Comcast contact sought

Al Whaley awnanog at sunnyside.com
Sun Sep 24 05:05:15 UTC 2023


I am looking for a senior contact at Comcast.

I have been trying to assist someone with a business connection that 
runs a server farm.  Recently the business cable modem started to 
short-stop port 53 for UDP and TCP.  Apparently, a transparent DNS proxy 
somehow got activated and all outbound traffic to any IPv4 or IPv6 
address is intercepted and handled by the modem – or not handled.  
Sadly, the proxy is stupid and a) ignores the intended destination 
address, and b) drops things it doesn’t know about, including any AXFR / 
IXFR and other more esoteric traffic, normal for DNS server 
installations, but not used by the public.  The DNS servers are not able 
to do work, e.g. act as secondaries.

I know others in the same configuration with servers that have been 
lucky and not had this ‘feature’ activated, but I have found several 
references on forums where people have been caught by this and 
unsuccessful in reaching anyone in management, so it is a known problem.

Comcast doesn’t allow customer supplied DOCSIS modems with multiple 
fixed IPs.  Other avenues exhausted as well.

I’m hoping someone at Comcast can disable this.  Attempts to go through 
customer service… well we all know where that ends up. Escalations just 
don’t go to anyone technical or interested.

regards
Al Whaley
Sunnyside Computing, Inc.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20230923/64feda5f/attachment.html>


More information about the NANOG mailing list