# ODD DNS issue with packages.elastic.co

**URL:** <https://discuss.elastic.co/t/odd-dns-issue-with-packages-elastic-co/84318>\
**Category:** Beats\
**Created:** [May 2, 2017, 7:07pm UTC](https://discuss.elastic.co/t/odd-dns-issue-with-packages-elastic-co/84318 "2017-05-02T19:07:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![eric51893](https://avatars.discourse-cdn.com/v4/letter/e/e274bd/32.png) [@eric51893](https://discuss.elastic.co/u/eric51893)\
**Post date:** [May 2, 2017, 7:07pm UTC](https://discuss.elastic.co/t/odd-dns-issue-with-packages-elastic-co/84318/1 "2017-05-02T19:07:39Z")

</div>

We had a very odd issue recently and it turned out to be caused by the long DNS record for [packages.elastic.co](http://packages.elastic.co).

The beats.repo uses that URL. During yum installs the DNS lookup would hang.

Turns out there is a limit on DNS UDP packets to 512 bytes. The response seemed to break that limit. DNS would normally then try TCP, but we did not have TCP port 53 open in our security.

The solutions was to enable TCP on port 53.

This is the DNS record response as of today 5/2/17. It is 637 bytes. Apparently this is longer that is was a few days ago when it all worked.

getent ahosts [packages.elastic.co](http://packages.elastic.co)  
184.72.234.88 STREAM [dualstack.download-colb-770446651.us-east-1.elb.amazonaws.com](http://dualstack.download-colb-770446651.us-east-1.elb.amazonaws.com)  
184.72.234.88 DGRAM  
184.72.234.88 RAW  
23.21.84.196 STREAM  
23.21.84.196 DGRAM  
23.21.84.196 RAW  
54.204.26.172 STREAM  
54.204.26.172 DGRAM  
54.204.26.172 RAW  
23.21.140.167 STREAM  
23.21.140.167 DGRAM  
23.21.140.167 RAW  
23.23.136.240 STREAM  
23.23.136.240 DGRAM  
23.23.136.240 RAW  
174.129.40.40 STREAM  
174.129.40.40 DGRAM  
174.129.40.40 RAW  
184.73.227.9 STREAM  
184.73.227.9 DGRAM  
184.73.227.9 RAW  
23.21.201.107 STREAM  
23.21.201.107 DGRAM  
23.21.201.107 RAW

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 2, 2017, 8:35pm UTC](https://discuss.elastic.co/t/odd-dns-issue-with-packages-elastic-co/84318/2 "2017-05-02T20:35:54Z")

</div>

Thanks for raising this, I have checked with our infra team who handles DNS and we'll get back to you 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 2, 2017, 9:20pm UTC](https://discuss.elastic.co/t/odd-dns-issue-with-packages-elastic-co/84318/3 "2017-05-02T21:20:01Z")

</div>

This is known functionality with DNS (ie Route53) - [http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/DNSBehavior.html](http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/DNSBehavior.html)

And as AWS provide the resolved CNAME, `dualstack.download-colb-770446651.us-east-1.elb.amazonaws.com`, we can't shorten that either sorry. You will need to use TCP instead of UDP.

---

<div class="post-metadata">

**Author:** ![eric51893](https://avatars.discourse-cdn.com/v4/letter/e/e274bd/32.png) [@eric51893](https://discuss.elastic.co/u/eric51893)\
**Post date:** [May 3, 2017, 12:37pm UTC](https://discuss.elastic.co/t/odd-dns-issue-with-packages-elastic-co/84318/4 "2017-05-03T12:37:46Z")

</div>

Understood. It was a tough issue to diagnose. I hope others may find this bit of information useful. I have worked many places and most only default DNS to 53/UDP in their firewalls.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 23, 2017, 7:18pm UTC](https://discuss.elastic.co/t/odd-dns-issue-with-packages-elastic-co/84318/5 "2017-05-23T19:18:01Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
