Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Are these DNS Requests Excessive?

Posted on 2013-06-07
2
Medium Priority
?
305 Views
Last Modified: 2013-06-10
Our UTM Firewall is alerting us to the fact that a number of DNS servers are going over set thresholds for DNS communication.

Now, I'm not saying something is wrong - the default threshold could just be set too low for instance - but I want to make sure given the size of the networks (all relatively small), the number of requests do not stand out as excessive.

How can I get a true metric of how many DNS requests are being processed per hour/day?
0
Comment
Question by:bikerhong
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 30

Accepted Solution

by:
Rich Weissler earned 2000 total points
ID: 39230226
On a windows server, the easiest way to collect the statistics would be with Performance Monitor.  The Windows DNS server adds counters for the DNS object.

I assume what you'll want to watch for is recursive queries... I know that's what my security folks have been chattering about lately.  Apparently open DNS servers which accept recursive queries are being used as a distributed denial of service attack against folks.  (I don't have any details, I just know an error was discovered on an edge router which was permitting the traffic on tcp/53... and it's fixed now.   We dropped from ~100 recursive queries/sec to a more normal 20-25.  We have a moderate size network though.)
0
 

Author Comment

by:bikerhong
ID: 39233991
Aha, interesting.

I have set perfmon to display some DNS stats and everything is really low - Ill keep an eye on it.
0

Featured Post

Looking for a new Web Host?

Lunarpages' assortment of hosting products and solutions ensure a perfect fit for anyone looking to get their vision or products to market. Our award winning customer support and 30-day money back guarantee show the pride we take in being the industry's premier MSP.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question