Home

Windows DNS client - delay with reverse lookup

%3CLINGO-SUB%20id%3D%22lingo-sub-182950%22%20slang%3D%22en-US%22%3EWindows%20DNS%20client%20-%20delay%20with%20reverse%20lookup%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-182950%22%20slang%3D%22en-US%22%3E%3CP%3EHello%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20windows%202012%20server%2C%20which%20is%20in%20MS%20cluster.%20In%20TCP%2FIP%20protocol%203%20dns%20servers%20are%20configured%20(this%20server%20works%20as%20dns%20client)%3C%2FP%3E%3CP%3EAnd%20there%20is%20problem%20with%20reverse%20lookup%20requests%20-%20there%20is%20additional%20delay%20about%204%20seconds.%3C%2FP%3E%3CP%3ESome%20facts%3A%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20DNS%20servers%20works%20fine.%20There%20is%20no%20delay%20in%20response%20(captured%20packets%20on%20network%20with%20Wireshark%2C%20response%20comes%20within%20mseconds.%20Exactly%20these%20DNS%20servers%20are%20also%20used%20on%20other%20windows%20machines%20and%20there%20is%20no%20problem%20with%20them.%3C%2FP%3E%3CP%3E2.%20nslookup%20works%20fine.%20There%20is%20no%20delay%20and%26nbsp%3B%20correct%20response%20is%20returned.%3C%2FP%3E%3CP%3E(but%20nslookup%20bypass%20dns%20client%20and%20queries%20DNS%20server%20directly)%3C%2FP%3E%3CP%3E3.%20ping%20-a%20gives%20delay%20for%20about%204%20seconds.%3C%2FP%3E%3CP%3E4.%20I%20do%20not%20see%20any%20NetBIOS%20or%20WINS%20requests%20from%20this%20computer%20in%20Wireshark.%3C%2FP%3E%3CP%3E5.%20If%20I%20add%20corresponding%20entries%20into%20hosts%20file%20-%20then%20ping%20-a%20works%20without%20delay.%3C%2FP%3E%3CP%3E6.%20Normal%20dns%20queries%20via%20dns%20client%20(ping%20%3CHOSTNAME%3E)%20works%20fine%2C%20there%20is%20no%20any%20additional%20delay.%3C%2FHOSTNAME%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20cannot%20blame%20DNS%20servers%20-%20they%20seems%20to%20work%20fine%20without%20any%20problem.%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20problem%20seems%20to%20be%20in%20the%20local%20dns%20client%2C%20but%20I%20am%20out%20of%20ideas%20what%20else%20can%20I%20check.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBelow%20captured%20traffic%20in%20Wireshark%2C%20and%20results%20of%20%22nslookup%20-debug%20%22%20command.%3C%2FP%3E%3CP%3EIf%20you%20have%20any%20idea%20where%20problem%20could%20be%20-%20you%20are%20more%20than%20welcome%20%3A-).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F32274i78AF836E010B3090%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%222018-04-14_23-06-51_hided.png%22%20title%3D%222018-04-14_23-06-51_hided.png%22%20%2F%3E%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20528px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F32273i3E356B19155A82E5%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22dns_reverse_lookup_response.png%22%20title%3D%22dns_reverse_lookup_response.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EC%3A%5CUsers%5Cadmin%5CDocuments%26gt%3Bnslookup%20-debug%2010.198.126.28%3CBR%20%2F%3E------------%3CBR%20%2F%3EGot%20answer%3A%3CBR%20%2F%3EHEADER%3A%3CBR%20%2F%3Eopcode%20%3D%20QUERY%2C%20id%20%3D%201%2C%20rcode%20%3D%20NOERROR%3CBR%20%2F%3Eheader%20flags%3A%20response%2C%20auth.