RE: OT: Tool to identify Evaluate DNS clients?

  • From: "PESA Postmaster" <isalist@xxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Tue, 17 Aug 2004 08:50:53 -0500

Packet sniffer?

PESA Postmaster

----- Original Message ----- 
From: William Robertson
To: [ISAserver.org Discussion List]
Sent: Tuesday, August 17, 2004 8:36 AM
Subject: [isalist] RE: OT: Tool to identify Evaluate DNS clients?


http://www.ISAserver.org

Hmmm, tried to avoid saying that... what I am seeing is that my internet
link is saturated with outbound DNS requests. In my Firewall Logs I can only
see my 2 DNS servers as doing the requests for outbound DNS queries, which
is the way it is meant to be...

But what I am presuming is that some client workstation is
generating/causing a helluva lot of DNS requests, either via directly
contacting my DNS Server, or by requesting Port 80 traffic which will then
route via my Firewall to my DNS Server, and then back through my firewall.

So I was hoping to tackle the easier scenario first, and hoping to generate
some sort of realtime/historical report which will show me the "Top
Requesters" for DNS resolution against my DNS Servers...

Is there something like this?





Other related posts: