On Thu, 2003-07-24 at 10:27, Bill.Light@kp.org wrote:> I just returned from a vacation, and noticed that since I''ve been
gone,
> I''m getting about 100 of these a day. Anybody have any ideas ?
Why
> would Microsoft be looking for name services from me ? This is my 3-NIC
> firewall box and it runs no DNS anyway. I''m showing the entire
207.42.x.x
> belongs to Microsoft ... Anyone else experiencing this ? They seem to
> occur regardless if anyone in the house is using any computer.
>
> Jul 23 18:01:08 mycomputer kernel: Shorewall:net2all:DROP:IN=eth0 OUT=
> MAC=00:03:47:48:77:8d:00:10:67:00:b1:86:08:00 SRC=207.46.150.13
> DST=my.real.internet.ip LEN=73 TOS=0x00 PREC=0x00 TTL=49 ID=27058
> PROTO=UDP SPT=22875 DPT=53 LEN=53
>
I''ve seen this with "Automatic Updates" when there was no
reverse DNS
mapping for the PC''s IP address -- as a final resort, a DNS query is
sent to the box itself in an apparent attempt to obtain a DNS name.
-Tom
--
Tom Eastep \ Shorewall - iptables made easy
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net