> I found logs of some incoming TCP packets with both source and
> destination ports as 53, on firewall. Actually, the packets are
> destined to our DNS server, but the fact that the source port is
> 53 as well, sounds strange; doesn't it? Is it any incident?
Could be a remote server with 'query-srouce * port 53;' set. Do the
hosts the packets appear to originate from seem suspicious?
Later,
-Mike
--
Eat drink and be merry, for tomorrow they may make it illegal.
_______________________________________________
Firewalls mailing list
[EMAIL PROTECTED]
http://lists.gnac.net/mailman/listinfo/firewalls