tcpdump -vv port 53 kimenete egy dns lekérdezés után
20:10:40.469840 IP (tos 0x0, ttl 64, id 54053, offset 0, flags [DF], proto: UDP (17), length: 64) 10.100.10.32.43713 > voyager.domain: [udp sum ok] 16575+ A? forum.videolan.org. (36)
20:10:40.471852 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 75) voyager.21723 > ns2.externet.hu.domain: [udp sum ok] 59366+ [1au] A? forum.videolan.org. ar: . OPT UDPsize=4096 OK (47)
20:10:40.473060 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 82) voyager.33178 > ns2.externet.hu.domain: [udp sum ok] 59768+ [1au] PTR? 37.37.70.195.in-addr.arpa. ar: . OPT UDPsize=4096 OK (54)
20:10:40.493336 IP (tos 0x0, ttl 60, id 54083, offset 0, flags [DF], proto: UDP (17), length: 189) ns2.externet.hu.domain > voyager.33178: 59768 q: PTR? 37.37.70.195.in-addr.arpa. 1/2/3 37.37.70.195.in-addr.arpa.[|domain]
20:10:40.531332 IP (tos 0x0, ttl 60, id 59969, offset 0, flags [DF], proto: UDP (17), length: 260) ns2.externet.hu.domain > voyager.21723: 59366 q: A? forum.videolan.org. 2/4/5 forum.videolan.org. CNAME[|domain]
20:10:40.532349 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 76) voyager.21271 > ns2.externet.hu.domain: [udp sum ok] 7452+ [1au] A? sirius.videolan.org. ar: . OPT UDPsize=4096 OK (48)
20:10:40.555344 IP (tos 0x0, ttl 60, id 7543, offset 0, flags [DF], proto: UDP (17), length: 240) ns2.externet.hu.domain > voyager.21271: 7452 q: A? sirius.videolan.org. 1/4/5 sirius.videolan.org. A sirius.videolan.org ns: [|domain]
20:10:40.556320 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 84) voyager.38454 > ns2.externet.hu.domain: 30590+ [1au] PTR? 119.250.191.88.in-addr.arpa. ar: . (56)
20:10:40.556878 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 249) voyager.domain > 10.100.10.32.43713: 16575 q: A? forum.videolan.org. 2/4/4 forum.videolan.org. CNAME[|domain]
20:10:40.683366 IP (tos 0x0, ttl 60, id 19776, offset 0, flags [DF], proto: UDP (17), length: 190) ns2.externet.hu.domain > voyager.38454: 30590 q: PTR? 119.250.191.88.in-addr.arpa. 1/2/3 119.250.191.88.in-addr.arpa.[|domain]
20:10:41.184209 IP (tos 0x0, ttl 64, id 54231, offset 0, flags [DF], proto: UDP (17), length: 67) 10.100.10.32.47680 > voyager.domain: [udp sum ok] 3274+ A? download.videolan.org. (39)
20:10:41.184959 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 78) voyager.65141 > ns2.externet.hu.domain: [udp sum ok] 19791+ [1au] A? download.videolan.org. ar: . OPT UDPsize=4096 OK (50)
20:10:41.280268 IP (tos 0x0, ttl 60, id 56924, offset 0, flags [DF], proto: UDP (17), length: 264) ns2.externet.hu.domain > voyager.65141: 19791 q: A? download.videolan.org. 2/4/5 download.videolan.org. CNAME[|domain]
20:10:41.281120 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 77) voyager.21019 > ns2.externet.hu.domain: [udp sum ok] 12552+ [1au] A? ganesh2.videolan.org. ar: . OPT UDPsize=4096 OK (49)
20:10:41.364478 IP (tos 0x0, ttl 60, id 13367, offset 0, flags [DF], proto: UDP (17), length: 241) ns2.externet.hu.domain > voyager.21019: 12552 q: A? ganesh2.videolan.org. 1/4/5 ganesh2.videolan.org. A ganesh2.videolan.org[|domain]
20:10:41.365332 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 82) voyager.35739 > ns2.externet.hu.domain: [udp sum ok] 28416+ [1au] PTR? 9.250.191.88.in-addr.arpa. ar: . OPT UDPsize=4096 OK (54)
20:10:41.365850 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 253) voyager.domain > 10.100.10.32.47680: 3274 q: A? download.videolan.org. 2/4/4 download.videolan.org. CNAME[|domain]
20:10:41.468510 IP (tos 0x0, ttl 60, id 59243, offset 0, flags [DF], proto: UDP (17), length: 189) ns2.externet.hu.domain > voyager.35739: 28416 q: PTR? 9.250.191.88.in-addr.arpa. 1/2/3 9.250.191.88.in-addr.arpa.[|domain]
fw bekapcsolása után:
20:16:26.858210 IP (tos 0x0, ttl 64, id 9583, offset 0, flags [DF], proto: UDP (17), length: 69) 10.100.10.32.38276 > voyager.domain: [udp sum ok] 22209+ A? www.linuxfoundation.org. (41)
