> I found logs of some incoming TCP packets with both source and
> destination ports  as 53, on firewall. Actually, the packets are 
> destined to our DNS server, but  the fact that the source port is 
> 53 as well, sounds strange; doesn't it? Is it any incident?

Could be a remote server with 'query-srouce * port 53;' set.  Do the
hosts the packets appear to originate from seem suspicious?

Later,
-Mike

--
 Eat drink and be merry, for tomorrow they may make it illegal.

_______________________________________________
Firewalls mailing list
[EMAIL PROTECTED]
http://lists.gnac.net/mailman/listinfo/firewalls

Reply via email to