On Saturday, 10 May 2025 01:35:28 CEST Greg Choules via bind-users wrote: > Third, use tcpdump to capture port 53. Do this to a file, then look at it > offline in Wireshark. (Michael just beat me to that tip). Check how queries > are arriving into BIND and what it does with them. Particularly look at the > timings of packets and for errors, such as packet loss or ICMP.
We were close, I'm impressed at your perception for having caught it in time! As for logging it to a file, yes, this is what logs it into a PCAP format. That can then be opened in Wireshark for further analysis. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users