Sunday, January 26, 2025

Debugging for Cisco Secure Access SWG

--------------------------------------------------------------------------------------------------------------------

2.Traceroute:

tracert swg-url-proxy-https-sse.sigproxy.qq.opendns.com

tracert 208.67.222.222

tracert 208.67.220.220

tracert 146.112.255.50

--------------------------------------------------------------------------------------------------------------------

% tracert swg-url-proxy-https-sse.sigproxy.qq.opendns.com 

zsh: command not found: tracert

taka@TKUROKAW-M-607Q ~ % traceroute swg-url-proxy-https-sse.sigproxy.qq.opendns.com

traceroute to k8s-sigproxy-sigproxy-5a5a348834-00d20179cbb1ae5c.elb.ap-east-1.amazonaws.com (18.167.154.183), 64 hops max, 40 byte packets

 1  10.130.0.1 (10.130.0.1)  8.488 ms  1.690 ms  1.542 ms

 2  bb116-14-127-252.singnet.com.sg (116.14.127.252)  3.198 ms  2.677 ms  2.379 ms

 3  165.21.193.22 (165.21.193.22)  7.728 ms  3.635 ms  3.410 ms

 4  165.21.193.21 (165.21.193.21)  5.629 ms  3.386 ms  3.082 ms

 5  165.21.138.245 (165.21.138.245)  5.122 ms  4.209 ms  5.617 ms

 6  sn-sinqt1-bo403-ae1.singnet.com.sg (165.21.138.85)  5.473 ms  3.508 ms  3.268 ms

 7  203.208.177.213 (203.208.177.213)  6.860 ms  3.988 ms  3.307 ms

 8  * * *

 9  * * *

<snip>


--------------------------------------------------------------------------------------------------------------------

% traceroute 208.67.222.222

traceroute to 208.67.222.222 (208.67.222.222), 64 hops max, 40 byte packets

 1  10.130.0.1 (10.130.0.1)  7.411 ms  1.922 ms  2.280 ms

 2  bb116-14-127-252.singnet.com.sg (116.14.127.252)  8.785 ms  2.767 ms  3.154 ms

 3  165.21.193.22 (165.21.193.22)  6.570 ms  8.376 ms  3.809 ms

 4  165.21.193.21 (165.21.193.21)  8.729 ms  3.705 ms  3.367 ms

 5  165.21.138.245 (165.21.138.245)  5.008 ms  3.908 ms  4.014 ms

 6  sn-sinqt1-bo403-ae1.singnet.com.sg (165.21.138.85)  4.369 ms  3.352 ms  3.254 ms

 7  203.208.177.213 (203.208.177.213)  8.059 ms  3.171 ms  3.690 ms

 8  xn-lhrcl1-bo706.ix.singtel.com (203.208.183.81)  5.836 ms  4.380 ms  4.088 ms

 9  203.208.158.9 (203.208.158.9)  7.494 ms

    203.208.172.106 (203.208.172.106)  41.574 ms

    203.208.171.229 (203.208.171.229)  39.886 ms

10  203.208.154.14 (203.208.154.14)  78.489 ms  40.237 ms  42.193 ms

11  203.208.151.122 (203.208.151.122)  53.342 ms

    203.208.154.14 (203.208.154.14)  46.588 ms

    203.208.178.229 (203.208.178.229)  46.363 ms

12  203.208.178.229 (203.208.178.229)  39.314 ms  45.246 ms  40.317 ms

13  * xe-3-4-1-2.a00.newthk04.hk.ce.gin.ntt.net (203.131.241.46)  45.080 ms *

14  * * *

<snip>


--------------------------------------------------------------------------------------------------------------------

% traceroute 208.67.220.220

traceroute to 208.67.220.220 (208.67.220.220), 64 hops max, 40 byte packets

 1  10.130.0.1 (10.130.0.1)  8.677 ms  2.382 ms  2.394 ms

 2  bb116-14-127-252.singnet.com.sg (116.14.127.252)  4.687 ms  3.321 ms  2.766 ms

 3  165.21.193.22 (165.21.193.22)  6.131 ms  3.680 ms  5.547 ms

 4  165.21.193.21 (165.21.193.21)  7.892 ms  3.580 ms  3.352 ms

 5  165.21.138.245 (165.21.138.245)  6.021 ms  4.359 ms  7.403 ms

 6  165.21.139.118 (165.21.139.118)  8.727 ms  3.845 ms  3.508 ms

 7  165.21.139.134 (165.21.139.134)  5.921 ms  4.572 ms  5.047 ms

 8  unknown.telstraglobal.net (210.57.30.65)  45.862 ms  39.708 ms  37.830 ms

 9  i-92.sgcn-core01.telstraglobal.net (202.84.219.174)  41.318 ms *  39.083 ms

10  i-93.istt04.telstraglobal.net (202.84.224.190)  125.209 ms  38.010 ms  53.270 ms

