Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I have just checked a wireshark capture of my network traffic from one of our domain controllers and it's showing a shed load of DNS requests for windows update.

 

I have attached a screenshot but the packets can be about 600 in a row, this is between my two DNS servers and then it will attempt the same from both my DNS servers to one on the forward list, they never seem to cache any response as it's pretty constant

 

 

Is this even remotely normal ?

dns_capture.jpg

Posted

10.22.161.6 is primary DNS and Domain Controller (which wireshark is running on) and 10.22.161.4 is the secondary DNS server.

 

It seems very odd

Posted
The only thing I could come up with was a client is trying to update - but that does not make any sense in regards to the IP addresses.....
Posted
I suspect it's DNS updates propergating from one DNS server to the other. As a result of DHCP leases being given out. Are one of these servers the DHCP server for the domain?
Posted
Yes the primary DNS server is also the DHCP server, it strikes me as odd that that many DNS queries can occur in such a short timeline (within a second or two) constantly as leases are not renewed that often
Posted
Funny you should mention this - im getting failures on my clients about failing to download updated root lists from that same web host (this was after M$ released a patch that broke WSUS)
Posted
I suspect it's DNS updates propergating from one DNS server to the other.

 

That often ?

I suppose you could stop DNS on one of the servers to prove this...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...