Social Icons

Pages

Showing posts with label Custom Domains Diagnoses Not Acceptable. Show all posts
Showing posts with label Custom Domains Diagnoses Not Acceptable. Show all posts

Friday, 1 March 2013

eNom Hosted Custom Domains Again Showing Intermittent Connectivity Issues

This week, we have a few reports in Blogger Help Forum: Something Is Broken, about active and mature domains, suddenly stopped working.
I have used my domain with no problems, since last year. Today, it suddenly stopped working, and the browser reports
Oops! Google Chrome could not find www.mydomain.com.
I asked my friends about my domain - and they tell me that my blog is inaccessible to them, also. I didn't change any settings - and it was fine, until last night.

As we reported last year, the Google partner registrar eNom occasionally has a problem with their DNS server complement. Right now, one of their DNS servers appears consistently bad.

Using a comprehensive Dig tool, we can observe a given domain, and compare the DNS addresses being served by all authoritative name servers for a given domain, in a single transaction.

Here's a hypothetical example, of what we're seeing right now, for several eNom hosted domains.

mycustomdomain.com@dns1.name-services.com.:

mycustomdomain.com. 1800 IN A 216.239.36.21
mycustomdomain.com. 1800 IN A 216.239.34.21
mycustomdomain.com. 1800 IN A 216.239.38.21
mycustomdomain.com. 1800 IN A 216.239.32.21

mycustomdomain.com@dns2.name-services.com.:

mycustomdomain.com. 1800 IN A 216.239.36.21
mycustomdomain.com. 1800 IN A 216.239.34.21
mycustomdomain.com. 1800 IN A 216.239.32.21
mycustomdomain.com. 1800 IN A 216.239.38.21

mycustomdomain.com@dns3.name-services.com.:

mycustomdomain.com. 1800 IN A 216.239.36.21
mycustomdomain.com. 1800 IN A 216.239.32.21
mycustomdomain.com. 1800 IN A 216.239.34.21
mycustomdomain.com. 1800 IN A 216.239.38.21

mycustomdomain.com@dns4.name-services.com.:

mycustomdomain.com. 1800 IN A 216.239.36.21
mycustomdomain.com. 1800 IN A 216.239.34.21
mycustomdomain.com. 1800 IN A 216.239.32.21
mycustomdomain.com. 1800 IN A 216.239.38.21

mycustomdomain.com@dns5.name-services.com.:

org. 3601 IN
SOA dns1.name-services.com. info.name-services.com. 2010 10800 3600 604800 3600


www.mycustomdomain.com@dns1.name-services.com.:

www.mycustomdomain.com. 1800 IN CNAME ghs.google.com.

www.mycustomdomain.com@dns2.name-services.com.:

www.mycustomdomain.com. 1800 IN CNAME ghs.google.com.

www.mycustomdomain.com@dns3.name-services.com.:

www.mycustomdomain.com. 1800 IN CNAME ghs.google.com.

www.mycustomdomain.com@dns4.name-services.com.:

www.mycustomdomain.com. 1800 IN CNAME ghs.google.com.

www.mycustomdomain.com@dns5.name-services.com.:

org. 3601 IN
SOA dns1.name-services.com. info.name-services.com. 2010 10800 3600 604800 3600
Right now, it appears that server "dns5" is consistently broken.

It's possible that this problem will affect more eNom customers, as the day progresses, cached DNS addresses expire, and readers of various eNom hosted domains request DNS addresses. I hope that eNom Customer Service can react to this problem more promptly than they have reacted to the immediately previous problem.

>> Top

Thursday, 12 July 2012

Custom Domain Publishing, And "403 Forbidden"

Next to its immediate cousin error
Another blog is already hosted at this address
I don't know of too many more frustrating Blogger error states than seeing
403 Forbidden
Most cases of "403 Forbidden", seen and discussed recently in Blogger Help Forum: Something Is Broken, have geographical affinity - and are typically transient - and apply to blogs published to "blogspot.com".

Some cases of "403 Forbidden" however, will involve custom domain publishing, where the blog owner should - but most likely will not - see
Another blog is already hosted at this address
When publishing the blog to the domain.

In some cases, when publishing a blog to an incorrectly setup custom domain, the custom domain publishing wizard will fail to detect the incorrect DNS addresses. Instead of the blog owner, seeing immediately
Another blog is already hosted at this address.
The owner will see
Your blog has been published.
Later, the blog owner - and all potential blog readers - see the secondary symptom
403 Forbidden
.




Here, we have an excellent example of the problem - diagnosis, and treatment.

Let's first look at a Dig log extract.
jubileeventure.org.uk.    86400    IN    A    94.136.40.75
www.jubileeventure.org.uk. 86400 IN A 94.136.40.75

Now, an HTTP trace extract, showing unsuccessful access to the domain.
Sending request:

GET / HTTP/1.1
Host: www.jubileeventure.org.uk
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
Referer: http://www.rexswain.com/httpview.html
Connection: close

• Finding host IP address...
• Host IP address = 94.136.40.75
• Finding TCP protocol...
• Binding to local socket...
• Connecting to host...
• Sending request...
• Waiting for response...
Receiving Header:
HTTP/1.1·403·Forbidden(CR)(LF)
The solution to this problem involves a standard misconfigured domain diagnosis (excerpted here), and requires DNS address correction.
Here's what you have:

jubileeventure.org.uk. 86400 IN A 94.136.40.75
www.jubileeventure.org.uk. 86400 IN A 94.136.40.75

Google custom domain publishing requires properly setup referrals to Google servers. "94.136.40.75" is not a Google server.

