DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

2860n: DNS Suddenly disappears for some users only

  • gary.lane
  • Topic Author
  • User
  • User
More
19 Dec 2016 14:01 #1 by gary.lane
OK, please bear with me as a I try and describe this intermittent problem.

The system is running normally and successfully with WAN access via VDSL and backup ADSL provided by a Vigor 120.

Occasionally, half the computers on the internal network suddenly lose the ability to browse the net. They still have connectivity, they can use email, spotify etc. and ping internet addresses but cannot access websites. From this, I deduce that something is wrong with the DNS servers. But what? In the LAN setup I have tried setting Google's DNS servers, OpenDNS servers and left blank for ISP's servers but no joy. If I release and renew the IP for a client, it fails to grab a new IP address implying the DHCP server is no longer working.

There is nothing that I can notice is different between "up" machines and "down" machines. And the specific machines that fail will be different during each "episode".

The only things that resolves the situation is a router reboot which is impractical and highly disruptive. Any thoughts where I should go looking?

Please Log in or Create an account to join the conversation.

More
19 Dec 2016 16:27 #2 by g6ifs
Any chance someone has accidently put another DHCP server on the network?

Please Log in or Create an account to join the conversation.

  • gary.lane
  • Topic Author
  • User
  • User
More
19 Dec 2016 16:34 #3 by gary.lane
Interesting thought. I'll check that

Please Log in or Create an account to join the conversation.

More
19 Dec 2016 18:33 #4 by piste basher
Yes, last time I had that problem there was an IP conflict on the network. Even though I use IP MAC binding one machine was grabbing its "old" IP.

Please Log in or Create an account to join the conversation.

  • gary.lane
  • Topic Author
  • User
  • User
More
19 Dec 2016 19:10 #5 by gary.lane
No. That was a sensible thought but there is no conflict and I have enforced strict firewall rules that deny access to any machine out of my DHCP range. No indication in the ARP table that anyone is not playing nice.

It's driving me mad. Any other ideas?

Please Log in or Create an account to join the conversation.

More
20 Dec 2016 11:57 #6 by admin3
Make sure to check the syslog output of the router. If your Vigor router was set up some time ago, the DoS defense for UDP flood defense has a fairly low value, which is increased with later default settings.
Enough DNS queries at once or UDP packets in general could potentially trigger the UDP flood defense which may cause behaviour similar to what you're describing.

If you see DoS defense messages in syslog, increasing the UDP flood defense count value (or disabling it), should resolve your problem.



Forum Administrator

Please Log in or Create an account to join the conversation.