portscan 32842:6100?

From: Jim Patterson (jim_patterson@attbi.com)
Date: 12/20/02

From: Jim Patterson <jim_patterson@attbi.com>
Date: Fri, 20 Dec 2002 15:23:56 GMT

I set up a system with ipchains and start logging everything and noticed
traffic between the firewall and ISP DNS. On the DNS side the port used
stays at 53 but on the firewall side the port changes from 32841 to
61000 (consecutively going up 16 ports per second). I would say that I
am getting a scan from the DNS server but the communication appears to
be originating from my firewall.

Is this legitimate traffic? (Is this supposed to be happening?)
Using RH7.3.

I also have a friend that set up a firewall using 7.3, who had problems
with the log file filling his hard drive. He noticed that 99% of the
traffic was almost a continuous commumication with his ISP's DNS
server. I don't think he ever saw or noted that the ports kept changing

Any ideas on what is happening?

Relevant Pages

  • Website setup questions.
    ... Create firewall rule to direct HTTP port 80 to the SBS External NIC ... Create firewall rule to point DNS port 53 to the SBS External NIC ... NICS to get this request to not timeout or be refused. ...
  • Re: Bind as cache DNS and firewall
    ... I'm using Bind as a cache DNS for a public network. ... As it's UDP I think of UDP queries going from my cache server to other DNS server, and I catch their UDP responses in the firewall. ... So I should open my firewall for UDP on port 53 for all the world? ...
  • Re: DNS Server set to forwarder randomly going out to root servers
    ... We implemented the EDNS0 change to no avail. ... The firewall is actually acting as a caching DNS server. ...
  • Re: Can Not Ping By Name
    ... >>> Make sure there's no firewall packaged with the VPN client. ... >>DNS server is the same physical server as the Exchange, ... > Network problem solving - general advice: ...
  • Re: dns server behind a firewall?
    ... > cause I wanted to be sure about the server IP switching. ... Your DNS will be down during switchover ... No. Doublecheck that the DNS server allows queries on all ... >>> firewall and want me to do the job, thats why I m posting again. ...