Daily IT Matters, this is the place where I post my daily findings on IT.

Wednesday, February 28, 2007

Strange DNS Queries from my DNS server

I have logged some strange DNS traffic [queries] in my Juniper 5GT firewall.
The traffic originates from the same IP and PORT that regular DNS queries are comming from but they are pointed to a completely other set of DNS servers on the internet.

I have my windows 2003 server setup to prevent DNS cache pollution.
I dont accept DNS queries from outside my local subnet.
When my server cant find a name he forwards the request to my ISP dns's
And if that fails the roothints take over.

I dont see anything strange in my DNS events, I have even enabled DNS Debug info but I can't find the culprit

Here are some DNS server my Server queries

  1. 209.66.91.13
  2. 209.130.187.10
  3. 206.165.6.10
  4. 64.212.106.87
  5. 67.17.215.134
  6. 66.231.188.181
  7. 66.231.188.229
  8. 209.130.187.10
  9. 202.96.209.5
  10. 216.104.96.11
  11. 216.104.96.10
  12. 192.5.6.32
  13. 61.0.0.5
  14. 80.255.35.180

Stay tuned for more info!

No comments:

Google