search cancel

Dig or NSlookup failed with fatal error unknown address family

book

Article ID: 229815

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

Nslookup or dig command failed when the WSS agent is enabled. however, It works after disabling the WSS agent.

bash-3.2$ /usr/bin/nslookup apple.com
/System/Volumes/Data/SWE/macOS/BuildRoots/220e8a1b79/Library/Caches/com.apple.xbs/Sources/bind9/bind9-57.5/bind9/lib/isc/sockaddr.c:427: fatal error: unknown address family: 0
Abort trap: 6

Environment

  • WSS Agent 7.2.1+
  • macOS Big Sur 11.6.2

Cause

In the macOS system logs, we observed that the macOS fails to handle the DNS request:

  • The WSS agent passing the DNS request back to the OS for handling.
  • The WSS agent snooped the request to get IP information about the domain.
  • The macOS kernel failed to append the data.
  • The WSS agent closes the UDP flow with error (null) as the kernel failed to append the data. See the screenshot below.

 

Resolution

It has been determined that the issue is with macOS Big Sur. Testing showed the following:

  • WSS Agent 7.5.1 in Big Sur 11.6.2 - DNS lookup failed.
  • WSS Agent 7.5.1 in Monterey 12.01 - DNS lookup were successful .

If you would like to get this fix backported to macOS Big Sur. I would suggest opening a bug report here with an attached sysdiagnose while the issue is taking place.

Install the following debug profiles before you take a sysdiagnose and reproduce the issue:

  • Network Diagnostics
  • Net-diagnose
  • mDNSResponder

Note the time and date the issue occurred on your Bug Report and provide this information to Apple Care.

Attachments