TechnitiumSoftware/DnsServer · error · InvalidOperationException

Network group map contains an invalid network address

Error message

Network group map contains an invalid network address: {network}

What it means

Thrown while parsing the Dns64App 'networkGroupMap' JSON object. Each key is parsed with NetworkAddress.TryParse expecting a CIDR network; on failure InvalidOperationException is raised during app initialization (the Dns64 app uses InvalidOperationException, like the blocking app, for this check).

Solutions

  1. Correct the 'networkGroupMap' key in dnsApp.config to valid CIDR notation (e.g. '2001:db8::/64', '192.168.0.0/16').
  2. Use '/128' or '/32' for a single host and never include a ':port'.
  3. Put the NAT64 translation prefix in 'dns64PrefixMap', not in 'networkGroupMap'.

Example fix

// before (dnsApp.config)
"networkGroupMap": { "2001:db8::1": "groupA" }
// after
"networkGroupMap": { "2001:db8::/64": "groupA" }
Defensive patterns

Strategy: validation

Validate before calling

foreach (string key in networkGroupMapKeys)
{
    if (!NetworkAddress.TryParse(key, out NetworkAddress _))
        throw new FormatException($"Dns64 'networkGroupMap' key '{key}' is not a valid CIDR network.");
}

Type guard

static bool IsValidCidrKey(string key) => NetworkAddress.TryParse(key, out NetworkAddress _);

Prevention

When it happens

Trigger: Calling the Dns64App initializer with a 'networkGroupMap' key that NetworkAddress.TryParse rejects: a hostname, a bare IP without prefix, a malformed CIDR, or an endpoint with a port.

Common situations: Using a single IPv6 client address without '/128'; pasting '2001:db8::1' instead of the subnet '2001:db8::/64'; CIDR typo; DNS64 NAT64 client prefix mistakenly placed in the network map.

Related errors


AI-assisted analysis of TechnitiumSoftware/DnsServer@d0484b6c1e (2026-08-13). Data as JSON: /api/errors/529016a8ea9360cf. Report an issue: GitHub.

Appendix: source

Thrown at Apps/Dns64App/App.cs:78

        #endregion

        #region public

        public Task InitializeAsync(IDnsServer dnsServer, string config)
        {
            _dnsServer = dnsServer;

            using JsonDocument jsonDocument = JsonDocument.Parse(config, _jsonParseOptions);
            JsonElement jsonConfig = jsonDocument.RootElement;

            _appPreference = Convert.ToByte(jsonConfig.GetPropertyValue("appPreference", 30));

            _enableDns64 = jsonConfig.GetProperty("enableDns64").GetBoolean();

            _networkGroupMap = jsonConfig.ReadObjectAsMap("networkGroupMap", delegate (string network, JsonElement group)
            {
                if (!NetworkAddress.TryParse(network, out NetworkAddress networkAddress))
                    throw new InvalidOperationException("Network group map contains an invalid network address: " + network);

                return new Tuple<NetworkAddress, string>(networkAddress, group.GetString());
            });

            _groups = jsonConfig.ReadArrayAsMap("groups", delegate (JsonElement jsonGroup)
            {
                Group group = new Group(jsonGroup);
                return new Tuple<string, Group>(group.Name, group);
            });

            return Task.CompletedTask;
        }

        public async Task<DnsDatagram> PostProcessAsync(DnsDatagram request, IPEndPoint remoteEP, DnsTransportProtocol protocol, DnsDatagram response)
        {
            if (!_enableDns64)
                return response;

View on GitHub (pinned to d0484b6c1e)