Deco M4R overriding DNS results

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Deco M4R overriding DNS results

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Deco M4R overriding DNS results
Deco M4R overriding DNS results
2020-12-20 03:40:55
Model: Deco M4  
Hardware Version: V2
Firmware Version: 1.4.3 Build 20200918 Rel. 74289

Something very strange is happening with DNS when using Deco M4R network. 

 

Using dig connected directly to the my isp router ( bypassing Deco M4 ) I get:

 

dig www.youtube.com @8.8.8.8

; <<>> DiG 9.10.6 <<>> www.youtube.com @8.8.8.8
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 3121
;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;www.youtube.com.        IN    A

;; ANSWER SECTION:
www.youtube.com.    16471    IN    CNAME    youtube-ui.l.google.com.
youtube-ui.l.google.com. 153    IN    A    216.58.211.46
youtube-ui.l.google.com. 153    IN    A    216.58.201.174
youtube-ui.l.google.com. 153    IN    A    216.58.215.142
youtube-ui.l.google.com. 153    IN    A    172.217.17.14
youtube-ui.l.google.com. 153    IN    A    172.217.168.174
youtube-ui.l.google.com. 153    IN    A    216.58.211.238

;; Query time: 27 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Sun Dec 20 03:22:35 WET 2020
;; MSG SIZE  rcvd: 174

 

So it is giving the correct response with multiple ips.

 

While using the Deco M4 I get a response for 10.0.0.2 even if I am forcing the name server to be 8.8.8.8

 

I took a tcpdump and here is what I see: 

 

 

I don't understand why would the DNS response from the Deco M4, intercept the requests I am making directly to 8.8.8.8 and add its response. 

I believe this might be a problem with dnsproxy?  

 

You can see from the tcpdump that the the request is going to the Deco M4 ( 3c:84:6a:97:42:94 ). 

 

This is screwing up all of my traffic, since it is messing up random domains with incorrect ips. 10.0.0.x is not any valid network that I own. 

 

Can anyone please explain what is going on in here?

  0      
  0      
#1
Options
6 Reply
Re:Deco M4R overriding DNS results
2020-12-21 09:23:00

@fboleto 

Hi,

Sorry for the delay.

Could you please help me check the following details:

1. The Deco M4 is on the access point mode, right?

2.Could you please draw a detailed network map from the internet service provider to Deco units?

 

Thank you very much.

 

  0  
  0  
#2
Options
Re:Deco M4R overriding DNS results
2020-12-22 13:40:17

@TP-Link 

 

I am using Router mode, since we want to use the QOS etc

 

Here it is the diagram:

 

 

Is this not related to a process that runs on your router called dnsproxy?

 

 

  0  
  0  
#3
Options
Re:Deco M4R overriding DNS results
2020-12-28 11:42:43

@fboleto 

Good day,

Thank you very much for your detailed information.

Based on your network map, it seems like there are two routers and both of them could resolve the DNS request.

If possible, could you please change the IPv4 DNS server on the Deco M4 to be 8.8.8.8/8.8.4.4;

(it is under More>advanced>IPV4>internet connection type>primary DNS/secondary DNS)

Thanks a lot for your cooperation and wait for your reply.

  0  
  0  
#4
Options
Re:Deco M4R overriding DNS results
2020-12-31 01:52:40

@TP-Link 

 

This is how it was setup, the servers I had were

 

1.1.1.1

8.8.8.8

 

So I don't think this is the issue. What is the dnsproxy service doing on your devices? Does it do a MiTM for dns? 

TP-Link wrote

@fboleto 

Good day,

Thank you very much for your detailed information.

Based on your network map, it seems like there are two routers and both of them could resolve the DNS request.

If possible, could you please change the IPv4 DNS server on the Deco M4 to be 8.8.8.8/8.8.4.4;

(it is under More>advanced>IPV4>internet connection type>primary DNS/secondary DNS)

Thanks a lot for your cooperation and wait for your reply.

 

  0  
  0  
#5
Options
Re:Deco M4R overriding DNS results
2022-01-03 19:17:15

@fboleto Any update? I'm also having issues with DNS resolution using a similar setup. I actually have issues when I have the ethernet backhaul connected and not when using just WIFI.

  2  
  2  
#6
Options
Re:Deco M4R overriding DNS results
2022-01-04 09:00:58

@PLG 

Hi, thank you very much for bringing it back.

I am afraid this issue has not been addressed yet.

Could you please send an email to support.forum@tp-link.com with the following information:

1. A picture of your network setup.

2. A screenshot of your DNS settings on the Deco APP.

3. A detailed description of your findings with DNS resolution.-Some pictures would be highly appreciated.

  0  
  0  
#7
Options