I notice in my logs the following:
[FONT=monospace]/var/log/packetfilter/2012/03/packetfilter-2012-03-13.log.gz:2012:03:13-19:03:02 wahine ulogd[6021]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="eth1" srcmac="0:c:29:67:ac:8e" srcip="174.x.y.z" dstip="128.8.10.90" proto="17" length="76" tos="0x00" prec="0x00" ttl="64" srcport="1901" dstport="53" [/FONT]
Looking at the dstip, I see the following:
Address lookup
canonical name d.root-servers.net. aliases
addresses 2001:500:2d:[:D]
128.8.10.90It looks like this the device blocking access to DNS root servers.
Is that a good thing?
I don't have DNS specific rules in my firewall (save one machine which is off).
In Network Services \ DNS I list Google's DNS servers. [feel free to comment]
Just checking.
This thread was automatically locked due to age.