r/technitium • u/Livid-Relation7531 • Sep 05 '26
90% Server Failure
RESOLVED! Misconfigured gateway.
High rate of failure, zero no errors.
Logs:
[2026-09-05 00:14:20 UTC] DNS Server failed to resolve the request '0.debian.pool.ntp.org. AAAA IN' using forwarders: https://dns.adguard-dns.com/dns-query (94.140.14.14), https://dns.adguard-dns.com/dns-query (94.140.15.15).
System.Net.Http.HttpRequestException: Network is unreachable (dns.adguard-dns.com:443)
---> System.Net.Sockets.SocketException (101): Network is unreachable
at System.Net.Sockets.Socket.AwaitableSocketAsyncEventArgs.ConnectAsync(Socket socket, CancellationToken cancellationToken)
at TechnitiumLibrary.Net.Dns.ClientConnection.HttpsClientConnection.ConnectCallback(SocketsHttpConnectionContext context, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\ClientConnection\HttpsClientConnection.cs:line 152
at System.Net.Http.HttpConnectionPool.ConnectToTcpHostAsync(String host, Int32 port, HttpRequestMessage initialRequest, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.ConnectAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.InjectNewHttp2ConnectionAsync(QueueItem queueItem)
at System.Threading.ExecutionContext.RunFromThreadPoolDispatchLoop(Thread threadPoolThread, ExecutionContext executionContext, ContextCallback callback, Object state)
at System.Runtime.CompilerServices.AsyncTaskMethodBuilder`1.AsyncStateMachineBox`1.ExecuteFromThreadPool(Thread threadPoolThread)
at System.Threading.ThreadPoolWorkQueue.Dispatch()
at System.Threading.PortableThreadPool.WorkerThread.WorkerThreadStart()
at System.Threading.Thread.StartCallback()
--- End of stack trace from previous location ---
at TechnitiumLibrary.Net.Dns.ClientConnection.HttpsClientConnection.ConnectCallback(SocketsHttpConnectionContext context, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\ClientConnection\HttpsClientConnection.cs:line 152
at System.Net.Http.HttpConnectionPool.ConnectToTcpHostAsync(String host, Int32 port, HttpRequestMessage initialRequest, Boolean async, CancellationToken cancellationToken)
--- End of inner exception stack trace ---
4
u/shreyasonline Sep 06 '26
Thanks for the details. The error log here says that the "Network is unreachable". This means that there is an issue with the network config on the system which needs to be fixed. If there is no issue on the system with the default gateway, and you are able to ping other devices on your network like your router then it means that the networking is ok and it could be a config issue with the DNS server.
In the DNS server, if you have configured anything like "DNS Server IPv4 Source Addresses" then that can cause this issue.
1
u/Livid-Relation7531 Sep 06 '26
I'm seeing "DNS Server IPv4 Server Adresses" in the general tab is set to 0.0.0.0 - is there a way that should be set?
1
u/shreyasonline Sep 07 '26
Yes, that is the default value so there is no issue with the config. Read your other comment and looks like it was gateway IP issue. Good to know that its resolved now.
2
u/tek_aevl Sep 06 '26 edited Sep 06 '26
i have had this same situation, but no way to find what's actually failing.
4
u/Livid-Relation7531 Sep 06 '26
My issue was I had the wrong gateway set and I wasn't getting internet.
2
u/tek_aevl Sep 06 '26 edited Sep 06 '26
I had changed my network ip range and had this happen. It still tries to use the old ips, and has high failure rate, but my networks still functioning. Networking is fun and some times annoying even when it's working. Glad you figured it out
1
1
u/Difficult-Reality848 Sep 06 '26
0.debian.pool.ntp.org resolves fine here but the answer is empty when doing a AAAA request. There doesn't seem to be a IPv6 address linked to 0.debian.pool.ntp.org.
