Welcome to the most active Linux Forum on the web.
Go Back > Forums > Linux Forums > Linux - Networking
User Name
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.


  Search this Thread
Old 11-23-2005, 11:37 AM   #1
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
Which process is making DNS queries?

Since last night, snort has been picking up a lot of UDP Port unreachable packets directed at our mail server. After watching the server for a little while, I've found that the server is attempting to make a DNS query to a specific IP address. No DNS server operates on that address, so the UDP packet is returend.

My problem is that I can't figure out why its making these queries or why its querying this IP address. My guess is that someone's DNS is not configured properly somewhere, but I can't tell. Whois and reverse lookups on the IP in question don't reveal anything of consequence. There are no messages in the mail queue directed at the domain to which the IP belongs.

How can I determine which process is making these requests?
Old 11-23-2005, 06:31 PM   #2
Registered: Oct 2003
Posts: 568

Rep: Reputation: 31
On a remote machine?
You may try to sniff it.
If you know what machine it is - tcpdump
Old 11-28-2005, 03:30 PM   #3
Registered: Apr 2002
Posts: 498

Original Poster
Rep: Reputation: 30
Originally posted by PenguinPwrdBox
On a remote machine?
You may try to sniff it.
If you know what machine it is - tcpdump
Tried that. That's how I even found out it was a DNS query generating the ICMP packets. AFAICT, tcpdump doesn't tell me anything about the process initiating the request.
Old 11-29-2005, 12:16 AM   #4
Registered: Oct 2003
Posts: 568

Rep: Reputation: 31
That's correct. It won't tell you the process....however, you can use it to troubleshoot which one is....
Old 11-29-2005, 05:05 PM   #5
Registered: Apr 2002
Posts: 498

Original Poster
Rep: Reputation: 30
Originally posted by PenguinPwrdBox
That's correct. It won't tell you the process....however, you can use it to troubleshoot which one is....
So should I repost my OP or wait a while?


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
ipv6 queries to dns peacebwitchu AIX 0 11-10-2005 07:57 PM
DNS IPv6 Queries Fail kawauso-kun Debian 1 01-15-2005 06:31 PM
DNS Queries lcplutz@wincor Linux - Networking 2 06-04-2004 07:59 AM
SQL: making queries from multiple tables ganninu Programming 1 01-08-2004 12:17 PM
Some queries related to DNS(bind) coolamit78 Linux - Networking 1 12-19-2003 04:05 AM > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:38 PM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration