Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 288
  • Last Modified:

"Denied Recursion" messages in firewall log

We recently put all our servers behind a firewall (an Instagate EX2 to be exact).  We have a few web servers, a mail server, and a DNS server running Simple DNS Plus.  I've set up all the policies and everything seems to be working fine except one thing.

Our firewall logs are HUGE and 99% of it is the same message over and over again:
"denied recursion for query from [69.18.166.34].1031 for svr5.erh.noaa.gov IN"
that IP address "69.18.166.34" is the external IP of our DNS server.

Does anybody know what this message means?  What causes it?  If there's anything we can do to stop it?  We go through periods where this message comes up about 50 times per second!

If it helps: Noaa.gov is a weather server that our webservers (using cold fusion) grab weather from to display on webpages.  Those weather pages are working fine despite this repeated message.
0
noreastnerd
Asked:
noreastnerd
1 Solution
 
daJmanCommented:
I suspect your DNS server config. Try this:

In the Options menu in DNS Server Plus remove the IP range listed under "Offer Recursion to"

If it requires IP's, put in the internal IP address range of your local LAN private subnet.

0
 
Tim HolmanCommented:
No comment has been added to this question in more than 21 days, so it is now classified as abandoned..
I will leave the following recommendation for this question in the Cleanup topic area:

--> Accept: daJman

Any objections should be posted here in the next 4 days. After that time, the question will be closed.

tim_holman
EE Cleanup Volunteer
0

Featured Post

Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now