Its an interesting alert as all my devices should be using my DC for DNS which then forwards the request out to OpenDNS.
However, all my android devices are making a direct connection to Google's DNS servers. Not best pleased they seem to be bypassing my DHCP scope settings.
As such I've actually put a block in to Google DNS from inside my network. Hope this won't affect the devices but not best pleased this is happening. I'm more annoyed at google than I was at getting the alerts!
Odd how an issue like this can identify things you're not expecting!
All afternoon my Advanced Threat Protection has been emailing me:
Advanced Threat Protection
A threat has been detected in your network The source IP/host listed below was found to communicate with a potentially malicious site outside your company.
Antes de esto tuve transito masivo por mi DNS esto esta relacionado con ello, tengo varias maquinas que hacen estos llamados, alguien sabe que sucede.
Gracias
regards
Before this I had my DNS mass transit, this is related to this, I have several machines that make these calls, anyone knows what happens.
thanks