I am seeing an extreme amount of outbound traffic from my dns servers (w2k) to outside DNS servers. All on port 1118. I thought DNS usesd Port 53? Can someone post a good link on what the flags mean. Or let me know whats going on here. I have a feeling this is slowing down our internet speed. When I do #sh conn here is part of the output:
UDP out 66.128.96.3:15578 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.3:15613 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.3:7410 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.3:7576 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.3:15744 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.3:15791 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.3:15776 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.4:15791 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.4:15776 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 24.217.0.4:9770 in 192.168.0.7:1118 idle 0:01:15 flags D
UDP out 24.217.0.4:5725 in 192.168.0.7:1118 idle 0:01:11 flags D
UDP out 24.217.0.4:5696 in 192.168.0.7:1118 idle 0:01:14 flags D
UDP out 66.128.96.3:15578 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.3:15613 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.3:7410 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.3:7576 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.3:15744 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.3:15791 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.3:15776 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.4:15791 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 66.128.96.4:15776 in 192.168.0.7:1118 idle 0:00:30 flags dD
UDP out 24.217.0.4:9770 in 192.168.0.7:1118 idle 0:01:15 flags D
UDP out 24.217.0.4:5725 in 192.168.0.7:1118 idle 0:01:11 flags D
UDP out 24.217.0.4:5696 in 192.168.0.7:1118 idle 0:01:14 flags D