Snort mailing list archives

Re: DNS question


From: mosquitooth () gmx net
Date: Wed, 6 Apr 2005 23:08:33 +0200 (MEST)

Thanks for replying to everyone!

Now,

- the Windows DNS server is not running (only client)
- of course, the server is configured to use the ISPs DNS servers (by DHCP)
and when I e.g. open www.google.com it does contact these servers for name
resolution.
- These connections to root servers are not used to do any dns resolution -
just tcp handshakes and graceful closes.
- I've added some ethereal logs to this mail...maybe this does enlighten the
whole lot.

Greetings,

Peter


mosquitooth () gmx net wrote:

But, I've had some strange experience when I recently ran TcpView
(www.sysinternals.com) and ethereal. My Win2k3 server (the one I
mentioned
above) connects to the root servers (e.g. 'l.root-servers.net:domain').
I cannot see any reason why this should happen - or did I get something
wrong during my DNS lessons?
 

From the sounds of it, your Win2k3 server is acting as it's own DNS
resolver. Check your services to see if you've got Microsoft's DNS
server running on it.



-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


-- 
Sparen beginnt mit GMX DSL: http://www.gmx.net/de/go/dsl

Attachment: dnslog
Description:


Current thread: