Win 2K Pro Why So Many DNS Requests?
#1
![Question](https://www.scoobynet.com/images/icons/icon5.gif)
Can anyone shed any light on the following - I have a Win 2K Pro PC which runs Mailsweeper for E-mail content filtering. It's default gateway is our internal firewall and it's DNS server entries are our ISPs addresses. During the day it makes DNS request about every 15mins until about 12am when it then does it every hour up until about 8am then it reverts back to 15mins. It does this even if I stop the Mailsweeper services, there is nothing else running on the PC. The PC used to run Win NT 4.0 Workstation and it never showed this sort of behaviour it's only since going to 2K. It is causing me a problem as every time it makes a DNS request it is bringing the ISDN line up which is fine during the day but not during the evening, the accountants want it stopping to save a few pence every day.
Si.
Si.
#5
Scooby Regular
Join Date: Oct 2001
Location: Ashford, Kent
Posts: 1,371
Likes: 0
Received 0 Likes
on
0 Posts
![Post](https://www.scoobynet.com/images/icons/icon1.gif)
With Intel ISDN routers you can create a rule to stop these type of requests.
I think they are UDP but I haven't had to do this one for a few years.
Cheers,
Phil
I think they are UDP but I haven't had to do this one for a few years.
Cheers,
Phil
#6
Scooby Regular
Join Date: Mar 2000
Location: Gloucestershire, home of the lawnmower.
Posts: 4,531
Likes: 0
Received 0 Likes
on
0 Posts
![Post](https://www.scoobynet.com/images/icons/icon1.gif)
On my Cisco ISDN router I need to set this rule:
SET IP FILTER ICMP OUT DESTINATION 194.43.224.130/32 IGNORE
where 194.43.224.130 is my ISPs DNS
That fixed the problem of spurious dial-ups. Maybe you can do something similar ?
Cheers
Ian
SET IP FILTER ICMP OUT DESTINATION 194.43.224.130/32 IGNORE
where 194.43.224.130 is my ISPs DNS
That fixed the problem of spurious dial-ups. Maybe you can do something similar ?
Cheers
Ian
#7
![Post](https://www.scoobynet.com/images/icons/icon1.gif)
Phil,
They are udp/dns requests on port 53.
Ian,
That would stop all DNS requests from the PC, I have some DNS requests that are initiated from the PC's e-mail software which need to be allowed through to the ISP. I need to be able to stop the requests that are not coming from the e-mail software.
All help is greatly appreciated.
Si.
They are udp/dns requests on port 53.
Ian,
That would stop all DNS requests from the PC, I have some DNS requests that are initiated from the PC's e-mail software which need to be allowed through to the ISP. I need to be able to stop the requests that are not coming from the e-mail software.
All help is greatly appreciated.
Si.
Trending Topics
#8
Scooby Regular
Join Date: Mar 2000
Location: Gloucestershire, home of the lawnmower.
Posts: 4,531
Likes: 0
Received 0 Likes
on
0 Posts
![Post](https://www.scoobynet.com/images/icons/icon1.gif)
Si,
No, it doesn't stop all DNS requests from the PC otherwise I wouldn't be able to surf, get email, read news etc.![Big Grin](https://www.scoobynet.com/images/smilies/biggrin.gif)
It actually ignores ICMP traffic if the line is inactive. If the line is active then ICMP traffic is allowed.
---
Erm, er, edited, to say you do want the traffic from your email to bring the line up but not the spurious traffic from Win2k. So, yes, I'm a dick![Wink](https://www.scoobynet.com/images/smilies/wink.gif)
Give us a clue what router you have, it may be possible to do something. For instance, are you running NetBIOS locally as that can generate some traffic.
Cheers
Ian
[Edited by IWatkins - 12/6/2002 11:52:55 AM]
No, it doesn't stop all DNS requests from the PC otherwise I wouldn't be able to surf, get email, read news etc.
![Big Grin](https://www.scoobynet.com/images/smilies/biggrin.gif)
It actually ignores ICMP traffic if the line is inactive. If the line is active then ICMP traffic is allowed.
---
Erm, er, edited, to say you do want the traffic from your email to bring the line up but not the spurious traffic from Win2k. So, yes, I'm a dick
![Wink](https://www.scoobynet.com/images/smilies/wink.gif)
Give us a clue what router you have, it may be possible to do something. For instance, are you running NetBIOS locally as that can generate some traffic.
Cheers
Ian
[Edited by IWatkins - 12/6/2002 11:52:55 AM]
#10
![Post](https://www.scoobynet.com/images/icons/icon1.gif)
Ian,
I have a Webramp router which is basically a Sonic Wall re-badged. The only protocol installed on the PC is TCP/IP but I do have NetBIOS set to enable over TCP/IP.
Si.
I have a Webramp router which is basically a Sonic Wall re-badged. The only protocol installed on the PC is TCP/IP but I do have NetBIOS set to enable over TCP/IP.
Si.
#11
![Post](https://www.scoobynet.com/images/icons/icon1.gif)
Possibly the 'DNS Client' service, which is essentially a local DNS client cache on the machine.
Stop it thru 'Computer Managment' or at the command prompt 'net stop "dns client" 'and see if that helps. If it does then set it to 'Disabled'
It dosent need to run, just helps things in an AD environment.
Ids
Stop it thru 'Computer Managment' or at the command prompt 'net stop "dns client" 'and see if that helps. If it does then set it to 'Disabled'
It dosent need to run, just helps things in an AD environment.
Ids
#13
![Post](https://www.scoobynet.com/images/icons/icon1.gif)
Can do (unless you are using DHCP
) as theres some spurious name resolution stuff that can actaully use DHCP.
Let us know how u get on.
Last thing to do is get a copy of Etherreal, WinCap or MS NetMon loaded. You can see what the actual traffic is then.
Ids
![Wink](https://www.scoobynet.com/images/smilies/wink.gif)
Let us know how u get on.
Last thing to do is get a copy of Etherreal, WinCap or MS NetMon loaded. You can see what the actual traffic is then.
Ids
Thread
Thread Starter
Forum
Replies
Last Post
Pro-Line Motorsport
Car Parts For Sale
2
29 September 2015 07:36 PM