%20answer%2C%20want%20recursion%2C%20recursion%20avail.questions%20%3D%201%2C%20answers%20%3D%201%2C%20authority%20records%20%3D%200%2C%20additional%20%3D%200%3C%2FP%3E%3CP%3EQUESTIONS%3A%3CBR%20%2F%3E199.199.199.10.in-addr.arpa%2C%20type%20%3D%20PTR%2C%20class%20%3D%20IN%3CBR%20%2F%3EANSWERS%3A%3CBR%20%2F%3E-%26gt%3B%20199.199.199.10.in-addr.arpa%3CBR%20%2F%3Ename%20%3D%20lbaxxxxx.xxx.xx%3CBR%20%2F%3Ettl%20%3D%2086400%20(1%20day)%3C%2FP%3E%3CP%3E------------%3CBR%20%2F%3EServer%3A%20lbaxxxxx.xxx.xx%3CBR%20%2F%3EAddress%3A%2010.199.199.199%3C%2FP%3E%3CP%3E------------%3CBR%20%2F%3EGot%20answer%3A%3CBR%20%2F%3EHEADER%3A%3CBR%20%2F%3Eopcode%20%3D%20QUERY%2C%20id%20%3D%202%2C%20rcode%20%3D%20NOERROR%3CBR%20%2F%3Eheader%20flags%3A%20response%2C%20auth.%20answer%2C%20want%20recursion%2C%20recursion%20avail.%3CBR%20%2F%3Equestions%20%3D%201%2C%20answers%20%3D%201%2C%20authority%20records%20%3D%200%2C%20additional%20%3D%200%3C%2FP%3E%3CP%3EQUESTIONS%3A%3CBR%20%2F%3E28.126.198.10.in-addr.arpa%2C%20type%20%3D%20PTR%2C%20class%20%3D%20IN%3CBR%20%2F%3EANSWERS%3A%3CBR%20%2F%3E-%26gt%3B%2028.126.198.10.in-addr.arpa%3CBR%20%2F%3Ename%20%3D%20SVMXXXX.xxx.xx%3CBR%20%2F%3Ettl%20%3D%2086400%20(1%20day)%3C%2FP%3E%3CP%3E------------%3CBR%20%2F%3EName%3A%20SVMXXXX.xxx.xx%3CBR%20%2F%3EAddress%3A%2010.198.126.28%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-182950%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ENetworking%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-358886%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20DNS%20client%20-%20delay%20with%20reverse%20lookup%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-358886%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3EI%20was%20wondering%20did%20you%20receive%20any%20feedback%20or%20find%20the%20reason%20why%20reverse%20DNS%20is%20slow.%20I%20see%20the%20exact%20same%20behavior%20at%20a%20customer%2C%20did%20also%20a%20Wireshark%20trace%20and%20see%20the%20DNS%20reverse%20request%2C%20immediate%20answer%20from%20DNS%20server%20and%20seconds%20nothing%20until%20de%20reply%20starts%20of%20the%20ping.%3CBR%20%2F%3E%3CBR%20%2F%3EI've%20seen%20also%20this%20behavior%3A%3CBR%20%2F%3E-%20reverse%20lookup%20in%20the%20same%20subnet%20%3D%20slow%20-%26gt%3B%20in%20this%20case%20I%20see%20ARP%20request%20just%20before%20the%20reply%20of%20the%20ping%20but%20delay%20between%20DNS%20reply%20and%20ARP%3CBR%20%2F%3E-%20reverse%20lookup%20in%20another%20subnet%20%3D%20fast%20-%26gt%3B%20in%20this%20case%20no%20ARP%20request%20because%20it%20is%20sent%20to%20the%20default%20gateway%20and%20that%20is%20already%20in%20his%20local%20ARP%20table.%20see%20immediately%20after%20the%20DNS%20response%20ICMP%20packets%3CBR%20%2F%3E-%20have%20it%20both%20on%20Windows%202012%20R2%20and%20Windows%202016%2C%20not%20on%20Windows%202008%20R2%3CBR%20%2F%3E-%20don't%20have%20it%20on%20non-domain%20joined%20servers%20(so%20in%20workgroup)%20or%20at%20least%20cannot%20simulate%20it%3CBR%20%2F%3E%3CBR%20%2F%3EFor%20simulation%20I%20just%20use%20ping%20-a%20x.x.x.x%3CBR%20%2F%3EIf%20you%20have%20more%20info%20let%20me%20know%3F%3CBR%20%2F%3E%3CBR%20%2F%3EThx%2C%3CBR%20%2F%3EPete%3C%2FLINGO-BODY%3E
loyder
Occasional Visitor

