> My /var/log/messages shows the following:
>
> Nov 23 09:24:56 firewall diald[2346]: Trigger: udp 192.168.0.100/61265
>207.198.253.36/53
>
> Port 53 is for name server querying and the 207.x.x.x address is my ISP
> nameserver. The 192.x.x.x address is the remote address I specified to
> diald as the placeholder address. I have no idea was port 61265 is about.
> My local named did not make any entries in my messages log. BTW I think
> that the same thing happens when my win98 systems reboot too.
The high port number (>61000) indicates a masqueraded connection. If you do a netstat
-Mn immediately after this entry appears in messages, you'll see the IP address of the
client doing the DNS query. named always logs the port number it uses to query other
name servers, and it's always below 61000.
Hope this helps...
Beat Bolli
--
dware design & software GmbH
Mattenstrasse 11, CH-2555 Br�gg b. Biel
Telefon: +41 (32) 374 27 00, Telefax: +41 (32) 374 27 01
E-Mail: [EMAIL PROTECTED]
-
To unsubscribe from this list: send the line "unsubscribe linux-diald" in
the body of a message to [EMAIL PROTECTED]