Archer C7 AC1750 Does not work with Large DNS Responses (Mac)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Archer C7 AC1750 Does not work with Large DNS Responses (Mac)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Archer C7 AC1750 Does not work with Large DNS Responses (Mac)
Archer C7 AC1750 Does not work with Large DNS Responses (Mac)
2017-11-18 02:51:13
Model :

Hardware Version :

Firmware Version :

ISP :

For DNS queries that are too large for UDP (over 512 bytes), TCP is used ( https://tools.ietf.org/html/rfc5966). In my case, this happens with login.windows.net, but I'm sure there are plenty of others. The C7 does not run a DNS server that is open to TCP traffic, so the DNS queries that result in large responses fail, causing an unresolvable hostname.

As a workaround, I changed my dhcp settings to provide my ISPs dns servers to each all of my dhcp clients. This bypasses the DNS server on the router. While not ideal, it works for the time being.

Is there any way to set up the C7 so it listens for DNS traffic via TCP? If not, sounds like a bug as it's not following the DNS spec.
  0      
  0      
#1
Options
4 Reply
Re:Archer C7 AC1750 Does not work with Large DNS Responses (Mac)
2017-11-18 19:02:59
Hi,

On the router's management page, you can go to Network---DHCP--DHCP Settings, then change the Primary DNS to your ISPs DNS server or 8.8.8.8, then Save and Reboot the router.
  0  
  0  
#2
Options
Re:Archer C7 AC1750 Does not work with Large DNS Responses (Mac)
2017-11-19 05:52:03
That is the workaround I am currently using, although not ideal to me. What I've found appears to be a bug with the router firmware itself. The router should respond to DNS requests via both TCP and UDP on port 53, but it only responds to UDP requests.

Below are the outputs from running nmap against port 53 on the router, once checking TCP and the other checking UDP.


....
PORT STATE SERVICE
53/udp open domain
....



....
PORT STATE SERVICE
53/tcp closed domain
...
  0  
  0  
#3
Options
Re:Archer C7 AC1750 Does not work with Large DNS Responses (Mac)
2017-11-22 09:20:50
Yes, change the DNS on the client devices seems to be the solution.
  0  
  0  
#4
Options
Re:Archer C7 AC1750 Does not work with Large DNS Responses (Mac)
2017-11-24 10:20:32
I am also in need
I am also in need
  0  
  0  
#5
Options

Information

Helpful: 0

Views: 512

Replies: 4