× Introducing the Orbi 970 Series Mesh System with WiFi 7 technology. For more information visit the NETGEAR Press Room.
Orbi WiFi 7 RBE973
Reply

Re: Orbi Pro SRR60 router hijacking DNS queries

owtluke
Aspirant

Orbi Pro SRR60 router hijacking DNS queries

Network setup:

1 Orbi Pro SRR60 router + 3 SRS60 satellites

PFSense firewall acting as DHCP server

Pihole DNS server

 

Before firmware upgrade:

All clients (including the Orbi devices) are assigned the pihole server for DNS queries.

Each client on wifi makes their DNS queries to pihole server. This is directly observable in the pihole logs and the metrics for each individual client can be seen on the pihole dashboard.

 

Upgraded to firmware 2.6.0.108. After firmware upgrade:

 

All clients (including the Orbi devices) are assigned the pihole server for DNS queries. Nothing has changed from a DHCP perspective.

Confirmed that the wifi devices are showing the pihole server as the DNS server.

However, the pihole logs now show a large increase in DNS queries from the pihole router itself, and ZERO queries from the wifi clients.

Tried doing a nslookup from a windows machine which is pointing to the pihole. Look at the pihole logs, and lo and behold, the request is coming from the Orbi router itself.

 

The Orbi router is intercepting the DNS requests and resubmitting them itself on behalf of the client. This is completely unacceptable and destroys the pihole metrics. I could not find anywhere in the firmware to turn this off, so the only solution was to roll back the firmware to the previous version. Having done so, the problem is instantly fixed.

 

@netgear, this is deceptive. You are ignoring the DNS server value being sent to the clients and injecting yourself in the middle. This should at a very minimum be made transparent to users, and there should be a way to disable this behavior.

 

Hasn't anyone else seen this behavior? I have the log files to prove it!

Model: SRK60B03|Orbi Pro Tri-Band Business WiFi System
Message 1 of 4
antinode
Guru

Re: Orbi Pro SRR60 router hijacking DNS queries

> Upgraded to firmware 2.6.0.108. [...]

 

   From?

 

> All clients (including the Orbi devices) are assigned the pihole
> server for DNS queries. Nothing has changed from a DHCP perspective.

 

   Really?  I know nothing, but I'd expect the DHCP server in a Netgear
router to offer itself as the DNS server for a DHCP client.

 

> The Orbi router is intercepting the DNS requests and resubmitting them
> itself on behalf of the client. [...]

 

   I'd expect that (or something like that).  The router needs to deal
with special names like "orbilogin.com".  But the implementation of that
"feature" might have changed.

 

> [...] roll back the firmware to the previous version. [...]

 

   Which was?

Message 2 of 4
owtluke
Aspirant

Re: Orbi Pro SRR60 router hijacking DNS queries

>> Upgraded to firmware 2.6.0.108. [...]

>

>From?

 

The old firmware is 2.5.2.104

 

>Really? I know nothing, but I'd expect the DHCP server in a Netgear
>router to offer itself as the DNS server for a DHCP client.

 

I would disagree. The router is running in AP mode, not router mode. I expect it to be transparent in the whole chain and not do anything with the DNS. The clients clearly show the pihole as the DNS server, so the DHCP requests are being passed through unmolested. But in the end it is the router making the request on behalf of the client. This is the core issue. I have a suspicion it is an attempt to collect DNS statistics.

Model: SRK60B03|Orbi Pro Tri-Band Business WiFi System
Message 3 of 4
antinode
Guru

Re: Orbi Pro SRR60 router hijacking DNS queries

> [...] The router is running in AP mode, not router mode. [...]

 

   Drat.  If only my psychic powers were greater, then I might have
divined that from your original problem description.  Foolishly, I
thought that "router" meant "router".

 

> [...] I expect it to be transparent in the whole chain and not do
> anything with the DNS. [...]

 

   Prepare for disappointment?

 

> [...] I have a suspicion it is an attempt to collect DNS statistics.

 

   Many things are possible, but I have a suspicion that it has
something to do with dealing with special names like "orbilogin.com".
Which might be expected to work, even when the router is configured as a
WAP.

 

   One of us could see if that behavior changed with the firmware.  If
so, then the change might have been intentional.

Message 4 of 4
Top Contributors
Discussion stats
  • 3 replies
  • 878 views
  • 0 kudos
  • 2 in conversation
Announcements

Orbi WiFi 7