众所周知,作DNS区域传输时会用到TCP:53
其实作域名查询时也可能会用到TCP进行查询。
当A记录为28条时,直接查询该A记录,仍使用UDP;若使用别名查询,就开始用TCP了
例如:
www IN CNAME server2
server2 IN A 192.168.1.20
server2 IN A 192.168.1.21
server2 IN A 192.168.1.22
server2 IN A 192.168.1.23
server2 IN A 192.168.1.24
server2 IN A 192.168.1.25
server2 IN A 192.168.1.26
server2 IN A 192.168.1.27
server2 IN A 192.168.1.28
server2 IN A 192.168.1.29
server2 IN A 192.168.1.30
server2 IN A 192.168.1.31
server2 IN A 192.168.1.32
server2 IN A 192.168.1.33
server2 IN A 192.168.1.34
server2 IN A 192.168.1.35
server2 IN A 192.168.1.36
server2 IN A 192.168.1.37
server2 IN A 192.168.1.38
server2 IN A 192.168.1.39
server2 IN A 192.168.1.40
server2 IN A 192.168.1.41
server2 IN A 192.168.1.42
server2 IN A 192.168.1.43
server2 IN A 192.168.1.44
server2 IN A 192.168.1.45
server2 IN A 192.168.1.46
server2 IN A 192.168.1.47
直接nslookup查询server2.oi.com会使用UDP
IP 192.168.1.26.1354 > 192.168.1.253.domain: 65+ A? server2.oi.com. (32)
IP 192.168.1.253.domain > 192.168.1.26.1354: 65* 28/1/0 A 192.168.1.42,[|domain]
如果查就会建TCP了
IP 192.168.1.26.1352 > 192.168.1.253.domain: 64+ A? . (28)
IP 192.168.1.253.domain > 192.168.1.26.1352: 64*| 29/0/0 CNAME server2.oi.com.,[|domain]
IP 192.168.1.26.1353 > 192.168.1.253.domain: S 628797928:628797928(0) win 65535
IP 192.168.1.253.domain > 192.168.1.26.1353: S 1611126570:1611126570(0) ack 628797929 win 5840
IP 192.168.1.26.1353 > 192.168.1.253.domain: . ack 1 win 65535
IP 192.168.1.26.1353 > 192.168.1.253.domain: P 1:3(2) ack 1 win 65535
IP 192.168.1.253.domain > 192.168.1.26.1353: . ack 3 win 5840
IP 192.168.1.26.1353 > 192.168.1.253.domain: P 3:31(28) ack 1 win 65535 256 [b2&3=0x1] [0q] [887au] (26)
IP 192.168.1.253.domain > 192.168.1.26.1353: . ack 31 win 5840
IP 192.168.1.253.domain > 192.168.1.26.1353: P 1:537(536) ack 31 win 5840 64* 29/1/1 CNAME[|domain]
IP 192.168.1.26.1353 > 192.168.1.253.domain: F 31:31(0) ack 537 win 64999
IP 192.168.1.253.domain > 192.168.1.26.1353: F 537:537(0) ack 32 win 5840
IP 192.168.1.26.1353 > 192.168.1.253.domain: . ack 538 win 64999
阅读(878) | 评论(0) | 转发(0) |