Compatible Support Forums: Why would my firewall block DNS requests?

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Why would my firewall block DNS requests?

#1 User is offline   kgeissler 

  • enthusiast
  • Group: Members
  • Posts: 362
  • Joined: 16-March 00

Posted 20 December 2001 - 07:04 AM

Here is an event I have in my Zone Alarm Pro log:

The firewall has blocked Internet access to your computer (UDP Port 7062) from 204.127.202.4 (DNS).

Why would zone alarm block this? Any idea?
0

#2 User is offline   clutch 

  • Carpal Tunnel
  • Group: Moderators
  • Posts: 3859
  • Joined: 29-March 00

Posted 20 December 2001 - 07:21 AM

Well, I am not familiar with that port number (you can check out port listings here for more info) and DNS resolution is normally hosted on port 53. But, in general, you don't want any external traffic to look to your network for name resolution if you have DNS servers that are only meant for your network. Now, if you were hosting your own Name Servers for external resolution of subdomains for your TLD, that would be a different story. But, it sounds like you aren't, so I wouldn't let them in anyway.

smile
0

#3 User is offline   Palos 

  • old hand
  • Group: Members
  • Posts: 723
  • Joined: 05-February 00

Posted 20 December 2001 - 12:45 PM

Maybe you were portscanned and the firewall detected that and automatically blocked the IP. However the attacker can spoof his IP and hide behind your provider's DNS, therefore locking you out of the Internet, lol.

I don't think that's the case, but maybe the NetBios name of that IP address IS actually DNS, lol too.
0

#4 User is offline   ryoko 

  • member
  • Group: Members
  • Posts: 163
  • Joined: 30-July 00

Posted 30 December 2001 - 11:55 PM

I would guess a port scan. Look at how high the origin port number is. Typically a PC will increment the port number for nonstandard tcp/ip proceesses. For example, if I ran a particular network app 4 times, the first use may use an outgoing port of say 4010, the second 4011, the third 4012 ... get the idea. Now that is just the origin port on my PC. If I were using a generic service, like FTP, then the destination port would be 21 in all the above examples. There are many exceptions to this, as a lot of software is made to use a specific port even for outgoing transmittions. Well, I hope this helped a little.

-RY
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users