query cache denied

Genco YILMAZ gyilmaz at mw.net.tr
Sat Jan 31 08:22:10 UTC 2004


hi,
I have directed "cache query denied" messages to  file but log file is 
growing in size so rapily.
now it is 35mb
I have seen that many hosts try to query cache repeatedly (e.g  the same 
host sends lots of queries)
even if request denied. Is this normal ? or Could it be a kind of attack  ?

sample output
Jan 31 18:28:24.240 security: client 12.129.205.100#21304: query (cache) 
denied
Jan 31 18:28:28.775 security: client 12.129.205.100#50228: query (cache) 
denied
Jan 31 18:28:29.033 security: client 12.129.205.100#12172: query (cache) 
denied
Jan 31 18:28:29.290 security: client 12.129.205.100#6021: query (cache) 
denied
Jan 31 18:28:34.594 security: client 12.129.205.101#64594: query (cache) 
denied
Jan 31 18:28:34.854 security: client 12.129.205.101#36411: query (cache) 
denied
Jan 31 18:28:35.111 security: client 12.129.205.101#4714: query (cache) 
denied
Jan 31 18:28:35.368 security: client 12.129.205.101#6344: query (cache) 
denied
Jan 31 18:28:39.078 security: client 12.129.205.101#20598: query (cache) 
denied
Jan 31 18:28:39.337 security: client 12.129.205.101#30493: query (cache) 
denied
Jan 31 18:28:44.435 security: client 12.129.205.101#33125: query (cache) 
denied
Jan 31 18:28:44.693 security: client 12.129.205.101#55731: query (cache) 
denied


Sometimes in addition to client requests, DNS servers make query cache .
Why do dns servers make cache queries from my name server ?

My server is close to recursive queries as well.


Yours Sincerely























More information about the bind-users mailing list