothwall connection, and consistent over multiple runs 5 seconds?!? That is long! The page has loads of objects and if there js a 5 second delay that could be it! What isp are you testing it from?
tom_newton Posted May 18 Posted May 18 That was from my home ISP, Andrews and Arnold. I've asked a few folks to test from their ISPs but had no repsonse yet
tom_newton Posted May 18 Posted May 18 OK, it is devinitely a DNS issue for me with behaviourwatch, although whatever I tell curl to use doesnt help, if I do the resolution manually it is lightening fast
ConceroEdu_Matt Posted May 18 Posted May 18 This isn't just for Arbor, we saw this last week with Instagram when unblocking, and changing DNS on the box resolved it for us as well. However, we changed it to 1.1.1.1 - from Googles, and then it worked.
5nowman Posted May 18 Posted May 18 3 hours ago, tom_newton said: @5nowman Smoothwall doesnt redirect to anything - it will use the DNS resolvers you tell it to use. 8.8.4.4 is the secondary to 8.8.8.8. You can also try quad9s (9.9.9.9) as an alternative, although that's a PDNS so will sometimes block stuff Edit - if you have a ticket # I can ask one of our engineers to take a look at yours in the same way as Alan did for @toffee_paul thank you . will DM you the ticket number. Are we saying different ISPS are having different delay times?
ConceroEdu_Matt Posted May 18 Posted May 18 42 minutes ago, 5nowman said: thank you . will DM you the ticket number. Are we saying different ISPS are having different delay times? It's not your ISP, it's your chosen DNS. Although, it doesn't really make sense, as I have seen it work on Google DNS one minute, and then not on Cloudflare, and then vice versa. Almost like changing the DNS in SW refreshes some cache or something
5nowman Posted May 18 Posted May 18 (edited) 4 hours ago, ConceroEdu_Matt said: It's not your ISP, it's your chosen DNS. Although, it doesn't really make sense, as I have seen it work on Google DNS one minute, and then not on Cloudflare, and then vice versa. Almost like changing the DNS in SW refreshes some cache or something Have had such a horrible time with this all week with behavourwatch smoothwall etc. Support has been decent from the ISP and behaviourwatch however neither could find the fault. Escalted to smoothwall direct today. I checked on our smoothwall 5 hours ago, ConceroEdu_Matt said: This isn't just for Arbor, we saw this last week with Instagram when unblocking, and changing DNS on the box resolved it for us as well. However, we changed it to 1.1.1.1 - from Googles, and then it worked. our smoothwall is set to: 1.1.1.1, 8.8.8.8, 9.9.9.9 which seems ok right.... Edited May 18 by 5nowman
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now