Instant On - Wireless

 View Only
Expand all | Collapse all

AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

  • 1.  AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 11-05-2021 11:11 AM
    Greetings,

    I'm a new Instant On user, about 2 months now. I have 1930 Switch and 5 AP12s (only ones offered locally where I am). Two days ago the APs update to Version 2.4.0 and since then my DNS flooded with PTR lookups from each of APs attempting reverse lookups of the other APs and only the other APs. Each AP is performing about 65,000 xxx.xxx.xxx.xxxin-addr.arpa PTR requests a day the reverse IPs are the other APs.

    This was not happening before for the update to 2.4.0, is anyone seeing this activity, or does anyone have any suggestions on how to stop it?

    Thanks much

    ------------------------------
    Dave TB
    ------------------------------


  • 2.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 11-05-2021 11:31 AM
    I've definitely noticed that as well. Haven't been able to determine if it's causing any issues per se but I'd definitely be curious as to why the change was made and what, if any, benefit it provides.

    PTR Lookups



  • 3.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Employee
    Posted 11-05-2021 01:10 PM
    Hi Dave,

    We appreciate you for making us aware of this, and we are working with our teams internally to find out more about this issue. We will update this thread when we have more information. Thank you for your patience.

    ------------------------------
    Aruba Instant On Communications
    ------------------------------



  • 4.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 11-06-2021 05:39 AM
    Thanks for the update.
    They also seem to call out directly to Quad9 as if they have it as a shared coded DNS server.  Every morning I'm reset the APs DNS counts so I find other events before they fill up my logs again. 
    Quad9



    ------------------------------
    Dave TB
    ------------------------------



  • 5.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 12-26-2021 12:01 PM
    Where is that menu ? Cant seem finding it. Do you manage them locally?

    ------------------------------
    Jim tsoutsouras
    ------------------------------



  • 6.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 11-17-2021 09:10 AM
    Any updates, my DNS is pushing 1.6 million PRT looks from the APs. This getting a bit out of hand at this point.

    ------------------------------
    Dave TB
    ------------------------------



  • 7.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 11-08-2021 01:46 AM
    Mine are doing this too. It seems like every 10 seconds they look up themselves, then in the interval, they look up their neighbours.

    Without blocking stuff at the router, I can't tell if they are trying anyone else's DNS (e.g. that DoH security nightmare) 
    Over about 15 hours:
    AP11D 1,2,3 and AP12 did about 22000 lookups each, about 5500 of each neighbour (and self)

    A quick fiddle suggests that this represents a doubling of PTR queries.

    grafana



    ------------------------------
    Still can't change my name from FL17!
    ------------------------------



  • 8.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 12-11-2021 08:01 AM
    What you can see here is the noise the APs generate with NO OTHER TRAFFIC WHAT SO EVER.
    It's a good thing the ISDN 2B+D era is almost over because that would be unusable. 

    This is about 94 kbit/s of noise to the APs and 28 from them. You can see where the other floors were powered down.

    I look forward to an explanation of this "feature" and why the APs need to know the name of every neighbour, every 10 seconds. 
    (I'm not sure if the 1930's are doing this too.)



    ------------------------------
    Still can't change my name from FL17!
    ------------------------------



  • 9.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Employee
    Posted 12-15-2021 03:44 PM
    Hey FL17, 

    We're working to provide a solution for this concern and will keep the community updated once we've done so.

    ------------------------------
    Aruba Instant On Communications
    ------------------------------



  • 10.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 11-08-2021 11:46 AM
    On my AP22 after 2.40, I'm getting extreme lag in FPS gaming (200ms ping). Anyone else get same? This is with CH36 and WiFi 6 unchecked and AP rebooted. Will try different 5ghz channels


  • 11.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 12-16-2021 09:54 AM
    Any change to check if this is also caused from the 1930 switch as well?
    Can you direct me on which menu to check that too?

    Thank you

    ------------------------------
    Jim tsoutsouras
    ------------------------------



  • 12.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 12-28-2021 10:20 PM
    The quickest way to do that is to point your 1930 at your own dns server and log it. That's how I can produce the graph above.
    The site with the 1930's does not have a local DNS server and is using CF (automatic). It's also in production as the owner moved in so I can't touch it and the router can't differentiate at all. (rtx1220 if you were wondering.)

    If the 8 port toy had a 10G uplink, I'd have to rethink. ^^;

    ------------------------------
    Still can't change my name from FL17!
    ------------------------------



  • 13.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 12-29-2021 03:46 AM
    The only configuration page (local management) is at Setup Network -> Get Connected and there you can set a static ip / subnet and gateway. So I don t get what you mean by pointing the 1930 to my dns server.
        By the way, what is the point of the switch having a gateway access, to search for firm updates?
    What is CF that  you mention the switch is using?

    ------------------------------
    Jim tsoutsouras
    ------------------------------



  • 14.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 12-30-2021 07:27 AM
    CF is CloudFlare or 1.1.1.1 which is hardcoded DNS in the ION range


  • 15.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 12-30-2021 08:48 AM
    Oh ok. I know CloudFlare of course but not it's abbreviation. Thousands of them nowadays, cant keep track. So since this D.N.S is hardcoded, how am I supposed to point the switch's dns to a custom one as FL17 user mentioned? I don t see the field to change that option.

    ------------------------------
    Jim tsoutsouras
    ------------------------------



  • 16.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Employee
    Posted 01-05-2022 05:27 PM
    Hey Jim,

    Our apologies for the delayed response but page 42 of the user guide will assist you with your concerns: https://community.arubainstanton.com/HigherLogic/System/DownloadDocumentFile.ashx?DocumentFileKey=3195c0b6-5079-5cf6-8e6a-f53814a84b72&forceDialog=0 

    ------------------------------
    Aruba Instant On Communications
    ------------------------------



  • 17.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Posted 01-05-2022 07:19 PM
    You do realize that I have mentioned a couple of times that I manage the switches locally and not on cloud right? 
    The options page 42 (DNS) presents, are for cloud based management. So what exactly to see there?

    ------------------------------
    Jim tsoutsouras
    ------------------------------



  • 18.  RE: AP12's perfroming tens of thousands PTR lookups a day after 2.4.0 update

    Employee
    Posted 01-07-2022 01:00 PM
    Hi Jim,

    It's not supported in local mode.

    ------------------------------
    Aruba Instant On Communications
    ------------------------------