LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 03-25-2012, 04:30 PM   #1
krazybob
Member
 
Registered: Oct 2009
Location: Los Angeles, CA
Distribution: Centos 5.x
Posts: 133

Rep: Reputation: 3
DNS Calls Blocked by Firewall


I have a Watchguard X8000 Peak firewall (excellent hardware!)

I have call after call to port 53 that are outbound. I switched to OpenDNS and line after line after line now shows me xxx.xxx.xxx.xxx 208.67.222.222 dns/udp 1-Trusted 0-External denial of service attack, drop this packet.

Looking at the actual three servers (out of over 100( only these three servers exhibit this problem. It appears that Webalyzer may be trying to do a hostname lookup but turning this off doesn't appear to be an option as it is with AWStats. Previously I had resolv.conf set for Level 3 4.2.2.1 and 4.2.2.2. My own firewall is block listing me!!!

I have resolv.conf set for

Code:
search priorityonehost.net
nameserver 208.67.222.222
nameserver 207.67.220.220
Each server has a unique name based on the customer but you get the idea.

I don't know if the DNS filter on the Watdchguard X8000 is supposed to be proxied or just a policy.

Any thoughts on what is going on? This began when I switched these servers to Plesk 9.3

Humbly Yours,

Bob
 
Old 03-27-2012, 01:16 AM   #2
Slackyman
Member
 
Registered: Mar 2011
Location: Rome - Italy
Distribution: Slackware 13.1
Posts: 347

Rep: Reputation: 44
One fast solution could be to set up DNSs directly on the Watchguard and use the Watchguard as unique DNS, but even if this will solve your issue you'll never know why you were having it!
I look on the Internet and found
http://forums.opendns.com/search.php...nSubmit=Search
It seems that the DNS response from OpenDNS can be interpreted as a port scan, a flood attack or other kind of DoS attack.
 
Old 03-27-2012, 09:29 AM   #3
krazybob
Member
 
Registered: Oct 2009
Location: Los Angeles, CA
Distribution: Centos 5.x
Posts: 133

Original Poster
Rep: Reputation: 3
Thank you except that the Watchguard is showing me attacking them. Web site are doing reverse lookups, I believe through Webalyzer, for better statistics resolution. I don't know how to turn that off o see if I am correct.

The Watchguard X800 Peak is not a DNS server. It is a router/top-end switch. I have 100 servers behind it and it has no way of handling DNS on that level. Only three servers are doing this and I cannot see what is different except that they are Plesk 9.3.
 
Old 03-27-2012, 10:03 AM   #4
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
This can be pursued/corrected on any of several levels, but the easiest is probably to just turn off webalizer's rDNS lookups. A cursory look at this webalizer manpage suggests that it may be possible to do so by omitting the DNSCache directive, and setting the DNSChildren directive to 0.
 
Old 03-27-2012, 10:37 PM   #5
krazybob
Member
 
Registered: Oct 2009
Location: Los Angeles, CA
Distribution: Centos 5.x
Posts: 133

Original Poster
Rep: Reputation: 3
Quote:
Originally Posted by anomie View Post
This can be pursued/corrected on any of several levels, but the easiest is probably to just turn off webalizer's rDNS lookups. A cursory look at this webalizer manpage suggests that it may be possible to do so by omitting the DNSCache directive, and setting the DNSChildren directive to 0.
Thank you. Plesk compiles everything so I'll have to dig a little deeper. I suspected that was th4e solution. With AWStats its and easy fix but if I turns it on the server load goes up considerably during nightly CRONs. Thank you again.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
NFSv4 Being Blocked By Firewall dman777 Linux - Security 2 10-29-2011 11:58 PM
[SOLVED] php includes blocked by firewall fishdink Linux - Security 2 06-18-2009 06:58 PM
NFS blocked by the firewall Tom Douglas Linux - Software 2 06-29-2007 05:49 AM
VPN through firewall with blocked ports Peter1980 Linux - Networking 2 06-03-2005 04:26 AM
Ping Blocked Across Firewall mehargags Linux - Networking 2 01-11-2004 02:15 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 08:43 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration