DNS resolution issue

Friends,
My setup is 19.07.08 + PC-Engine X86 HW.
Packages used : mwan3, wifidog.

I am facing a strange issue of DNS resolution.
"ping goolg.com" fails 2 out of 10 times, from within the firewall.
As user too through an wifi access-point, DNS failed issue shows up frequently while using internet.
I tried configuring 8.8.8.8 or ISP's own DNS, didn't see much difference.
I think it gets worse as the user load reaches 100.

I had marked this off as ISP issue, but then when box replaced it with a non-OpenWRT box, the issue doesn't show up.
It's very hard to believe its OpenWRT issue, except for this last data-point.

What could be going wrong?

This is long since eol and unsupported. You need to upgrade to a modern version.

Sure, thats my next move.
But still I am running a few other boxes with exact same version, works fine.

Upgrade to 25.12 first. You will need to recreate your config from scratch, as the configs from 19.07 are not compatible with 25.12. You can use a backup of your existing config to serve as a human readable reference so you can remember things like the subnet definitions and other general config details, but do not try to restore the backup to your new installation.

Staying up-to-date is essential for many reasons -- most notably security. The version you are using now has not been updated about half a decade and has many known security vulnerabilities. Beyond this, the old versions are officially unsupported -- as time goes on, the syntax and methods for configuration change and it's not practical for people to maintain working knowledge of old and obsolete methods (to draw a parallel, it would be a stretch to expect anyone to help you with the Windows 95 registry unless you were asking in a community of retro-computing enthusiasts).

Thanks, I can upgrade and reconfigure, no help required on that.
Neither am I looking for someone to check my configs and debug my issue.
Just wanted to hear from community:
In what way OpenWRT can affect DNS resolution.
Firewall rules should be deterministic. Not 2/10 failures.
If its local congestion, ping 8.8.8.8 goes through.
Things along these line.

.... running a 7 yo release, don't expect lots of replies.

On every device using that AP, or just one?

You, probably, have a dns cache issue (browser,OS,switch,AP, etc).

But,
I could guess all day with 19.07.08.

The only thing I know about it, for sure, is: all my Pixies are accounted for and not running around lose; even if they were running amok, they think 19.x is just "ewwww"...

with 25.x what would be your guess?
Simple test I am doing.
From within the OpenWRT box i do:
ping google.com, wait for 1 response.
2 out of 10 such iterations fails to get reponse.
ping 8.8.8.8 always works.
My question is how can a router impact DNS resolution?
It's just forwarding the query.

If you ping google.com, and 8.8.8.8 fails to respond, it's not a DNS issue, since the name lookup worked ?

It's highly unlikley the router.

Depends on your setup and circumstances.

And in general: Without seeing configs or logs it is just a waste of time to poke in the dark.

Edit ps. And yes, a 7 year old release does not make it easier. Sure the main functions of dnsmasq changed not much but nevertheless it has seen many bug fixes too.

I was enjoying making up stories!

Feel free to post fan fiction :slightly_smiling_face:

No, let me clarify.
ping google.com fails, 2 out of 10 times.
ping 8.8.8.8 [google dns server, or it could be any other valid IP] works all the time.
Pointing to name resolution issue, isn't it?

What are those, can we talk?
Can we discuss beyond the old version I am using, yes, security issue but the risk is all on me.
What exactly would've changed from DNS?
19.x was a stable working OpenWRT at its time.

Please post one of those failed occasions.

Also post output of nslookup google.com.

Use the </> the button you paste the cli output.

I don't have exact log to cp-paste but can recreate from memory.
I do ping google.com
3 types of response:

  1. Normal, ping response in 1 second from google IP printed. (I cancel and repeat).
  2. A delayed response, like 3-4 seconds (i cancel and repeat)
  3. "bad address"

We'll wait until you do.

All your 'questions/replies' are rebuttals.

Answer questions, (HOW MANY DEVICES ARE FAILING???) and follow instructions.

I want to thank you for participating on my concern.
However you don't seem to be following.
Failing number of "devices" is not a variable here.
I am pinging right from within the firewall.