This thread was automatically locked due to age.
HI Alex,
Thank you for the PCAP , Could you share the logs from the reports that were detected? That should help us analyze the logs.
As for the port you may use console>tcpdump filedump verbose count 10000 'port 53 -s0 #where 53 is the port address you would monitor for DNS queries.
Hi guys,
I put my XG on line again after adding VLANs and VoIP phones.
I think you are looking at the wrong place for the DNS errors. My XG is reporting DNS errors for port 53, IMAPS and a host of other ports.
I have included the daily report, it show the attacking servers as being my ISP DNS. I will change the DNS and see if that reduces the attack reports.