I'm seeing some strange UDP activity.
Seeing stuff like this :
UDP out xxxx :12105 in yyyy:12105 idle 0:00:46 flags D
UDP out xxxx :14133 in yyyy:14133 idle 0:00:37 flags D
UDP out xxxx :13290 in yyyy:13290 idle 0:00:36 flags D
xxxx = ISP DNS server
yyyy= Internal DNS
Appears to be DNS queries, but is this normal?
Does the PIX perform a fix up on out bound UPD ?
I would expect to see port 53 on the xxxx side ?
Help
-Danny
dan@snoboarder.net
Seeing stuff like this :
UDP out xxxx :12105 in yyyy:12105 idle 0:00:46 flags D
UDP out xxxx :14133 in yyyy:14133 idle 0:00:37 flags D
UDP out xxxx :13290 in yyyy:13290 idle 0:00:36 flags D
xxxx = ISP DNS server
yyyy= Internal DNS
Appears to be DNS queries, but is this normal?
Does the PIX perform a fix up on out bound UPD ?
I would expect to see port 53 on the xxxx side ?
Help
-Danny
dan@snoboarder.net