Re: Portscan from DNS server?

From: Sven Pran (no.direct@mail.please)
Date: 06/10/02


From: "Sven Pran" <no.direct@mail.please>
Date: Mon, 10 Jun 2002 05:15:45 GMT


"Andrew Norman" <andy@norman.cx> wrote in message
news:l8r7gucuhmhacuel6l9iuehv78rsroaqkm@4ax.com...
> On Sun, 09 Jun 2002 20:56:23 GMT, "Sven Pran" <no.direct@mail.please>
> wrote:
>
> >With an ADSL connection and a DLINK DI-804 router/gateway/firewall
> >between the ADSL modem and my local network I installed the free
> >version of ZoneAlarm to see if it has any merits in addition to DI-804.
> >
> >Apparently yes, it began reporting what appeared to be a portscan
> >(starting with port 1025 and working its way up).
> >
> >A little investigation revealed that the "intruder" was actually the
> >primary DNS server whose address had been obtained by the DI-804
> >from DHCP when I last started my ADSL connection.
> >
> >So now I have some questions:
> >
> >Is there any legitimate reason for DNS to perform a portscan like
> >this?
>
> These are not portscans. These are replies from the DNS server to DNS
> queries you have made. You need to allow TCP/UDP traffic from port 53
> through your firewall for DNS queries to work properly.

Thanks - that sounds reasonable, except that I did not notice any
malfunction (DNS lookup failure) during the hours when ZoneAlarm
reported all such traffic being blocked?

So how do I best configure ZoneAlarm to not bother about this particular
traffic? Temporarily I have added the actual IP addresses to my local
zone, but as the DNS addresses are received from DHCP I believe I
have no guarantee (and should not depend upon) that they might not
change in the future.

Is it safe to open for any and all incoming traffic from port 53 regardless
of IP address?

regards Sven



Relevant Pages

  • Re: Spooler subsystem app accessing DNS
    ... ZoneAlarm controls both incoming and outgoing access. ... I keep getting ZoneAlarm alerts telling me that the ... > Spooler subsystem app is attempting to access my ISP's DNS ...
    (comp.security.firewalls)
  • Re: Spooler subsystem app accessing DNS
    ... ZoneAlarm controls both incoming and outgoing access. ... I keep getting ZoneAlarm alerts telling me that the ... > Spooler subsystem app is attempting to access my ISP's DNS ...
    (alt.computer.security)
  • Re: Spooler subsystem app accessing DNS
    ... ZoneAlarm controls both incoming and outgoing access. ... I keep getting ZoneAlarm alerts telling me that the ... > Spooler subsystem app is attempting to access my ISP's DNS ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: Spooler subsystem app accessing DNS
    ... ZoneAlarm controls both incoming and outgoing access. ... I keep getting ZoneAlarm alerts telling me that the ... > Spooler subsystem app is attempting to access my ISP's DNS ...
    (microsoft.public.win2000.security)
  • Re: Portscan from DNS server?
    ... >>between the ADSL modem and my local network I installed the free ... >>version of ZoneAlarm to see if it has any merits in addition to DI-804. ... >>primary DNS server whose address had been obtained by the DI-804 ...
    (comp.security.firewalls)

Quantcast