9
Questions 1-3: 4) DNS Query & Response; sent over UDP

WireShark DNS Lab

Embed Size (px)

Citation preview

Page 1: WireShark DNS Lab

Questions 1-3:

4) DNS Query & Response; sent over UDP

Page 2: WireShark DNS Lab

5) Destination port for DNS Query message is 53; Source port of DNS Response message is 53.

6) DNS Query message is sent to 192.168.1.254; yes, it’s the same as my local DNS server.

7) It’s a Type A DNS Query; no, it does not contain any answers.

Page 3: WireShark DNS Lab

8) 1 answer; this is what it contains:

9) Yes, the destination IP of the subsequent TCP SYN packet sent by my host is 12.22.58.30, which is the IP address of www.ietf.org provided in the DNS response message.

10) No, my host does not issue new DNS queries before retrieving each image.

11) The destination port for the DNS query message is 53; the source port of the DNS response message is 53.

12) The DNS query message is sent to 192.168.1.254; yes, it’s the IP my local DNS server.

13) It’s a Type AAAA DNS query; no, it does not contain any answers.

14) 2 answers are provided; this is what they contain:

Page 4: WireShark DNS Lab

15)

Page 5: WireShark DNS Lab

16) The DNS query message is sent to 192.168.1.254; yes, it’s the IP my local DNS server.

17) It is a type NS DNS query; no, it doesn’t contain any answers

18) The DNS response message provides the following MIT nameservers:

STRAWB.mit.edu, W20NS.mit.edu, and BITSY.mit.edu

No, the response message does not also provide the IP addresses of the MIT nameservers

Page 6: WireShark DNS Lab

19)

Page 7: WireShark DNS Lab

20) The DNS query message is sent to 18.72.0.3; corresponds to the IP of BITSY.mit.edu.

21) It is a Type AAAA DNS query; does not contain any answers.

22) The DNS response message does not contain any answers.

Page 8: WireShark DNS Lab

23)