DNS port requests

Robert D. Holtz - Lists robert.d.holtz at gmail.com
Wed Sep 6 22:22:37 UTC 2006


I'm guessing that this is the source port for the client ip in the exchange.

-----Original Message-----
From: bind-users-bounce at isc.org [mailto:bind-users-bounce at isc.org] On Behalf
Of Rasheed Darras
Sent: Wednesday, September 06, 2006 5:18 AM
To: bind-users at isc.org
Subject: RE: DNS port requests

What the meaning of these requests? Why a customer query my DNS for
"port=xxxx" ???

Rasheed 

-----Original Message-----
From: bind-users-bounce at isc.org [mailto:bind-users-bounce at isc.org] On Behalf
Of Kevin Darcy
Sent: Tuesday, September 05, 2006 11:12 PM
To: bind-users at isc.org
Subject: Re: DNS port requests

Rasheed Darras wrote:
> Dears,
>
> If I captured DNS packets using snoop, I found many requests like:
>
> "Customer IP" > "My DNS IP" DNS C port=16931 "Customer IP" > "My DNS 
> IP" DNS C port=16932 "Customer IP" > "My DNS IP" DNS C port=2949 
> "Customer IP" > "My DNS IP" DNS C port=16931 "Customer IP" > "My DNS 
> IP" DNS C port=16932 "Customer IP" > "My DNS IP" DNS C port=16932 
> "Customer IP" > "My DNS IP" DNS C port=16932 "Customer IP" > "My DNS 
> IP" DNS C port=16932 "Customer IP" > "My DNS IP" DNS C port=31864 
> "Customer IP" > "My DNS IP" DNS C port=31875 "Customer IP" > "My DNS 
> IP" DNS C port=2949
>
> What are these requests?
>   
Since they're coming to the "DNS" (53) port on your DNS server, I'd assume
they were DNS queries.

Or, do you consider this traffic unusual in some way?

- Kevin






More information about the bind-users mailing list