Hello

 

I have windows 2012 server, which is in MS cluster. In TCP/IP protocol 3 dns servers are configured (this server works as dns client)

And there is problem with reverse lookup requests - there is additional delay about 4 seconds.

Some facts: 

1. DNS servers works fine. There is no delay in response (captured packets on network with Wireshark, response comes within mseconds. Exactly these DNS servers are also used on other windows machines and there is no problem with them.

2. nslookup works fine. There is no delay and  correct response is returned.

(but nslookup bypass dns client and queries DNS server directly)

3. ping -a <ip-address> gives delay for about 4 seconds.

4. I do not see any NetBIOS or WINS requests from this computer in Wireshark.

5. If I add corresponding entries into hosts file - then ping -a <ip-address> works without delay.

6. Normal dns queries via dns client (ping <hostname>) works fine, there is no any additional delay.

 

I cannot blame DNS servers - they seems to work fine without any problem. 

The problem seems to be in the local dns client, but I am out of ideas what else can I check.

 

Below captured traffic in Wireshark, and results of "nslookup -debug <ip-address>" command.

If you have any idea where problem could be - you are more than welcome :-).

 

2018-04-14_23-06-51_hided.pngdns_reverse_lookup_response.png

 

C:\Users\admin\Documents>nslookup -debug 10.198.126.28
------------
Got answer:
HEADER:
opcode = QUERY, id = 1, rcode = NOERROR
header flags: response, auth. answer, want recursion, recursion avail.
questions = 1, answers = 1, authority records = 0, additional = 0

QUESTIONS:
199.199.199.10.in-addr.arpa, type = PTR, class = IN
ANSWERS:
-> 199.199.199.10.in-addr.arpa
name = lbaxxxxx.xxx.xx
ttl = 86400 (1 day)

------------
Server: lbaxxxxx.xxx.xx
Address: 10.199.199.199

------------
Got answer:
HEADER:
opcode = QUERY, id = 2, rcode = NOERROR
header flags: response, auth. answer, want recursion, recursion avail.
questions = 1, answers = 1, authority records = 0, additional = 0

QUESTIONS:
28.126.198.10.in-addr.arpa, type = PTR, class = IN
ANSWERS:
-> 28.126.198.10.in-addr.arpa
name = SVMXXXX.xxx.xx
ttl = 86400 (1 day)

------------
Name: SVMXXXX.xxx.xx
Address: 10.198.126.28

1 Reply
Hi,

I was wondering did you receive any feedback or find the reason why reverse DNS is slow. I see the exact same behavior at a customer, did also a Wireshark trace and see the DNS reverse request, immediate answer from DNS server and seconds nothing until de reply starts of the ping.

I've seen also this behavior:
- reverse lookup in the same subnet = slow -> in this case I see ARP request just before the reply of the ping but delay between DNS reply and ARP
- reverse lookup in another subnet = fast -> in this case no ARP request because it is sent to the default gateway and that is already in his local ARP table. see immediately after the DNS response ICMP packets
- have it both on Windows 2012 R2 and Windows 2016, not on Windows 2008 R2
- don't have it on non-domain joined servers (so in workgroup) or at least cannot simulate it

For simulation I just use ping -a x.x.x.x
If you have more info let me know?

Thx,
Pete
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies