Monday, June 18, 2018

Packet capture shows DNS answer but nslookup will NOT display this

Hi guys,

I'm having a super weird problem. I have one user with below symptoms:

  1. Cannot access a particular intranet website on any web browser (e.g. bug.company.com)
  2. nslookup gives an external address (206.) labeled "Non-authoritative answer" instead of the correct internal one (192.)

My laptop has absolutely NO problems at all accessing this website - nslookup is fine, web browser is fine, etc

I've confirmed:

  1. Laptop is on the EXACT same network as my laptop
  2. Laptop has IDENTICAL IPv4/NIC setting down to every checkbox (DNS server, DHCP, network, etc)
  3. Running DNS lookup while specifying DNS servers addresses produces same result
  4. ipconfig /flushdns
  5. Reboot multiple times
  6. Different (but still intranet) network segment via both wired/wifi

Very strange thing is that I ran a Wireshark packet capture on this problematic laptop.

And I RECEIVED the CORRECT ANSWER in the packets when I ran the same query... but the nslookup from Windows cmd did NOT display this at all.

Other than concluding that the native name resolution protocol on this installation of Windows is FUCKED, I'm kind of lost on what else to do next... Generally packet capture is my last resort that shows you 100% of what's going on, but I can't explain this behaviour of nslookup.

Any help? Thanks in advance



No comments:

Post a Comment