On Fri, Mar 22, 2002 at 10:38:51AM -0500, Mike McCandless wrote: > I am using RH 7.2, w/ IPTABLES 1.2.4. About twice a day, I see traffic destined >for port 53, using UDP, always length 53 from some of the following addresses: > > 65.203.232.2, > 203.197.173.129, > 202.54.111.72, > 209.240.77.130 > > I see these because they don't match any firewall rules and get logged. Are these >port scans or legitimate traffic?
What's the originate port? Are you running an authoritative dns server for a zone? If (53, yes) then it's legitimate. Ramin > > > -------------------------------------------------------- > Mike McCandless > [EMAIL PROTECTED]
