I can see different packages on my firewall:
192.168.70.250 is my mailcow dockerized host host
192.168.89.10 is my internal DNS server
tcpdump -ni igc0.10 port 53 and src or dst 192.168.70.250
======= no answer from the external servers ==============
14:02:29.907240 IP 192.168.70.250.48835 > 192.203.230.10.53: 63600% [1au] NS? . (28)
14:02:30.660538 IP 192.168.70.250.62572 > 192.203.230.10.53: 31860% [1au] NS? . (28)
14:02:34.426525 IP 192.168.70.250.22435 > 198.97.190.53.53: 61323% [1au] NS? . (28)
14:02:35.179706 IP 192.168.70.250.44438 > 198.97.190.53.53: 33745% [1au] NS? . (28)
14:02:36.687445 IP 192.168.70.250.28075 > 170.247.170.2.53: 65094% [1au] NS? . (28)
14:02:37.440559 IP 192.168.70.250.65089 > 170.247.170.2.53: 52982% [1au] NS? . (28)
14:02:42.714327 IP 192.168.70.250.43985 > 192.5.5.241.53: 25941% [1au] NS? . (28)
14:02:43.467583 IP 192.168.70.250.21064 > 192.5.5.241.53: 8375% [1au] NS? . (28)
14:02:50.246415 IP 192.168.70.250.60779 > 192.5.5.241.53: 17457% [1au] NS? . (28)
14:02:51.751340 IP 192.168.70.250.28204 > 192.5.5.241.53: 2973% [1au] NS? . (28)
14:02:53.257525 IP 192.168.70.250.61425 > 199.7.83.42.53: 26413% [1au] NS? . (28)
====== the internal server answers ==========
14:02:53.848946 IP 192.168.70.250.58687 > 192.168.89.10.53: 7394+ [1au] AAAA? bazaar.abuse.ch. (44)
14:02:53.849390 IP 192.168.70.250.35524 > 192.168.89.10.53: 26113+ [1au] A? bazaar.abuse.ch. (44)
14:02:53.879490 IP 192.168.89.10.53 > 192.168.70.250.58687: 7394 1/1/1 CNAME p2.shared.global.fastly.net. (156)
14:02:53.880268 IP 192.168.89.10.53 > 192.168.70.250.35524: 26113 2/0/1 CNAME p2.shared.global.fastly.net., A 146.75.118.49 (101)
when I send a request to the external servers I can see an answer:
dig www.heise.de @192.33.4.12
tcpdump:
14:07:44.182651 IP 192.168.70.250.52271 > 192.33.4.12.53: 41983+ [1au] A? www.heise.de. (53)
14:07:44.275878 IP 192.33.4.12.53 > 192.168.70.250.52271: 41983- 0/6/13 (443)
nope:
docker-compose logs unbound-mailcow
mailcowdockerized-unbound-mailcow-1 | Setting console permissions…
mailcowdockerized-unbound-mailcow-1 | Receiving anchor key…
mailcowdockerized-unbound-mailcow-1 | Receiving root hints…
######################################################################## 100.0%
mailcowdockerized-unbound-mailcow-1 | setup in directory /etc/unbound
mailcowdockerized-unbound-mailcow-1 | Certificate request self-signature ok
mailcowdockerized-unbound-mailcow-1 | subject=CN = unbound-control
mailcowdockerized-unbound-mailcow-1 | removing artifacts
mailcowdockerized-unbound-mailcow-1 | Setup success. Certificates created. Enable in unbound.conf file to use
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 0: validator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 1: iterator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] info: start of service (unbound 1.17.1).
nope:
docker-compose logs unbound-mailcow
mailcowdockerized-unbound-mailcow-1 | Setting console permissions…
mailcowdockerized-unbound-mailcow-1 | Receiving anchor key…
mailcowdockerized-unbound-mailcow-1 | Receiving root hints…
######################################################################## 100.0%
mailcowdockerized-unbound-mailcow-1 | setup in directory /etc/unbound
mailcowdockerized-unbound-mailcow-1 | Certificate request self-signature ok
mailcowdockerized-unbound-mailcow-1 | subject=CN = unbound-control
mailcowdockerized-unbound-mailcow-1 | removing artifacts
mailcowdockerized-unbound-mailcow-1 | Setup success. Certificates created. Enable in unbound.conf file to use
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 0: validator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 1: iterator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] info: start of service (unbound 1.17.1).
