On Fri, Mar 22, 2002 at 10:38:51AM -0500, Mike McCandless wrote:

>  I am using RH 7.2, w/ IPTABLES 1.2.4.  About twice a day, I see traffic destined 
>for port 53, using UDP, always length 53 from some of the following addresses:
> 
> 65.203.232.2,
> 203.197.173.129,
> 202.54.111.72,
> 209.240.77.130
> 
> I see these because they don't match any firewall rules and get logged.  Are these 
>port scans or legitimate traffic?

What's the originate port? Are you running an authoritative dns server
for a zone? If (53, yes) then it's legitimate.

Ramin

> 
> 
> --------------------------------------------------------
> Mike McCandless
> [EMAIL PROTECTED]

Reply via email to