11  i-91.istt04.telstraglobal.net (202.84.224.197)  47.025 ms

    unknown.telstraglobal.net (202.127.73.50)  48.208 ms  50.623 ms

12  unknown.telstraglobal.net (202.127.73.50)  56.407 ms *  46.342 ms

13  * * *

14  * * *

<snip>


--------------------------------------------------------------------------------------------------------------------


% traceroute 146.112.255.50

traceroute to 146.112.255.50 (146.112.255.50), 64 hops max, 40 byte packets

 1  10.130.0.1 (10.130.0.1)  8.720 ms  1.954 ms  3.073 ms

 2  bb116-14-127-252.singnet.com.sg (116.14.127.252)  8.597 ms  2.375 ms  2.454 ms

 3  165.21.193.22 (165.21.193.22)  10.124 ms  282.606 ms  7.634 ms

 4  165.21.193.21 (165.21.193.21)  6.764 ms  3.604 ms  3.988 ms

 5  165.21.138.245 (165.21.138.245)  15.043 ms  3.983 ms  3.794 ms

 6  sn-sinqt1-bo403-ae1.singnet.com.sg (165.21.138.85)  4.938 ms  2.978 ms  2.771 ms

 7  203.208.177.213 (203.208.177.213)  13.649 ms  10.204 ms  3.884 ms

 8  xn-lhrcl1-bo706.ix.singtel.com (203.208.183.81)  27.494 ms *  7.412 ms

 9  203.208.152.194 (203.208.152.194)  47.812 ms

    203.208.171.229 (203.208.171.229)  42.616 ms  36.318 ms

10  203.208.158.206 (203.208.158.206)  15.053 ms

    203.208.154.14 (203.208.154.14)  56.055 ms

    203.208.178.17 (203.208.178.17)  62.593 ms

11  203.208.154.14 (203.208.154.14)  42.300 ms  45.868 ms

    203.208.178.229 (203.208.178.229)  46.825 ms

12  203.208.178.229 (203.208.178.229)  45.777 ms  57.698 ms

    xe-3-4-1-2.a00.newthk04.hk.ce.gin.ntt.net (203.131.241.46)  49.709 ms

13  203.208.178.17 (203.208.178.17)  40.206 ms

    146.112.251.27 (146.112.251.27)  45.923 ms

    146.112.251.28 (146.112.251.28)  52.339 ms

14  146.112.251.28 (146.112.251.28)  46.799 ms  40.328 ms

    203.208.154.14 (203.208.154.14)  40.605 ms

15  203.208.178.229 (203.208.178.229)  53.644 ms *  40.729 ms

16  * * *

17  146.112.251.25 (146.112.251.25)  47.123 ms  40.681 ms *

18  * * *

19  * * *

<snip>


--------------------------------------------------------------------------------------------------------------------



--------------------------------------------------------------------------------------------------------------------

3.nslookup


nslookup swg-url-proxy-https-sse.sigproxy.qq.opendns.com 208.67.222.222

nslookup swg-url-proxy-https-sse.sigproxy.qq.opendns.com localDNS configured in the NIC

nslookup swg-url-proxy-https-sse.sigproxy.qq.opendns.com 127.0.0.1

nslookup -type=TXT debug.sigproxy.qq.opendns.com

nslookup -type=TXT debug.opendns.com

--------------------------------------------------------------------------------------------------------------------



% nslookup swg-url-proxy-https-sse.sigproxy.qq.opendns.com 208.67.222.222


Server: 208.67.222.222

Address: 208.67.222.222#53


Non-authoritative answer:

swg-url-proxy-https-sse.sigproxy.qq.opendns.com canonical name = swg-proxy_ap-southeast-1_1_1n.sigproxy.aws.umbrella.com.

swg-proxy_ap-southeast-1_1_1n.sigproxy.aws.umbrella.com canonical name = k8s-sigproxy-sigproxy-0beb0c6be5-2ecb15868b8331c4.elb.ap-southeast-1.amazonaws.com.

Name: k8s-sigproxy-sigproxy-0beb0c6be5-2ecb15868b8331c4.elb.ap-southeast-1.amazonaws.com

Address: 3.0.236.175





--------------------------------------------------------------------------------------------------------------------



% nslookup swg-url-proxy-https-sse.sigproxy.qq.opendns.com 165.21.100.88

Server: 165.21.100.88

Address: 165.21.100.88#53


Non-authoritative answer:

swg-url-proxy-https-sse.sigproxy.qq.opendns.com canonical name = swg-proxy_ap-southeast-1_1_1n.sigproxy.aws.umbrella.com.

swg-proxy_ap-southeast-1_1_1n.sigproxy.aws.umbrella.com canonical name = k8s-sigproxy-sigproxy-0beb0c6be5-2ecb15868b8331c4.elb.ap-southeast-1.amazonaws.com.

