Results 1 to 6 of 6
  1. #1
    Untanglit
    Join Date
    Aug 2010
    Posts
    27

    Default Misidentified DNS Traffic

    First of all thanks for the awesome product. It is working well now that I have a box that can handle the modules I want to use.

    Protocol Control is identifying some DNS traffic as other protocols.
    My DHCP scope has the following statement for DNS servers:
    option domain-name-servers 4.2.2.1, 8.8.8.8, 208.67.222.222, 8.8.4.4, 68.87.85.98;

    Port 53 (DNS) is being misidentified on occasion as:
    (S)NTP, NBNS, STUN, World of Warcraft & X Windows Version 11
    (S)NTP was by far the most misidentified.

    Here is a bit of the log:
    Code:
    9/20/2010 5:03	PC1	(S)NTP			FALSE	208.67.222.222	53
    9/20/2010 9:03	PC2	(S)NTP			FALSE	8.8.8.8		53
    9/20/2010 11:13	PC2	STUN			FALSE	68.87.85.98	53
    9/20/2010 11:17	PC3	(S)NTP			FALSE	68.87.85.98	53
    9/20/2010 14:09	PC4	X Windows Version 11	FALSE	4.2.2.1		53
    9/20/2010 17:52	PC4	World of Warcraft	FALSE	4.2.2.1		53
    9/20/2010 20:29	S1	NBNS			FALSE	8.8.4.4		53
    I am not noticing any issues with internet access.
    There are 11 kinds of people in the world, those who know binary, those who don't, & those who think they do.

    Proud member of America’s most distrusted minority!!

  2. #2
    Untangler jcoffin's Avatar
    Join Date
    Aug 2008
    Location
    Sunnyvale, CA
    Posts
    2,633

    Default

    Procotol uses packet signatures to flag or block on all ports. To avoid this extra logging, change port 53 to bypass the UVM by using bypass rules in Networking.

  3. #3
    Untanglit
    Join Date
    Aug 2010
    Posts
    27

    Default

    sounds good.
    thanks for the fast reply
    There are 11 kinds of people in the world, those who know binary, those who don't, & those who think they do.

    Proud member of America’s most distrusted minority!!

  4. #4
    Untangle Ninja dwasserman's Avatar
    Join Date
    Jun 2008
    Location
    Argentina
    Posts
    3,965

    Default

    Can be a security issue bypass port 53 from inside. What if the protocol control work well and is blocking some DNS attack from inside to DNS servers?

    Im in the 11´s kind of people, the paranoic
    The world is divided into 10 kinds of people, who know binary and those not

  5. #5
    Untanglit eth><'s Avatar
    Join Date
    Sep 2010
    Posts
    29

    Default

    Quote Originally Posted by Giljorak View Post
    First of all thanks for the awesome product. It is working well now that I have a box that can handle the modules I want to use.

    Protocol Control is identifying some DNS traffic as other protocols.
    My DHCP scope has the following statement for DNS servers:
    option domain-name-servers 4.2.2.1, 8.8.8.8, 208.67.222.222, 8.8.4.4, 68.87.85.98;

    Port 53 (DNS) is being misidentified on occasion as:
    (S)NTP, NBNS, STUN, World of Warcraft & X Windows Version 11
    (S)NTP was by far the most misidentified.

    Here is a bit of the log:
    Code:
    9/20/2010 5:03	PC1	(S)NTP			FALSE	208.67.222.222	53
    9/20/2010 9:03	PC2	(S)NTP			FALSE	8.8.8.8		53
    9/20/2010 11:13	PC2	STUN			FALSE	68.87.85.98	53
    9/20/2010 11:17	PC3	(S)NTP			FALSE	68.87.85.98	53
    9/20/2010 14:09	PC4	X Windows Version 11	FALSE	4.2.2.1		53
    9/20/2010 17:52	PC4	World of Warcraft	FALSE	4.2.2.1		53
    9/20/2010 20:29	S1	NBNS			FALSE	8.8.4.4		53
    I am not noticing any issues with internet access.
    i got the same issue 2 days ago, discover it in the rapports yesterday.

    maybe a new sort of scan or bad traffic through port 53
    in the past i noticed a similar issue on port 53 with socks5 and not DNS indent.
    Would be very interesting to find out what exactly's behind that kind of issues
    Last edited by eth><; 09-28-2010 at 08:08 AM.

  6. #6
    Untanglit eth><'s Avatar
    Join Date
    Sep 2010
    Posts
    29

    Default

    http://www.abuse.ch/?p=2796

    i hope, it is not this one

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2