Hallo Community
Leider konnte mir der Tel-Support nicht helfen. Wie DNS funktioniert ist dort nicht bekannt.
Das Phänomen ist, dass ich im Browser grundsätzlich surfen kann, also z.B. google, DuckDuckGo, etc. kann aufgerufen werden, auch die präsentierten URLs können verwendet werden. Mit der URL postfinance.ch haben wir Probleme.
Technisch ist der Aufbau so, dass hinter der weissen UPC Box ein Router aufgebaut ist, auf dem unbound läuft, der die beiden Nameserver
62.2.24.158 ns4.cablecom.net
62.2.17.61 ns11.cablecom.net
eingetragen hat. Diese beiden Server wurden irgendwann mal zugewiesen und seit dem verwende ich die. Cablecom scheint also eine ganze Reihe von Servern zu haben, was ich verstehe.
Im Log vom unbound steht:
14:38:46 unbound: [1684:0] info: start of service (unbound 1.19.3).
14:38:47 unbound: [1684:0] info: generate keytag query _ta-4a5c-4f66. NULL IN
14:38:49 unbound: [1684:0] error: SERVFAIL <browser.events.data.msn.com. A IN>: all the configured stub or forward servers failed, at zone . upstream server timeout
14:38:49 unbound: [1684:0] error: SERVFAIL <r.msftstatic.com. A IN>: all the configured stub or forward servers failed, at zone . upstream server timeout
14:38:49 unbound: [1684:0] error: SERVFAIL <r.bing.com. A IN>: all the configured stub or forward servers failed, at zone . upstream server timeout
14:38:49 unbound: [1684:0] error: SERVFAIL <img-s-msn-com.akamaized.net. A IN>: all the configured stub or forward servers failed, at zone . from 192.168.0.1 upstream server timeout
14:38:49 unbound: [1684:0] error: SERVFAIL <www.bing.com. A IN>: all the configured stub or forward servers failed, at zone . from 192.168.0.1 upstream server timeout
14:38:50 unbound: [1684:0] error: SERVFAIL <srtb.msn.com. A IN>: all the configured stub or forward servers failed, at zone . from 192.168.0.1 upstream server timeout
14:38:50 unbound: [1684:0] error: SERVFAIL <edge.microsoft.com. A IN>: all the configured stub or forward servers failed, at zone . from 192.168.0.1 upstream server timeout
14:38:52 unbound: [1684:0] error: SERVFAIL <bzib.nelreports.net. A IN>: all the configured stub or forward servers failed, at zone . upstream server timeout
14:39:03 unbound: [1684:0] error: SERVFAIL <deff.nelreports.net. A IN>: all the configured stub or forward servers failed, at zone . from 192.168.0.1 upstream server timeout
14:39:04 unbound: [1684:0] error: SERVFAIL <c.bing.com. A IN>: all the configured stub or forward servers failed, at zone . upstream server timeout
14:39:04 unbound: [1684:0] error: SERVFAIL <api.msn.com. A IN>: all the configured stub or forward servers failed, at zone . upstream server timeout
14:39:05 unbound: [1684:0] error: SERVFAIL <c.msn.com. A IN>: all the configured stub or forward servers failed, at zone . from 192.168.0.1 upstream server timeout
14:39:40 unbound: [1684:0] error: SERVFAIL <images.archive-digger.com. A IN>: all the configured stub or forward servers failed, at zone . upstream server timeout
14:39:41 unbound: [1684:0] error: SERVFAIL <shftr.adnxs.net. A IN>: all the configured stub or forward servers failed, at zone . upstream server timeout
14:40:04 unbound: [1684:0] info: validation failure <postfinance.ch. A IN>: No DNSKEY record for key postfinance.ch. while building chain of trust
14:40:04 unbound: [1684:0] info: validation failure <www.postfinance.ch. AAAA IN>: No DNSKEY record for key postfinance.ch. while building chain of trust
14:40:04 unbound: [1684:0] info: validation failure <postfinance.ch. AAAA IN>: No DNSKEY record for key postfinance.ch. while building chain of trust
14:40:04 unbound: [1684:0] info: validation failure <www.postfinance.ch. A IN>: No DNSKEY record for key postfinance.ch. while building chain of trust
14:40:48 unbound: [1684:0] info: validation failure <postfinance.ch. A IN>: key for validation postfinance.ch. is marked as invalid because of a previous
14:42:41 unbound: [1684:0] info: validation failure <postfinance.ch. A IN>: No DNSKEY record for key postfinance.ch. while building chain of trust
14:42:41 unbound: [1684:0] info: validation failure <postfinance.ch. AAAA IN>: No DNSKEY record for key postfinance.ch. while building chain of trust
14:43:08 unbound: [1684:0] info: validation failure <postfinance.ch. A IN>: key for validation postfinance.ch. is marked as invalid because of a previous
14:43:08 unbound: [1684:0] info: validation failure <postfinance.ch. AAAA IN>: key for validation postfinance.ch. is marked as invalid because of a previous
14:43:08 unbound: [1684:0] info: validation failure <postfinance.ch. A IN>: key for validation postfinance.ch. is marked as invalid because of a previous
14:43:08 unbound: [1684:0] info: validation failure <postfinance.ch. AAAA IN>: key for validation postfinance.ch. is marked as invalid because of a previous
14:43:39 unbound: [1684:0] info: validation failure <www.postfinance.ch. A IN>: No DNSKEY record for key postfinance.ch. while building chain of trust
Ein restart des unbound auf dem Router löst das Problem temporär. Es sieht aber für mich danach aus, als ob es Errors gibt (Servfail), die von der Box nicht korrekt beantwortet werden, woraufhin die chain of trust zu postfinance.ch nicht aufgebaut werden kann.
Warum?
Was kann ich dagegen tun?
Danke!