Name: k8s-sigproxy-sigproxy-0beb0c6be5-2ecb15868b8331c4.elb.ap-southeast-1.amazonaws.com

Address: 3.0.236.175



--------------------------------------------------------------------------------------------------------------------




% nslookup swg-url-proxy-https-sse.sigproxy.qq.opendns.com 127.0.0.1

Server: 127.0.0.1

Address: 127.0.0.1#53


Non-authoritative answer:

swg-url-proxy-https-sse.sigproxy.qq.opendns.com canonical name = swg-proxy_ap-southeast-1_1_1n.sigproxy.aws.umbrella.com.

swg-proxy_ap-southeast-1_1_1n.sigproxy.aws.umbrella.com canonical name = k8s-sigproxy-sigproxy-0beb0c6be5-2ecb15868b8331c4.elb.ap-southeast-1.amazonaws.com.

Name: k8s-sigproxy-sigproxy-0beb0c6be5-2ecb15868b8331c4.elb.ap-southeast-1.amazonaws.com

Address: 3.0.236.175



--------------------------------------------------------------------------------------------------------------------



% nslookup -type=TXT debug.sigproxy.qq.opendns.com

Server: 165.21.100.88

Address: 165.21.100.88#53


Non-authoritative answer:

debug.sigproxy.qq.opendns.com text = "DATACENTER = hkg"

debug.sigproxy.qq.opendns.com text = "CLIENT_COUNTRY = SG"

debug.sigproxy.qq.opendns.com text = "CLIENT_ORG_ID = 8206400"

debug.sigproxy.qq.opendns.com text = "SOURCE_IP = 67.215.82.78"

debug.sigproxy.qq.opendns.com text = "CLIENT_IP = 220.255.190.244"

debug.sigproxy.qq.opendns.com text = "SERVICE_ZONE = sigproxy.qq.opendns.com"

debug.sigproxy.qq.opendns.com text = "QUADRA_SLUG = zeus-dnslb-d84cd7e65211.signginx.hkg"

debug.sigproxy.qq.opendns.com text = "SWG URL = swg-url-proxy-https.sigproxy.qq.opendns.com."

debug.sigproxy.qq.opendns.com text = "SSE URL = swg-url-proxy-https-sse.sigproxy.qq.opendns.com."


Authoritative answers can be found from:



--------------------------------------------------------------------------------------------------------------------



% nslookup -type=TXT debug.opendns.com

;; Truncated, retrying in TCP mode.

Server: 165.21.100.88

Address: 165.21.100.88#53


Non-authoritative answer:

debug.opendns.com text = "server m45.hkg"

debug.opendns.com text = "device 0101cce9112df3f6"

debug.opendns.com text = "organization id 8206400"

debug.opendns.com text = "user id b2ad6de34dbbb52cf4c6d4a600661b0d"

debug.opendns.com text = "remoteip 10.130.0.23"

debug.opendns.com text = "flags 10A040034 0 0 180000000000000000003800000000000000000"

debug.opendns.com text = "device orgid 8206400"

debug.opendns.com text = "device originid 635704254"

debug.opendns.com text = "originid 635704254"

debug.opendns.com text = "orgid 8206400"

debug.opendns.com text = "orgflags 37B7E750F59028E6"

debug.opendns.com text = "actype 0"

debug.opendns.com text = "bundle 14293004"

debug.opendns.com text = "rules based policy enabled"

debug.opendns.com text = "source 220.255.190.244:60972"

debug.opendns.com text = "dnscrypt enabled (ES1, qSL81ju1)"


Authoritative answers can be found from:



--------------------------------------------------------------------------------------------------------------------

4.dig

dig swg-url-proxy-https-sse.sigproxy.qq.opendns.com +nsid +short @208.67.222.222

dig swg-url-proxy-https-sse.sigproxy.qq.opendns.com +nsid +short @local resolver IP

 

--------------------------------------------------------------------------------------------------------------------



% dig swg-url-proxy-https-sse.sigproxy.qq.opendns.com +nsid +short @208.67.222.222

swg-proxy_ap-southeast-1_1_1n.sigproxy.aws.umbrella.com.

k8s-sigproxy-sigproxy-0beb0c6be5-2ecb15868b8331c4.elb.ap-southeast-1.amazonaws.com.

3.0.236.175




 % dig swg-url-proxy-https-sse.sigproxy.qq.opendns.com +nsid +short @165.21.100.88

swg-proxy_ap-southeast-1_1_1n.sigproxy.aws.umbrella.com.

k8s-sigproxy-sigproxy-0beb0c6be5-2ecb15868b8331c4.elb.ap-southeast-1.amazonaws.com.

3.0.236.175


















No comments:

Post a Comment

Cisco Secure Access Docker

  sudo apt-get update sudo apt-get install ca-certificates curl sudo install -m 0755 -d /etc/apt/keyrings sudo curl -fsSL https://download.d...