Hello all,
I recently configured DNS servers on our two GB-1000 boxes. One of your ISP's had
been doing the DNS hosting for us. Now, we are doing our own DNS hosting with the
GB-1000 boxes.
Below are three examples of packets that are being sent to the GB-1000. I have no idea
why we're getting them. In every case, the source port is 53 and the destination port
is 1585. Doing a reverse IP address lookup reveals these messages are coming from root
servers. And we get a lot of these messages.
Can anybody tell me what it means?
Thanks in advance.
IP PACKET: UDP [192.41.162.30/53]-->[x.x.x.x/1585] l=282
l.gtld-servers.net
IP PACKET: UDP [192.35.51.30/53]-->[x.x.x.x/1585] l=284
f.gtld-servers.net
IP PACKET: UDP [202.12.27.33/53]-->[x.x.x.x/1585] l=96
m.root-servers.net