Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Win 2K Pro Why So Many DNS Requests?

Thread Tools
 
Search this Thread
 
Old 06 December 2002, 09:30 AM
  #1  
sillysi
Scooby Regular
Thread Starter
 
sillysi's Avatar
 
Join Date: Jan 2002
Posts: 1,440
Likes: 0
Received 0 Likes on 0 Posts
Question

Can anyone shed any light on the following - I have a Win 2K Pro PC which runs Mailsweeper for E-mail content filtering. It's default gateway is our internal firewall and it's DNS server entries are our ISPs addresses. During the day it makes DNS request about every 15mins until about 12am when it then does it every hour up until about 8am then it reverts back to 15mins. It does this even if I stop the Mailsweeper services, there is nothing else running on the PC. The PC used to run Win NT 4.0 Workstation and it never showed this sort of behaviour it's only since going to 2K. It is causing me a problem as every time it makes a DNS request it is bringing the ISDN line up which is fine during the day but not during the evening, the accountants want it stopping to save a few pence every day.

Si.
Old 06 December 2002, 09:36 AM
  #2  
dsmith
Scooby Regular
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

No idea on the DNS - but if you have access to the router (and its a cisco) you can play with the Dial-Up access-list so DNS wont cause a dial from say 8pm to 7am.

Deano
Old 06 December 2002, 09:37 AM
  #3  
HHxx
Scooby Regular
 
HHxx's Avatar
 
Join Date: Nov 2001
Posts: 2,576
Likes: 0
Received 0 Likes on 0 Posts
Post

Is the register this connection box checked in the dns tab in tcpip advanced?

If so uncheck it. It used to dynamically register itself when used in a ad domain.

H
Old 06 December 2002, 09:43 AM
  #4  
sillysi
Scooby Regular
Thread Starter
 
sillysi's Avatar
 
Join Date: Jan 2002
Posts: 1,440
Likes: 0
Received 0 Likes on 0 Posts
Post

H,

It is unchecked but still makes no difference.

Deano,

My router does not have dial-up times so that ones out.

Si.
Old 06 December 2002, 10:43 AM
  #5  
Lust4Life
Scooby Regular
 
Lust4Life's Avatar
 
Join Date: Oct 2001
Location: Ashford, Kent
Posts: 1,371
Likes: 0
Received 0 Likes on 0 Posts
Post

With Intel ISDN routers you can create a rule to stop these type of requests.

I think they are UDP but I haven't had to do this one for a few years.

Cheers,

Phil
Old 06 December 2002, 10:57 AM
  #6  
IWatkins
Scooby Regular
 
IWatkins's Avatar
 
Join Date: Mar 2000
Location: Gloucestershire, home of the lawnmower.
Posts: 4,531
Likes: 0
Received 0 Likes on 0 Posts
Post

On my Cisco ISDN router I need to set this rule:

SET IP FILTER ICMP OUT DESTINATION 194.43.224.130/32 IGNORE

where 194.43.224.130 is my ISPs DNS

That fixed the problem of spurious dial-ups. Maybe you can do something similar ?

Cheers

Ian
Old 06 December 2002, 11:39 AM
  #7  
sillysi
Scooby Regular
Thread Starter
 
sillysi's Avatar
 
Join Date: Jan 2002
Posts: 1,440
Likes: 0
Received 0 Likes on 0 Posts
Post

Phil,

They are udp/dns requests on port 53.

Ian,

That would stop all DNS requests from the PC, I have some DNS requests that are initiated from the PC's e-mail software which need to be allowed through to the ISP. I need to be able to stop the requests that are not coming from the e-mail software.

All help is greatly appreciated.

Si.
Old 06 December 2002, 11:43 AM
  #8  
IWatkins
Scooby Regular
 
IWatkins's Avatar
 
Join Date: Mar 2000
Location: Gloucestershire, home of the lawnmower.
Posts: 4,531
Likes: 0
Received 0 Likes on 0 Posts
Post

Si,

No, it doesn't stop all DNS requests from the PC otherwise I wouldn't be able to surf, get email, read news etc.

It actually ignores ICMP traffic if the line is inactive. If the line is active then ICMP traffic is allowed.

---

Erm, er, edited, to say you do want the traffic from your email to bring the line up but not the spurious traffic from Win2k. So, yes, I'm a dick

Give us a clue what router you have, it may be possible to do something. For instance, are you running NetBIOS locally as that can generate some traffic.

Cheers

Ian

[Edited by IWatkins - 12/6/2002 11:52:55 AM]
Old 06 December 2002, 11:56 AM
  #9  
dsmith
Scooby Regular
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

are you running NetBIOS locally as that can generate some traffic.
Master of Understatement
Old 06 December 2002, 12:50 PM
  #10  
sillysi
Scooby Regular
Thread Starter
 
sillysi's Avatar
 
Join Date: Jan 2002
Posts: 1,440
Likes: 0
Received 0 Likes on 0 Posts
Post

Ian,

I have a Webramp router which is basically a Sonic Wall re-badged. The only protocol installed on the PC is TCP/IP but I do have NetBIOS set to enable over TCP/IP.

Si.
Old 06 December 2002, 03:56 PM
  #11  
ids
Scooby Regular
 
ids's Avatar
 
Join Date: May 1999
Posts: 424
Likes: 0
Received 0 Likes on 0 Posts
Post

Possibly the 'DNS Client' service, which is essentially a local DNS client cache on the machine.

Stop it thru 'Computer Managment' or at the command prompt 'net stop "dns client" 'and see if that helps. If it does then set it to 'Disabled'

It dosent need to run, just helps things in an AD environment.

Ids
Old 06 December 2002, 04:45 PM
  #12  
sillysi
Scooby Regular
Thread Starter
 
sillysi's Avatar
 
Join Date: Jan 2002
Posts: 1,440
Likes: 0
Received 0 Likes on 0 Posts
Post

Ids,

I shall give that a go. Is it worth stopping the DHCP service as well?

Si.
Old 06 December 2002, 04:49 PM
  #13  
ids
Scooby Regular
 
ids's Avatar
 
Join Date: May 1999
Posts: 424
Likes: 0
Received 0 Likes on 0 Posts
Post

Can do (unless you are using DHCP ) as theres some spurious name resolution stuff that can actaully use DHCP.

Let us know how u get on.

Last thing to do is get a copy of Etherreal, WinCap or MS NetMon loaded. You can see what the actual traffic is then.

Ids
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Pro-Line Motorsport
Car Parts For Sale
1
30 November 2015 05:52 PM
Ganz1983
Subaru
5
02 October 2015 09:22 AM
Pro-Line Motorsport
Car Parts For Sale
2
29 September 2015 07:36 PM
Pro-Line Motorsport
Car Parts For Sale
0
27 September 2015 11:21 AM



Quick Reply: Win 2K Pro Why So Many DNS Requests?



All times are GMT +1. The time now is 09:33 PM.