Strange DNS Queries from my DNS server
I have logged some strange DNS traffic [queries] in my Juniper 5GT firewall. The traffic originates from the same IP and PORT that regular DNS queries are comming from but they are pointed to a completely other set of DNS servers on the internet. I have my windows 2003 server setup to prevent DNS cache pollution. I dont accept DNS queries from outside my local subnet. When my server cant find a name he forwards the request to my ISP dns's And if that fails the roothints take over. I dont see anything strange in my DNS events, I have even enabled DNS Debug info but I can't find the culprit Here are some DNS server my Server queries 209.66.91.13 209.130.187.10 206.165.6.10 64.212.106.87 67.17.215.134 66.231.188.181 66.231.188.229 209.130.187.10 202.96.209.5 216.104.96.11 216.104.96.10 192.5.6.32 61.0.0.5 80.255.35.180 Stay tuned for more info! DNS , Firewall , Cache Pollution , Security