Lab 04
- 1. Lab 04
Name : Om Rakesh Thakkar
Roll No. : 201501109
Subject : Computer Networks
Batch : 1
Topic : Wireshark
Q.1) Run nslookup to obtain the IP address of a Web server in
Asia.
nslookup has been performed for “www.paytm.com”.
- 2. Q.2) Run nslookup to determine the authoritative DNS servers
for a university in Europe.
nslookup has been performed on Oxford University situated in
Europe.
- 3. Q.3) Run nslookup so that one of the DNS servers obtained in
Question 2 is queried for the mail servers for Yahoo! Mail.
Connection is timed out and no servers are reached.
Q.4) Locate the DNS query and response messages. Are they sent
over UDP or TCP?
DNS Queries and Response Messages have been located. They are
sent over UDP.
DNS Query
- 4. DNS Response
Q.5) What is the destination port for the DNS query message?
What is the source port of DNS response message?
The Destination Port for DNS Query is 53 and Source Port of DNS
Response is 53.
DNS Query
- 5. DNS Response
Q.6) To what IP address is the DNS query message sent? Use
ipconfig to determine the IP address of your local DNS server.
Are these two IP addresses the same?
The DNS Query message has been sent to 208.67.222.222, which is
the IP Address of one of my local DNS Servers as shown in the
image.
- 6. Q.7) Examine the DNS query message. What “Type” of DNS
query is it? Does the query message contain any “answers”?
It is a type A Standard Query and it doesn’t contain any answers.
Q.8) Examine the DNS response message. How many “answers”
are provided? What do each of these answers contain?
There are 2 answers provided in the DNS Response Message. They
contain information about the Name of host, Type of address, Class,
Time to Live, Data Length, IP Address.
- 7. Q.9) Consider the subsequent TCP SYN packet sent by your host.
Does the destination IP address of the SYN packet correspond to
any of the IP addresses provided in the DNS response message?
The first SYN packet was sent to 104.20.0.85 which corresponds to
the first IP address provided in the DNS response message.
Q.10) This web page contains images. Before retrieving each
image, does your host issue new DNS queries?
No, the host issues DNS Queries after retrieving the image.
- 8. ● nslookup www.mit.edu
Q.11) What is the destination port for the DNS query message?
What is the source port of DNS response message?
Destination port of DNS Query message is 53 and Source Port of
DNS Response message is 53.
DNS Query
- 9. DNS Response
Q.12) To what IP address is the DNS query message sent? Is this
the IP address of your default local DNS server?
It’s sent to 208.67.222.222 which is the IP Address of one of my local
DNS Servers as shown in the image.
Q.13) Examine the DNS query message. What “Type” of DNS
query is it? Does the query message contain any “answers”?
The Query is Type A and the query message contains no answers.
- 10. Q.14) Examine the DNS response message. How many “answers”
are provided? What do each of these answers contain?
The DNS Response message contains 3 answers as shown below. It
contains Name of host, type of address, Class, TTL, Data Length and
CName.
- 11. ● nslookup –type=NS mit.edu
Q.16) To what IP address is the DNS query message sent? Is this
the IP address of your default local DNS server?
It is sent to 208.67.222.222 which is one of my local DNS Servers.
Q.17) Examine the DNS query message. What “Type” of DNS
query is it? Does the query message contain any “answers”?
It is NS Type DNS Query Message and contains no answers.
- 12. Q.18) Examine the DNS response message. What MIT
nameservers does the response message provide? Does this
response message also provide the IP addresses of the MIT
nameservers?
The nameservers are usw2, ns1-173, ns1-37, asia1, use2, use5, eur5,
asia2. We can find their IP addresses if we expand the Additional
records field in Ethereal as shown in the image below.
- 13. ● nslookup www.aiit.or.kr bitsy.mit.edu
Q.20) To what IP address is the DNS query message sent? Is this
the IP address of your default local DNS server? If not, what does
the IP address correspond to?
The DNS Query is sent to 18.72.0.3 which corresponds to
bitsy.mit.edu.
- 14. Q.21) Examine the DNS query message. What “Type” of DNS
query is it? Does the query message contain any “answers”?
It is a standard Type A DNS Query and contains no answers.
Q.22) Examine the DNS response message. How many “answers”
are provided? What does each of these answers contain?
The DNS Response message contains one answer as follows :