This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

High Volume of DNS Reverse Lookup Requests

The IPS/IDS is reporting a flood of DNS requests coming from the SolarWinds server which I realize is associated with NetFlow. The volume is such that it actually puts a certain amount of stress on the IPS/IDS appliance although it doesn't appear to be service affecting. Curiously the event starts at exactly the same time every 48 hours and runs for 2 to 2 and half hours. Apparently this is a scheduled activity so does anyone know how to implement a change to the schedule?

  • I've seen similar activity, although it doesn't seem to be scheduled for us -- it's a constant stream of requests.  Incidentally, why do you feel it's related to Netflow?  I assumed the activity was from the Orion server polling the hostname using SNMP, thus necessitating all the DNS lookups.

  • I believe it's related to Netflow because I started witnessing this activity after we installed and enabled Netflow. Also, if you refer to another post named "Flood of DNS Requests" dated 11/03/08 you'll see an entry that states "This is occuring to resolve the hostname of the ip addresses that are part of the netflow data."

  • Ouch.

     

    That may explain a few things i'm seeing on my IDS as well, actually (I see tons of external DNS requests periodically through the evenings to external DNS servers -- maybe it's related somehow)

     

    Thanks for the explanation.