- 论坛徽章:
- 1
|
這問題 netman 兄巳經講得很清楚了,這不屬於理論或實作的問題,
問題在於 GCD 對出口進口的 DNS 做了手腳,這個問題在一兩年前就巳經被證明了
# 這個 DNS @202.101.103.55 在大陸福建,跟它查 "台灣的一個新聞站台",沒有返回結果
- [root@eai1 root]# dig @202.101.103.55 www.chinatimes.com
- ; <<>> DiG 9.3.0 <<>> @202.101.103.55 www.chinatimes.com
- ;; global options: printcmd
- ;; Got answer:
- ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 64934
- ;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 2, ADDITIONAL: 2
- ;; QUESTION SECTION:
- ;www.chinatimes.com. IN A
- ;; AUTHORITY SECTION:
- chinatimes.com. 139669 IN NS ct-dns2.chinatimes.com.
- chinatimes.com. 139669 IN NS ct-dns1.chinatimes.com.
- ;; ADDITIONAL SECTION:
- ct-dns1.chinatimes.com. 139669 IN A 210.200.239.19
- ct-dns2.chinatimes.com. 148966 IN A 211.72.253.9
- ;; Query time: 232 msec
- ;; SERVER: 202.101.103.55#53(202.101.103.55)
- ;; WHEN: Mon Jul 10 15:46:08 2006
- ;; MSG SIZE rcvd: 112
复制代码
再查另一大報 udn.com, 還是裝白吃
- [root@eai1 root]# dig @202.101.103.55 udn.com
- ; <<>> DiG 9.3.0 <<>> @202.101.103.55 udn.com
- ;; global options: printcmd
- ;; Got answer:
- ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 15259
- ;; flags: qr rd; QUERY: 1, ANSWER: 8, AUTHORITY: 2, ADDITIONAL: 2
- ;; QUESTION SECTION:
- ;udn.com. IN A
- ;; ANSWER SECTION:
- udn.com. 711 IN A 210.244.31.147
- udn.com. 711 IN A 210.244.31.151
- udn.com. 711 IN A 210.244.31.152
- udn.com. 711 IN A 210.244.31.154
- udn.com. 711 IN A 210.243.166.43
- udn.com. 711 IN A 210.243.166.44
- udn.com. 711 IN A 210.243.166.45
- udn.com. 711 IN A 210.244.31.140
- ;; AUTHORITY SECTION:
- udn.com. 313 IN NS dns1.udn.com.
- udn.com. 313 IN NS dns2.udn.com.
- ;; ADDITIONAL SECTION:
- dns1.udn.com. 149315 IN A 210.243.166.37
- dns2.udn.com. 155231 IN A 211.72.249.39
- ;; Query time: 184 msec
- ;; SERVER: 202.101.103.55#53(202.101.103.55)
- ;; WHEN: Mon Jul 10 15:46:20 2006
- ;; MSG SIZE rcvd: 223
复制代码
是不是不接受 recursive, 用新浪測
- [root@eai1 root]# dig @202.101.103.55 www.sina.com.cn
- ; <<>> DiG 9.3.0 <<>> @202.101.103.55 www.sina.com.cn
- ;; global options: printcmd
- ;; Got answer:
- ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 19951
- ;; flags: qr rd; QUERY: 1, ANSWER: 18, AUTHORITY: 3, ADDITIONAL: 3
- ;; QUESTION SECTION:
- ;www.sina.com.cn. IN A
- ;; ANSWER SECTION:
- www.sina.com.cn. 57 IN CNAME jupiter.sina.com.cn.
- jupiter.sina.com.cn. 59 IN CNAME antares.sina.com.cn.
- antares.sina.com.cn. 58 IN A 218.30.66.116
- antares.sina.com.cn. 58 IN A 218.30.66.117
- antares.sina.com.cn. 58 IN A 218.30.66.118
- antares.sina.com.cn. 58 IN A 218.30.66.119
- antares.sina.com.cn. 58 IN A 218.30.66.120
- antares.sina.com.cn. 58 IN A 218.30.66.121
- antares.sina.com.cn. 58 IN A 218.30.66.122
- antares.sina.com.cn. 58 IN A 218.30.66.123
- antares.sina.com.cn. 58 IN A 218.30.66.108
- antares.sina.com.cn. 58 IN A 218.30.66.109
- antares.sina.com.cn. 58 IN A 218.30.66.110
- antares.sina.com.cn. 58 IN A 218.30.66.111
- antares.sina.com.cn. 58 IN A 218.30.66.112
- antares.sina.com.cn. 58 IN A 218.30.66.113
- antares.sina.com.cn. 58 IN A 218.30.66.114
- antares.sina.com.cn. 58 IN A 218.30.66.115
- ;; AUTHORITY SECTION:
- sina.com.cn. 85478 IN NS ns3.sina.com.cn.
- sina.com.cn. 85478 IN NS ns1.sina.com.cn.
- sina.com.cn. 85478 IN NS ns2.sina.com.cn.
- ;; ADDITIONAL SECTION:
- ns1.sina.com.cn. 53041 IN A 202.106.184.166
- ns2.sina.com.cn. 53917 IN A 61.172.201.254
- ns3.sina.com.cn. 53367 IN A 202.108.44.55
- ;; Query time: 364 msec
- ;; SERVER: 202.101.103.55#53(202.101.103.55)
- ;; WHEN: Mon Jul 10 15:46:33 2006
- ;; MSG SIZE rcvd: 435
复制代码
所以結果為 GCD 過濾所致,因為台灣的新聞網站在大陸是被禁止的
而很多 "禁止的" 不完全是新聞網站
因為 https smtps 需要 DNS 做底層的解析,
攔走你的 DNS 封包,你還沒能 s 就完了, 國外的 proxy 之所以可以 work 是因為
resolver domain/fqdn 是丟給了 proxy server 做,但用久了通常也是封了 |
|