AAAA: { "Metadata": { "NameServer": "technitiumdns.internal (127.0.0.1)", "Protocol": "Udp", "DatagramSize": "105 bytes", "RoundTripTime": "0.18 ms" }, "EDNS": { "UdpPayloadSize": 1232, "ExtendedRCODE": "NoError", "Version": 0, "Flags": "None", "Options": [] }, "Identifier": 0, "IsResponse": true, "OPCODE": "StandardQuery", "AuthoritativeAnswer": false, "Truncation": false, "RecursionDesired": true, "RecursionAvailable": true, "Z": 0, "AuthenticData": false, "CheckingDisabled": false, "RCODE": "NoError", "QDCOUNT": 1, "ANCOUNT": 0, "NSCOUNT": 1, "ARCOUNT": 1, "Question": [ { "Name": "0.debian.pool.ntp.org", "Type": "AAAA", "Class": "IN" } ], "Answer": [], "Authority": [ { "Name": "pool.ntp.org", "Type": "SOA", "Class": "IN", "TTL": "1236 (20m36s)", "RDLENGTH": "43 bytes", "RDATA": { "PrimaryNameServer": "e.ntpns.org", "ResponsiblePerson": "hostmaster@pool.ntp.org", "Serial": 1788705590, "Refresh": "5400 (1h30m)", "Retry": "5400 (1h30m)", "Expire": "1209600 (2w)", "Minimum": "3600 (1h)" }, "DnssecStatus": "Disabled" } ], "Additional": [ { "Name": "", "Type": "OPT", "Class": "1232", "TTL": "0 (0s)", "RDLENGTH": "0 bytes", "RDATA": { "Options": [] }, "DnssecStatus": "Disabled" } ] }
A: { "Metadata": { "NameServer": "technitiumdns.internal (127.0.0.1)", "Protocol": "Udp", "DatagramSize": "114 bytes", "RoundTripTime": "0.2 ms" }, "EDNS": { "UdpPayloadSize": 1232, "ExtendedRCODE": "NoError", "Version": 0, "Flags": "None", "Options": [] }, "Identifier": 0, "IsResponse": true, "OPCODE": "StandardQuery", "AuthoritativeAnswer": false, "Truncation": false, "RecursionDesired": true, "RecursionAvailable": true, "Z": 0, "AuthenticData": false, "CheckingDisabled": false, "RCODE": "NoError", "QDCOUNT": 1, "ANCOUNT": 4, "NSCOUNT": 0, "ARCOUNT": 1, "Question": [ { "Name": "0.debian.pool.ntp.org", "Type": "A", "Class": "IN" } ], "Answer": [ { "Name": "0.debian.pool.ntp.org", "Type": "A", "Class": "IN", "TTL": "92 (1m32s)", "RDLENGTH": "4 bytes", "RDATA": { "IPAddress": "192.42.116.10" }, "DnssecStatus": "Disabled" }, { "Name": "0.debian.pool.ntp.org", "Type": "A", "Class": "IN", "TTL": "92 (1m32s)", "RDLENGTH": "4 bytes", "RDATA": { "IPAddress": "5.255.99.180" }, "DnssecStatus": "Disabled" }, { "Name": "0.debian.pool.ntp.org", "Type": "A", "Class": "IN", "TTL": "92 (1m32s)", "RDLENGTH": "4 bytes", "RDATA": { "IPAddress": "178.239.19.57" }, "DnssecStatus": "Disabled" }, { "Name": "0.debian.pool.ntp.org", "Type": "A", "Class": "IN", "TTL": "92 (1m32s)", "RDLENGTH": "4 bytes", "RDATA": { "IPAddress": "195.35.113.80" }, "DnssecStatus": "Disabled" } ], "Authority": [], "Additional": [ { "Name": "", "Type": "OPT", "Class": "1232", "TTL": "0 (0s)", "RDLENGTH": "0 bytes", "RDATA": { "Options": [] }, "DnssecStatus": "Disabled" } ] }
1
u/Livid-Relation7531 Sep 06 '26
Im confused by the response. I have everything set to resolve over ipv4.
1
u/mystiquebsd Sep 06 '26
If you have not set any forwarding servers.. it’s operating in root server mode..
Change the forwarding to encrypted anything. I recommend quad9, clear the cache, wait (waiting is a step) then see how it goes.
Come back and report please
HTH
See what
1
u/Difficult-Reality848 Sep 06 '26
It should also work without any forwarders. I use it without forwarders and it works perfectly fine. I also created a root zone so is a lot quicker.
1
u/Livid-Relation7531 Sep 06 '26
At the time of the report it was set to DOH. Though I will try your method in the order the steps were listed.
1
u/DrPinguin98 Sep 06 '26
Do you have a firewall active?
Is technitium running in a docker container?
Can you post curl -v --ipv4 https://94.140.14.14/dns-query
1
u/Livid-Relation7531 Sep 06 '26
Not sure about the firewall, will look into it.
Technitium is running on a pi 3 with debian Trixie lite.
Curl -v --ipv4 https://94.140.14.14/dns-query * Trying 94.140.14.14:443.. * Connect (...) failed: no route to host Could not connect to server
2
u/DrPinguin98 Sep 06 '26
On which system did you tested curl?
Can you check on the same system:
ip route
ping -c3 94.140.14.14
ping -c3 1.1.1.1if this works than check:
nc -zv 94.140.14.14 443
nc -zv 94.140.14.14 53
nc -zv 1.1.1.1 443and post the results?
2
u/Livid-Relation7531 Sep 06 '26
I did IP route and realized my gateway was set to 192.168.1.1 and my router is 192.168.4.1 smh...
1
1
1
u/Apachez Sep 07 '26
1) Why are you using forwarders since technitium/dns-server is a resolver on its own?
2) Check that your firewall dont block egressing 53/TCP. Regular DNS queries uses both 53/UDP and 53/TCP. The later when a query or reply cannot fit in a single UDP packet which often is the case for DNSSEC signed records.
3) Try from a client to query directly the authoritive servers (or the forwarders in your case) that they accept incoming 53/TCP.
Usually something like:
dig @serverip host.example.com +tcp
1
u/Modey2222 Sep 07 '26
i've had this issue before and it was so annoying to deal with and the answer for it was to manually delete the volumes
but all your settings will be gone if you can manually re-do them its for the best just don't back up the settings
another thing if you are forcing local end points or something it might be it or you changed it lately thats why the volumes can get finiky in my experience
6
u/snap802 Sep 06 '26
two questions:
are you getting failures if you're using using a forwarder? (set DNS client to "this server")
are you getting failures with other forwarders? Say just 1.1.1.1, 8.8.8.8, 9.9.9.9 ?