CloudStack OS

CloudStack Console Proxy Unable To Resolve DNS Address

UPDATE (20131122): Sometimes goes down and can cause DNS failures.

Recently, console access to my CloudStack VMs stopped from the browser altogether. Safari would simply show a blank page while Google Chrome would show a more helpful “Unable to resolve the server’s DNS address” error.

Screen Shot 2013-10-19 at 4.26.57 PM

And the culprit turned out to be a minor dnsmasq setting in DD-WRT.

The browser was unable to resolver the console access URLs generated by CloudStack. These URLs point to which is the default wildcard DNS domain configured in CloudStack. Queries for was failing.

$ host
Using domain server:

The same query would work against public DNS servers like Google DNS

$ host
Using domain server:
Aliases: has address

I recently changed my home edge router from a Linksys EA3500 to Asus RTN16 running the open-source DD-WRT firmware. The DD-WRT “No DNS Rebind” setting was set to “Enabled” and was causing the DNS resolution to fail.

According to dnsmasq(8),

Reject (and log) addresses from upstream nameservers which are in the private IP ranges. This blocks an attack where a browser behind a firewall is used to probe machines on the local network.

Since my home CloudStack public network uses RFC 1918 private subnets, the requests were being dropped by my local DNS server

The fix is to Disable No DNS Rebind option as below

Screen Shot 2013-10-19 at 4.39.52 PM

After the change, addresses started resolving and console proxy access from the browser works once more.

$ host has address

Screen Shot 2013-10-19 at 4.45.31 PM

Update (20131118): OpenWRT users should turn off Rebind Protection option.

Screen Shot 2013-11-18 at 5.57.28 pm

By Shanker Balan

Shanker Balan is a devops and infrastructure freelancer with over 14 years of industry experience in large scale Internet systems. He is available for both short term and long term projects on contract.

Please use the Contact Form for any enquiry.

One reply on “CloudStack Console Proxy Unable To Resolve DNS Address”

Leave a Reply

Your email address will not be published. Required fields are marked *