Here's what you need:

jubileeventure.org.uk. 86400 IN A 216.239.32.21
jubileeventure.org.uk. 86400 IN A 216.239.34.21
jubileeventure.org.uk. 86400 IN A 216.239.36.21
jubileeventure.org.uk. 86400 IN A 216.239.38.21
www.jubileeventure.org.uk. 86400 IN CNAME ghs.google.com.

>> Top

Monday, 2 July 2012

eNom: Fix Your DNS Servers!

For over 2 months, we've been seeing reports from blog owners who published their blogs to custom domains, with domain DNS hosted by eNom, in Blogger Help Forum: Something Is Broken.
I bought my domain name through Blogger,last week. It is being hosted by eNom. Ever since I bought it some of my followers, and sometimes myself, can't access my site. There is either a DNS search or a "Ooops, Google Chrome can't find..."

I tried contacting eNom, and they said they can see my site and that all of my settings are correct. They say it must be Google's problem.
The keyword here is "sometimes".
Ever since I bought it some of my followers, and sometimes myself, can't access my site.

A simple Dig, for the domain in question, will frequently show normal results. The usual DNS configuration, for a domain purchased using "Buy a domain", will be asymmetrical aka "Google Apps".
enomhosteddomain.com. 1800 IN A 216.239.32.21
enomhosteddomain.com. 1800 IN A 216.239.34.21
enomhosteddomain.com. 1800 IN A 216.239.36.21
enomhosteddomain.com. 1800 IN A 216.239.38.21
www.enomhosteddomain.com. 1800 IN CNAME ghs.google.com.
The problem, which not so many people appreciate, is that eNom uses multiple DNS servers, possibly geographically separated. This is normal DNS hosting technique, and guarantees redundancy if one data center goes offline.

However, for redundancy to work, all DNS servers have to be kept consistently synchronised. If we examine the 5 eNom DNS servers individually, we will frequently see discrepancies.
enomhosteddomain.com @ dns1.name-services.com.:

enomhosteddomain.com. 1800 IN A 216.239.32.21
enomhosteddomain.com. 1800 IN A 216.239.34.21
enomhosteddomain.com. 1800 IN A 216.239.36.21
enomhosteddomain.com. 1800 IN A 216.239.38.21
enomhosteddomain.com. 3600 IN NS dns1.name-services.com.
enomhosteddomain.com. 3600 IN NS dns2.name-services.com.
enomhosteddomain.com. 3600 IN NS dns3.name-services.com.
enomhosteddomain.com. 3600 IN NS dns4.name-services.com.
enomhosteddomain.com. 3600 IN NS dns5.name-services.com.

enomhosteddomain.com @ dns2.name-services.com.:

enomhosteddomain.com. 1800 IN A 216.239.34.21
enomhosteddomain.com. 1800 IN A 216.239.38.21
enomhosteddomain.com. 1800 IN A 216.239.32.21
enomhosteddomain.com. 1800 IN A 216.239.36.21

enomhosteddomain.com @ dns3.name-services.com.:

com. 3601 IN SOA dns1.name-services.com. info.name-services.com. 2010 10001 1801 604801 181

enomhosteddomain.com @ dns4.name-services.com.:

enomhosteddomain.com. 1800 IN A 216.239.32.21
enomhosteddomain.com. 1800 IN A 216.239.36.21
enomhosteddomain.com. 1800 IN A 216.239.34.21
enomhosteddomain.com. 1800 IN A 216.239.38.21

enomhosteddomain.com @ dns5.name-services.com.:

enomhosteddomain.com. 1800 IN A 216.239.32.21
enomhosteddomain.com. 1800 IN A 216.239.34.21
enomhosteddomain.com. 1800 IN A 216.239.36.21
enomhosteddomain.com. 1800 IN A 216.239.38.21
enomhosteddomain.com. 3600 IN NS dns1.name-services.com.
enomhosteddomain.com. 3600 IN NS dns2.name-services.com.
enomhosteddomain.com. 3600 IN NS dns3.name-services.com.
enomhosteddomain.com. 3600 IN NS dns4.name-services.com.
enomhosteddomain.com. 3600 IN NS dns5.name-services.com.


www.enomhosteddomain.com @ dns1.name-services.com.:

www.enomhosteddomain.com. 1800 IN CNAME ghs.google.com.

www.enomhosteddomain.com @ dns2.name-services.com.:

www.enomhosteddomain.com. 1800 IN CNAME ghs.google.com.

www.enomhosteddomain.com @ dns3.name-services.com.:

com. 3601 IN SOA dns1.name-services.com. info.name-services.com. 2010 10001 1801 604801 181

www.enomhosteddomain.com @ dns4.name-services.com.:

www.enomhosteddomain.com. 1800 IN CNAME ghs.google.com.

www.enomhosteddomain.com @ dns5.name-services.com.:

www.enomhosteddomain.com. 1800 IN CNAME ghs.google.com.

This is one of the more subtle discrepancies, which I have observed, in the past couple months - only DNS Server #3 is out of synch, in this case. But that's enough, to make the domain unreliable.
The problem is intermittent. All of a sudden my site loads, but 10 minutes ago it didn't.
That's one eNom customer, out of over a dozen, which I have documented. And that's one eNom customer, who should be complaining, to someone above eNom Customer Service.

eNom: fix your servers!


(Update 2012/07/03): Suspicion that the problem is related to Anycast DNS led me to a bud, who is a fellow TC, and a network expert in India, and who provided an intriguing blog post, neatly diagnosing the underlying problem. It appears that eNom server monitoring policies may be a bit superficial.


Use these links, for convenient reference:

>> Top