tcpdump dns output codes

Posted by tim on Server Fault See other posts from Server Fault or by tim
Published on 2012-06-18T20:25:34Z Indexed on 2012/06/18 21:18 UTC
Read the original article Hit count: 254

Filed under:
|

Captured on the nameserver:

21:54:35.391126 IP resolver.7538 > server.domain: 57385% [1au] A? www.domain.de. (42)

What das the percent sign in 57385% mean? As far as I can see 57385 is the clients sequence number, a plus would mean RD bit set.

Second question: what does the ARCOUNT do in the query? As I understand the tcpdump man page the [1au] means tcpdump treats this as a protocol anomalie - as would I. I see this in a lot of queries.

© Server Fault or respective owner

Related posts about dns

Related posts about tcpdump