|
|||||||||||
|
Re: strange traffic on UDP port 53
From: Anders Reed Mohn <anders_rm(at)utepils.com>
Date: Thu Jun 12 2003 - 04:39:50 EDT > 1. Using the same src_IP:port# to dst_IP:port# (as earlier provided) it
Smells of a faulty DNS-setup, and of faulty routing. Some machine out there thinks you have the DNS for 1.1.192.in-addr.arpa, and is trying to resolve 48.1.1.192.in-addr.arpa through you. At least, that's a scenario I have seen a few times. This could be just a typo in an SOA or in the DNS-address specified on a specific computer. I addition, someone didn't get their routing right, 'cuz traffic to and from 242.x.x.x should not be routed to the Internet, AFAIK.
Cheers,
Received on Thu Jun 12 13:55:40 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:09 EDT |
||||||||||
|
|||||||||||