Bind attempting to connect to invalid servers on port 53

Solution Verified - Updated -

Issue

Our main DMZ DNS servers have experienced sporadic outages due to them being blackholed by the firewall for attempting to connect to unauthorized servers on port 53.

The IP networks in question are:

Internal: 10.0.0.0
DMZ: 192.168.0.0

The DMZ DNS servers are being blackholed trying to get to port 53 on systems in our stores (e.g. 10.4.1.0, 10.2.1.0, etc)

The question I'm trying to answer is how is it possible to get a bind server to attempt a name lookup on system that is not listed as a nameserver in any configuration file, inlcuding the root hints?

Environment

Red Hat Enterprise Linux bind DNS server

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.