I recently got a letter from my ISP complaining about rdns coming out of my site.
I have a firewall and behind this 900 ish devices. I have 2 primary DNS servers.
Server 1 shows 1,342,000 recursive queries. On avg about 1.5 - 2 per second.
I need to\ want to figure out where these are coming from so I can find out what they are looking for and asjust it.
I have used perfmon to gather some information, and have used netmon to gather packets and filter DNS, but im not exactly sure what I am looking for.
How do I trace this rdns issue?
I have reset the dns servers and started at zero to monitor.