Solved

"Denied Recursion" messages in firewall log

Posted on 2003-11-07
3
278 Views
Last Modified: 2013-11-16
We recently put all our servers behind a firewall (an Instagate EX2 to be exact).  We have a few web servers, a mail server, and a DNS server running Simple DNS Plus.  I've set up all the policies and everything seems to be working fine except one thing.

Our firewall logs are HUGE and 99% of it is the same message over and over again:
"denied recursion for query from [69.18.166.34].1031 for svr5.erh.noaa.gov IN"
that IP address "69.18.166.34" is the external IP of our DNS server.

Does anybody know what this message means?  What causes it?  If there's anything we can do to stop it?  We go through periods where this message comes up about 50 times per second!

If it helps: Noaa.gov is a weather server that our webservers (using cold fusion) grab weather from to display on webpages.  Those weather pages are working fine despite this repeated message.
0
Comment
Question by:noreastnerd
3 Comments
 
LVL 5

Accepted Solution

by:
daJman earned 180 total points
ID: 9703776
I suspect your DNS server config. Try this:

In the Options menu in DNS Server Plus remove the IP range listed under "Offer Recursion to"

If it requires IP's, put in the internal IP address range of your local LAN private subnet.

0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 10976315
No comment has been added to this question in more than 21 days, so it is now classified as abandoned..
I will leave the following recommendation for this question in the Cleanup topic area:

--> Accept: daJman

Any objections should be posted here in the next 4 days. After that time, the question will be closed.

tim_holman
EE Cleanup Volunteer
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now