> It seems that BIND 8.2.4 is not using ephemeral ports but rather uses
> 1745. I did not configure this in named.conf. Is this normal
> operation?

Did you restart BIND? As BIND will bind to a port in the
anonymous port range for your IP stack and just use it by
default AFAIK.

You can of course specify what ports you'd like BIND to use in
named.conf, but making assumptions about packet content based on
source port's above 1023 is never going to work 100%.

