17 ms·
After reading their explanation, I don't understand the purpose of 1e100.net. Maybe someone who is more technical than I am can explain how it is used to identi
by EarthIsHome 8y ago
After reading their explanation, I don't understand the purpose of 1e100.net. Maybe someone who is more technical than I am can explain how it is used to identify Google's servers and why that's useful.
On that note, I should answer their question: Was this article helpful? with No.
- Pharaoh2 8y agoIts the domain name they use for their servers. Its generally a good practice to have a dns name that maps to a particular server apart form the website its supposed to be serving for administrative purposes. Try this: > dig google.com ;; ANSWER SECTION: google.com. 299 IN A 172.217.164.110 > nslookup 172.217.164.110 Non-authoritative answer: 110.164.217.172.in-addr.arpa name = sfo03s18-in-f14.1e100.net.
- aviau 8y agothey use subdomains of 1e100.net as names in their network
- cpeterso 8y agoI don't see any requests to 1e100.net when loading Google sites like google.com or youtube.com. I see domains like gstatic.com and apis.google.com, but but not 1e100.net.
- yebyen 8y agoTry a reverse lookup yebyen:~$ host google.com google.com has address 172.217.10.46 google.com has IPv6 address 2607:f8b0:4006:803::200e ... yebyen:~$ host 172.217.10.46 46.10.217.172.in-addr.arpa domain name pointer lga34s13-in-f14.1e100.net.
- forgottenpass 8y agoYou wouldn't. Multiple domain names can point to the same IP address. Any one IP address can only have one reverse (PTR) record.
- TimTheTinker 8y agoYou can think of all user-facing domains in a system as an interface or API, which abstracts away implementation details about which specific servers are behind them. This allows flexibility in infrastructure — you can swap machines in and out (e.g. by updating public DNS records, updating the machines’ IP addresses, or adding them to (or removing them from) a load balanced pool behind a reverse proxy). But you still need a way to reference individual machines regardless of whether they’re serving or not. That’s where domains like 1e100.net come in — a system of concrete (non-abstract) references to specific machines in your infrastructure.
- Buge 8y ago$ ping google.com PING google.com (172.217.7.206) 56(84) bytes of data. 64 bytes from iad30s10-in-f14.1e100.net (172.217.7.206): icmp_seq=1 ttl=48 time=0.676 ms
- walrus01 8y agoIt's good practice to have working reverse DNS for all of your public IP space. Using a short domain name is convenient. There are a number of ISPs that own their AS number as a domain such as as12345.net and use that for their rDNS, so it will show up nicely in traceroutes either direction. Google has done something a little bit different here, it's not their AS number, but same general concept.
- amenghra 8y agoGoogle is big enough they own/need several ASNs. Having a dedicated domain totally makes sense.
- peterwwillis 8y agoIt's to provide a domain name when you query the reverse DNS address of an IP.
- stingraycharles 8y agoFor normal purposes, DNS translates domain names into IP addresses (e.g. youtube.com to one of Google’s IPs). However, you can also do it the other way around: a reverse DNS lookup where you ask the associated domain name of an IP address. Google decided to let all their IPs return a reverse DNS lookup under the 1e100 domain name. It makes things simpler when you want to figure out who’s connecting to your servers, for example.
- vxNsr 8y ago>It makes things simpler when you want to figure out who’s connecting to your servers, for example. Why? Or rather I guess, How does it make things simpler?
- ninkendo 8y agoTheir infrastructure probably allows them to host multiple products in the same subnet, it's possible any given (IP belonging to a) physical host could be hosting a youtube API one minute, google search next, gmail the next. So they picked a subdomain that belongs to none of these, to eliminate any confusion.
- vxNsr 8y agoI thought the "who" was referring to users, but you're saying it's referring to different google services, is that right?
- Lan 8y agoConsider a scenario where you have a log file and in the log file is an IP address (172.217.5.14). You are not sure whose IP address it is. So you run the following commands: # dig -x 172.217.5.14 +short lga15s49-in-f14.1e100.net. ord38s19-in-f14.1e100.net. # dig lga15s49-in-f14.1e100.net. +short 172.217.5.14 # dig lga15s49-in-f14.1e100.net. +short 172.217.5.14 The first command (dig -x) checks the PTR record for the IP address 172.217.5.14. It returns two PTR records: lga15s49-in-f14.1e100.net. and ord38s19-in-f14.1e100.net.[0]. Those are subdomains of 1e100.net, which we know Google owns. However, you can set a PTR to pretty much whatever you want, so we now take an additional step as well. We run the dig command again to check the A records for the domains. This returns the same IP address we started with, which is good. Since Google controls the DNS for 1e100.net we can be reasonably sure that it is in fact a Google server. This is called Forward-confirmed reverse DNS (FCrDNS) and is one tool you can use to determine the ownership of an IP address. For example, it is frequently used as a weight in email spam filters. Although, because of the intricacies of email, in that case it is usually not used for identification and instead used as a general purpose check to determine whether a mail server is rogue or not, since spam servers very often do not have proper FCrDNS. There are other tools to determine who owns an IP address, like whois, but in some instances one will garner useful information and the other will not. So it's nice to have both at your disposal. [0] As a side note: the trailing . in those PTR records returned by dig is not a typo. All domains actually end in a dot, it's just usually implied.
- tlb 8y agoServers need a name that's different from the product(s) they're serving. For example, when I look up google.com and then reverse-lookup the IP address, I get sfo07s13-in-f14.1e100.net (you'd get something different depending where you are). The name sfo07s13-in-f14 could tell someone where to look if that machine is misbehaving. If they'd named it sfo07s13-in-f14.google.com, then browsing to that URL sends google cookies. If it's some server from a recent acquisition that may not be up to Google's level of security, that's dangerous. Even fairly small companies are well-advised to have a domain name for their brand and a separate domain name for their infrastructure.
- EarthIsHome 8y agoSo, for example, the domain google.com points to the domain sfo07s13-in-f14.1e100.net (depending on where you're browsing) which then points to an IP address of the server that's serving you the content. google.com -> subdomain.1e100.net -> server IP address Then when you run a reverse DNS on the IP address, you get sfo07s13-in-f14.1e100.net. rDNS: server IP address -> subdomain.1e100.net So, like you said, if something is wrong with the server, you can run a reverse DNS on the IP address to get the subdomain sfo07s13-in-f14.1e100.net. Is this the correct understanding? But don't you already have the IP address of the misbehaving machine?
- tlb 8y agoYes. The name sfo07s13-in-f14 is mnemonic to Google engineers -- it's probably in San Francisco data center 7. Also, that server probably has both an IPv4 and IPv6 address. Also, sometimes IP addresses change but you want servers to keep their identity. So names are convenient.
- peterwwillis 8y agoLots of people look at IP addresses. Most of the people who find the "1e100.net" records in their network logs would have no easy way of knowing that 1.2.3.4 (or whatever) was a Google IP. The reverse lookup allows you to easily find out what domain it belongs to (1e100.net, which a Google search shows is a Google address). You can also embed other information in the reverse name, such as the region, datacenter, floor, switch, rack, or unit number of the machine. It can be incredibly easy to locate the machine by just looking at its reverse name. "Oh, 1.2.3.4 is in us-east-1, on floor 3, in rack 27, unit 5. Let me go check the network cable."