For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Bhoopendra_Vish's avatar
Bhoopendra_Vish
Icon for Nimbostratus rankNimbostratus
Nov 08, 2015

How to Capture DNS Packets on GTM

I want to capture DNS traffic on GTM, i want to verify if request is going to the next available Data Centre when i invoke the DR

 

1 Reply

  • I haven't licensed or used GTM so my advice is based purely on speculation.

    Have you tried simply dumping the traffic from an interface using tcpdump? Most DNS traffic is unencrypted so you should be able to see what's going on.

    First, find out which interface you want to sniff with the "ifconfig" command. If the destination server is located on an interface called "vlan1275" you can dump all DNS traffic to a specific IP address thus:

    [xxx@BIG10001:Active:Changes Pending] log  tcpdump -i vlan1275 udp port 53 and host 1.2.3.4
    
    tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
    
    listening on vlan1275, link-type EN10MB (Ethernet), capture size 96 bytes
    
    11:25:31.279433 IP 10.x.x.x.61750 > server.domain:  52331+ A? client-cf.dropbox.com. (39)
    
    11:25:31.445888 IP server.domain > 10.x.x.x.61750:  52331 8/0/0 A[|domain]
    
    11:25:31.586319 IP 10.x.x.x.61754 > server.domain:  43652+ A? [www.bing.com.] (http://www.bing.com.) (30)
    
    11:25:31.587767 IP server > 10.x.x.x.61754:  43652 2/0/0 CNAME any.edge.bing.com., (69)
    

    ^C