Hi All,
We don't have a firewall and is just relying on Access-list on our border router. After i applied the new access-list I am continously receiving the logs showed below. The destination IP is our mail server (and its not running any DNS service) and I'm suspicious as to the pattern on the source port and destination port udp 53, however I am not aware of any trojan or worm using the below. I already tried searching google but cannot find the explanation... Please help.
PS;
I am continuosly monitoring these denied packets as continously hitting for the past 3 days now...
--logs starts here---
Jun 4 04:36:48.867 denied udp XX7.Y3.71.242(54067) -> XX3.Y1.246.66(53), 1 packet
Jun 4 04:37:07.556 denied udp XX7.Y3.71.242(54070) -> XX3.Y1.246.66(53), 1 packet
Jun 4 04:37:26.496 denied udp XX7.Y3.71.242(53967) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:37:45.120 denied udp XX7.Y3.71.242(53972) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:38:03.744 denied udp XX7.Y3.71.242(53979) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:38:07.888 denied udp XX7.Y3.71.242(53989) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:38:22.704 denied udp XX7.Y3.71.242(54003) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:38:41.380 denied udp XX7.Y3.71.242(53982) -> XX3.Y1.246.66(53), 34 packets
Jun 4 04:39:00.132 denied udp XX7.Y3.71.242(54009) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:39:18.904 denied udp XX7.Y3.71.242(54027) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:39:33.772 denied udp XX7.Y3.71.242(54035) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:39:37.616 denied udp XX7.Y3.71.242(54042) -> XX3.Y1.246.66(53), 2 packets
We don't have a firewall and is just relying on Access-list on our border router. After i applied the new access-list I am continously receiving the logs showed below. The destination IP is our mail server (and its not running any DNS service) and I'm suspicious as to the pattern on the source port and destination port udp 53, however I am not aware of any trojan or worm using the below. I already tried searching google but cannot find the explanation... Please help.
PS;
I am continuosly monitoring these denied packets as continously hitting for the past 3 days now...
--logs starts here---
Jun 4 04:36:48.867 denied udp XX7.Y3.71.242(54067) -> XX3.Y1.246.66(53), 1 packet
Jun 4 04:37:07.556 denied udp XX7.Y3.71.242(54070) -> XX3.Y1.246.66(53), 1 packet
Jun 4 04:37:26.496 denied udp XX7.Y3.71.242(53967) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:37:45.120 denied udp XX7.Y3.71.242(53972) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:38:03.744 denied udp XX7.Y3.71.242(53979) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:38:07.888 denied udp XX7.Y3.71.242(53989) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:38:22.704 denied udp XX7.Y3.71.242(54003) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:38:41.380 denied udp XX7.Y3.71.242(53982) -> XX3.Y1.246.66(53), 34 packets
Jun 4 04:39:00.132 denied udp XX7.Y3.71.242(54009) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:39:18.904 denied udp XX7.Y3.71.242(54027) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:39:33.772 denied udp XX7.Y3.71.242(54035) -> XX3.Y1.246.66(53), 2 packets
Jun 4 04:39:37.616 denied udp XX7.Y3.71.242(54042) -> XX3.Y1.246.66(53), 2 packets