20:16:26.860040 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 80) voyager.21763 > 195.70.37.37.domain: [udp sum ok] 33695+ [1au] A? www.linuxfoundation.org. ar: . OPT UDPsize=4096 OK (52)
20:16:27.972916 IP (tos 0x0, ttl 60, id 33908, offset 0, flags [DF], proto: UDP (17), length: 181) 195.70.37.37.domain > voyager.21763: 33695 q: A? www.linuxfoundation.org. 1/2/3 www.linuxfoundation.org. A[|domain]
20:16:27.973689 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 170) voyager.domain > 10.100.10.32.38276: 22209 q: A? www.linuxfoundation.org. 1/2/2 www.linuxfoundation.org. A[|domain]
20:16:58.448307 IP (tos 0x0, ttl 64, id 17481, offset 0, flags [DF], proto: UDP (17), length: 60) 10.100.10.32.39953 > voyager.domain: [udp sum ok] 9313+ A? www.google.com. (32)
20:16:58.449367 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 73) voyager.12979 > 195.70.37.37.domain: [udp sum ok] 18752+ [1au] A? www.l.google.com. ar: . OPT UDPsize=4096 OK (45)
20:16:58.468348 IP (tos 0x0, ttl 60, id 57110, offset 0, flags [DF], proto: UDP (17), length: 361) 195.70.37.37.domain > voyager.12979: 18752 q: A? www.l.google.com. 4/7/8 www.l.google.com. A 74.125.43.103, www.l.google.com.[|domain]
20:16:58.469404 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 368) voyager.domain > 10.100.10.32.39953: 9313 q: A? www.google.com. 5/7/7 www.google.com. CNAME www.l.google.com., www.l.google.com.[|domain]
20:17:18.943065 IP (tos 0x0, ttl 64, id 22605, offset 0, flags [DF], proto: UDP (17), length: 70) 10.100.10.32.51000 > voyager.domain: [udp sum ok] 48711+ A? hu.search.etargetnet.com. (42)
20:17:18.943524 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 163) voyager.domain > 10.100.10.32.51000: 48711 q: A? hu.search.etargetnet.com. 1/2/2 hu.search.etargetnet.com. A[|domain]
20:17:26.682790 IP (tos 0x0, ttl 64, id 24540, offset 0, flags [DF], proto: UDP (17), length: 67) 10.100.10.32.33082 > voyager.domain: [udp sum ok] 53422+ A? www.freestandards.org. (39)
20:17:26.683922 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 78) voyager.46933 > 195.70.37.37.domain: [udp sum ok] 19301+ [1au] A? www.freestandards.org. ar: . OPT UDPsize=4096 OK (50)
20:17:26.909908 IP (tos 0x0, ttl 60, id 58666, offset 0, flags [DF], proto: UDP (17), length: 179) 195.70.37.37.domain > voyager.46933: 19301 q: A? www.freestandards.org. 1/2/3 www.freestandards.org. A[|domain]
20:17:26.910543 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 168) voyager.domain > 10.100.10.32.33082: 53422 q: A? www.freestandards.org. 1/2/2 www.freestandards.org. A[|domain]
20:17:29.694587 IP (tos 0x0, ttl 64, id 25293, offset 0, flags [DF], proto: UDP (17), length: 70) 10.100.10.32.53864 > voyager.domain: [udp sum ok] 32543+ A? www.linux-foundation.org. (42)
20:17:29.695605 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 81) voyager.32328 > 195.70.37.37.domain: [udp sum ok] 29327+ [1au] A? www.linux-foundation.org. ar: . OPT UDPsize=4096 OK (53)
20:17:29.913620 IP (tos 0x0, ttl 60, id 46154, offset 0, flags [DF], proto: UDP (17), length: 165) 195.70.37.37.domain > voyager.32328: 29327 q: A? www.linux-foundation.org. 1/2/3 www.linux-foundation.org. A[|domain]
20:17:29.914213 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 154) voyager.domain > 10.100.10.32.53864: 32543 q: A? www.linux-foundation.org. 1/2/2 www.linux-foundation.org. A[|domain]
20:17:32.706791 IP (tos 0x0, ttl 64, id 26046, offset 0, flags [DF], proto: UDP (17), length: 70) 10.100.10.32.44433 > voyager.domain: [udp sum ok] 27683+ A? www.google-analytics.com. (42)
20:17:32.707397 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 354) voyager.domain > 10.100.10.32.44433: 27683 q: A? www.google-analytics.com. 2/7/7 www.google-analytics.com. CNAME[|domain]