nope:
docker-compose logs unbound-mailcow
mailcowdockerized-unbound-mailcow-1 | Setting console permissions…
mailcowdockerized-unbound-mailcow-1 | Receiving anchor key…
mailcowdockerized-unbound-mailcow-1 | Receiving root hints…
######################################################################## 100.0%
mailcowdockerized-unbound-mailcow-1 | setup in directory /etc/unbound
mailcowdockerized-unbound-mailcow-1 | Certificate request self-signature ok
mailcowdockerized-unbound-mailcow-1 | subject=CN = unbound-control
mailcowdockerized-unbound-mailcow-1 | removing artifacts
mailcowdockerized-unbound-mailcow-1 | Setup success. Certificates created. Enable in unbound.conf file to use
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 0: validator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 1: iterator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] info: start of service (unbound 1.17.1).
nope:
docker-compose logs unbound-mailcow
mailcowdockerized-unbound-mailcow-1 | Setting console permissions…
mailcowdockerized-unbound-mailcow-1 | Receiving anchor key…
mailcowdockerized-unbound-mailcow-1 | Receiving root hints…
######################################################################## 100.0%
mailcowdockerized-unbound-mailcow-1 | setup in directory /etc/unbound
mailcowdockerized-unbound-mailcow-1 | Certificate request self-signature ok
mailcowdockerized-unbound-mailcow-1 | subject=CN = unbound-control
mailcowdockerized-unbound-mailcow-1 | removing artifacts
mailcowdockerized-unbound-mailcow-1 | Setup success. Certificates created. Enable in unbound.conf file to use
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 0: validator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 1: iterator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] info: start of service (unbound 1.17.1).
nope:
docker-compose logs unbound-mailcow
mailcowdockerized-unbound-mailcow-1 | Setting console permissions…
mailcowdockerized-unbound-mailcow-1 | Receiving anchor key…
mailcowdockerized-unbound-mailcow-1 | Receiving root hints…
######################################################################## 100.0%
mailcowdockerized-unbound-mailcow-1 | setup in directory /etc/unbound
mailcowdockerized-unbound-mailcow-1 | Certificate request self-signature ok
mailcowdockerized-unbound-mailcow-1 | subject=CN = unbound-control
mailcowdockerized-unbound-mailcow-1 | removing artifacts
mailcowdockerized-unbound-mailcow-1 | Setup success. Certificates created. Enable in unbound.conf file to use
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 0: validator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 1: iterator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] info: start of service (unbound 1.17.1).
Nothing I identify as error:
docker-compose logs unbound-mailcow
mailcowdockerized-unbound-mailcow-1 | Setting console permissions…
mailcowdockerized-unbound-mailcow-1 | Receiving anchor key…
mailcowdockerized-unbound-mailcow-1 | Receiving root hints…
######################################################################## 100.0%
mailcowdockerized-unbound-mailcow-1 | setup in directory /etc/unbound
mailcowdockerized-unbound-mailcow-1 | Certificate request self-signature ok
mailcowdockerized-unbound-mailcow-1 | subject=CN = unbound-control
mailcowdockerized-unbound-mailcow-1 | removing artifacts
mailcowdockerized-unbound-mailcow-1 | Setup success. Certificates created. Enable in unbound.conf file to use
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 0: validator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 1: iterator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] info: start of service (unbound 1.17.1).
Nothing I identify as error:
docker-compose logs unbound-mailcow
mailcowdockerized-unbound-mailcow-1 | Setting console permissions...
mailcowdockerized-unbound-mailcow-1 | Receiving anchor key...
mailcowdockerized-unbound-mailcow-1 | Receiving root hints...
######################################################################## 100.0%
mailcowdockerized-unbound-mailcow-1 | setup in directory /etc/unbound
mailcowdockerized-unbound-mailcow-1 | Certificate request self-signature ok
mailcowdockerized-unbound-mailcow-1 | subject=CN = unbound-control
mailcowdockerized-unbound-mailcow-1 | removing artifacts
mailcowdockerized-unbound-mailcow-1 | Setup success. Certificates created. Enable in unbound.conf file to use
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 0: validator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] notice: init module 1: iterator
mailcowdockerized-unbound-mailcow-1 | [1708524103] unbound[1:0] info: start of service (unbound 1.17.1).
[unknown]
uuups —- sorry for the multiple inserts