"Denied Recursion" messages in firewall log

We recently put all our servers behind a firewall (an Instagate EX2 to be exact).  We have a few web servers, a mail server, and a DNS server running Simple DNS Plus.  I've set up all the policies and everything seems to be working fine except one thing.

Our firewall logs are HUGE and 99% of it is the same message over and over again:
"denied recursion for query from [69.18.166.34].1031 for svr5.erh.noaa.gov IN"
that IP address "69.18.166.34" is the external IP of our DNS server.

Does anybody know what this message means?  What causes it?  If there's anything we can do to stop it?  We go through periods where this message comes up about 50 times per second!

If it helps: Noaa.gov is a weather server that our webservers (using cold fusion) grab weather from to display on webpages.  Those weather pages are working fine despite this repeated message.
noreastnerdAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

daJmanCommented:
I suspect your DNS server config. Try this:

In the Options menu in DNS Server Plus remove the IP range listed under "Offer Recursion to"

If it requires IP's, put in the internal IP address range of your local LAN private subnet.

0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Tim HolmanCommented:
No comment has been added to this question in more than 21 days, so it is now classified as abandoned..
I will leave the following recommendation for this question in the Cleanup topic area:

--> Accept: daJman

Any objections should be posted here in the next 4 days. After that time, the question will be closed.

tim_holman
EE Cleanup Volunteer
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.