www.rna.gov.it is not resolvable when we are in our network with public 184.108.40.206 while using dns over https, but also just using nslookup using 220.127.116.11. As we use Zero Trust I was able to see that the specific error is “no reachalbe authority”. using other networks and italian public ips it works. interstingly enough it also works when using 18.104.22.168. how is this issue resolvable?
Indeed, I can reproduce the issue that 22.214.171.124 and Zero Trust Gateway both can’t resolve the query, while Quad9, OpenDNS and Google Public DNS do reply with an IP.
$ dig www.rna.gov.it @126.96.36.199 ; <<>> DiG 9.16.33-RH <<>> www.rna.gov.it @188.8.131.52 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 49842 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 512 ;; QUESTION SECTION: ;www.rna.gov.it. IN A ;; ANSWER SECTION: www.rna.gov.it. 2630 IN A 184.108.40.206 ;; Query time: 3 msec ;; SERVER: 220.127.116.11#53(18.104.22.168) ;; WHEN: Mon Nov 14 08:33:23 CET 2022 ;; MSG SIZE rcvd: 59 $ dig www.rna.gov.it @22.214.171.124 ; <<>> DiG 9.16.33-RH <<>> www.rna.gov.it @126.96.36.199 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 2390 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232 ; EDE: 22 (No Reachable Authority): (at delegation rna.gov.it.) ;; QUESTION SECTION: ;www.rna.gov.it. IN A ;; Query time: 893 msec ;; SERVER: 188.8.131.52#53(184.108.40.206) ;; WHEN: Mon Nov 14 08:33:32 CET 2022 ;; MSG SIZE rcvd: 74
Thanks for confirming. I was wondering if Cloudflare or me myself can resolve the “no reachalbe authority” problem or it must be the nameserver of the dns.
Users of Cloudflare DNS like you and me can’t do anything about it. As it already going on for 11 days, submitting the 220.127.116.11 purge cache form won’t help either.
I’m not sure if the problem should be solved by Cloudflare or by the administrators of the gov.it authoritative nameservers.
I’m sorry for the delay. From what I can see, our service is not able to query the domain’s nameserver
ns.dgiai.gov.it.. We’ll try to contact the other side to see what is going on.