Facebook picture issue fixed :D

So, recently I’ve been having issues with pictures loading on Facebook. Basically everything else works, but random images just fail to load.

I was messing around with it this morning and noticed that chrome was stuck on “Resolving address…”

Popping open a terminal window, I tried to see if it was a DNS issue.

none-2:~ yaleman$ nslookup fbcdn-sphotos-b-a.akamaihd.net
;; Truncated, retrying in TCP mode.
;; connection timed out; no servers could be reached

Well, that’s just weird. My DNS server’s running locally… oh wait. A few weeks ago, I’d been messing with host-based firewalls on some of my machines just as a learning exercise. Logging into the DNS server, I showed the firewall rules:

yaleman@dnsbox:~$ sudo ufw status verbose
Status: active
Logging: on (low)
Default: deny (incoming), allow (outgoing)
New profiles: skip

To Action From
-- ------ ----
10.0.0.2/tcp ALLOW IN 10.0.0.13/tcp
10.0.0.2 22/tcp ALLOW IN Anywhere
10.0.0.2 53/udp ALLOW IN Anywhere
10.0.0.2 123/udp ALLOW IN Anywhere
10.0.0.2 5678/udp ALLOW IN Anywhere

Well, look at that, I’d been blocking TCP DNS requests on port 53. I’ll fix that right up:

yaleman@dnsbox:~$ sudo ufw allow 53/tcp

And instantly, everything worked!

none-2:~ yaleman$ nslookup fbcdn-sphotos-b-a.akamaihd.net
;; Truncated, retrying in TCP mode.
Server: 10.0.0.2
Address: 10.0.0.2#53

Non-authoritative answer:
fbcdn-sphotos-b-a.akamaihd.net canonical name = fbcdn-sphotos-b-a.akamaihd.net.edgesuite.net.
fbcdn-sphotos-b-a.akamaihd.net.edgesuite.net canonical name = a1402.dspw40.akamai.net.
Name: a1402.dspw40.akamai.net
Address: 173.223.232.35
Name: a1402.dspw40.akamai.net
Address: 173.223.232.42
Name: a1402.dspw40.akamai.net
Address: 173.223.232.51
Name: a1402.dspw40.akamai.net
Address: 173.223.232.58
Name: a1402.dspw40.akamai.net
Address: 173.223.232.59
Name: a1402.dspw40.akamai.net
Address: 173.223.232.64
Name: a1402.dspw40.akamai.net
Address: 173.223.232.67
Name: a1402.dspw40.akamai.net
Address: 173.223.232.72
Name: a1402.dspw40.akamai.net
Address: 173.223.232.74

I really need to keep a changelog of my local stuff, I mess with too many things and a learning history would be sensible 🙂



#dns #fail #Firewalls #Linux