K-12 Forums

Talk with other K-12 network administrators in your state.

Or see all states.

Categories

Vanilla 1.1.4 is a product of Lussumo. More Information: Documentation, Community Support.

This discussion has been inactive for longer than 30 days, and is thus closed.
    • CommentAuthorrenes
    • CommentTimeMay 23rd 2009 edited
     permalink
    I see numerous UDP packets from port 53 on the OpenDNS DNS servers to closed ports my computer several times per minute.

    I'm not running the updater.

    Why the storm of packets trying to connect to closed ports on my computer?
    • CommentAuthorrotblitz
    • CommentTimeMay 23rd 2009 edited
     permalink
    Thought OpenDNS is attempting a DDoS attack against you? :shocked:
    Sure, they have nothing else to do! :tongue:

    No, dude, these are the responses to YOUR DNS lookups, and this is how DNS works in general. The "random" ports are generated by YOU. (Why are you doing such crap? :cool:)
    Don't know how DNS works? Then read about it.
    In brief: An application on your device (computer or anything else) raises a DNS lookup, UDP from YourIPaddress:nnnnn to 208.67.222.222:53, and the DNS service (OpenDNS or any other) responds with UDP from 208.67.222.222:53 to YourIPaddress:nnnnn, where nnnnn is any port within a high range.
    • CommentAuthorrenes
    • CommentTimeMay 27th 2009
     permalink
    The incoming packets are being sent to closed ports which is why my firewall is reporting them.

    I'm just running Windows.
    • CommentAuthorrotblitz
    • CommentTimeMay 27th 2009 edited
     permalink
    A firewall closing ports for explicitly expected responses and therefore blocking them is worth to be thrown away. I wonder how DNS can work in general for you. :confused:
    No matter what DNS service you use (OpenDNS or your ISP's or another 3rd party), you will always face this "problem".
    I would like to suggest to reconfigure your firewall accordingly.

This discussion has been inactive for longer than 30 days, and is thus closed.