tcpdump dns output codes
Posted
by
tim
on Server Fault
See other posts from Server Fault
or by tim
Published on 2012-06-18T20:25:34Z
Indexed on
2012/06/18
21:18 UTC
Read the original article
Hit count: 250
Captured on the nameserver:
21:54:35.391126 IP resolver.7538 > server.domain: 57385% [1au] A? www.domain.de. (42)
What das the percent sign in 57385% mean? As far as I can see 57385 is the clients sequence number, a plus would mean RD bit set.
Second question: what does the ARCOUNT do in the query? As I understand the tcpdump man page the [1au] means tcpdump treats this as a protocol anomalie - as would I. I see this in a lot of queries.
© Server Fault or respective owner