DNS port requests
Robert D. Holtz - Lists
robert.d.holtz at gmail.com
Wed Sep 6 22:22:37 UTC 2006
I'm guessing that this is the source port for the client ip in the exchange.
-----Original Message-----
From: bind-users-bounce at isc.org [mailto:bind-users-bounce at isc.org] On Behalf
Of Rasheed Darras
Sent: Wednesday, September 06, 2006 5:18 AM
To: bind-users at isc.org
Subject: RE: DNS port requests
What the meaning of these requests? Why a customer query my DNS for
"port=xxxx" ???
Rasheed
-----Original Message-----
From: bind-users-bounce at isc.org [mailto:bind-users-bounce at isc.org] On Behalf
Of Kevin Darcy
Sent: Tuesday, September 05, 2006 11:12 PM
To: bind-users at isc.org
Subject: Re: DNS port requests
Rasheed Darras wrote:
> Dears,
>
> If I captured DNS packets using snoop, I found many requests like:
>
> "Customer IP" > "My DNS IP" DNS C port=16931 "Customer IP" > "My DNS
> IP" DNS C port=16932 "Customer IP" > "My DNS IP" DNS C port=2949
> "Customer IP" > "My DNS IP" DNS C port=16931 "Customer IP" > "My DNS
> IP" DNS C port=16932 "Customer IP" > "My DNS IP" DNS C port=16932
> "Customer IP" > "My DNS IP" DNS C port=16932 "Customer IP" > "My DNS
> IP" DNS C port=16932 "Customer IP" > "My DNS IP" DNS C port=31864
> "Customer IP" > "My DNS IP" DNS C port=31875 "Customer IP" > "My DNS
> IP" DNS C port=2949
>
> What are these requests?
>
Since they're coming to the "DNS" (53) port on your DNS server, I'd assume
they were DNS queries.
Or, do you consider this traffic unusual in some way?
- Kevin
More information about the bind-users
mailing list