This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

DNS resolution is flooding our network

Not sure how this is happening to this magnitude, but after turning up Netflow on our edge routers and MSFC, we appear to be creating thousands of connections on our Firewall as our internal DNS server tries to resolve FQDN's externally.  

Is there a simple way to turn off DNS resolution for FQDN's in Netflow or NPM?  We're running NPM 9.2 and NTA 9.1 SP3.

Thanks,

George

  • Yes, there is a Thwack thread about this issue.  It is located here:

    You might be seeing the new NetBIOS resolution that we are doing in NTA 3.1.  As you see in the other post, at the present, you can't turn off the NetBIOS from within NetFlow.  We'll correct this in a future service pack hopefully, but you can turn all name resolution off if you want.  But there is a workaround... You can open up your network cards "Properties".  Select the TCP/IP protocol, open its properties, hit the "Advanced" button, click the "WINS" tab and there in the "NetBIOS Settings" grouping, click the "Disable NetBIOS over TCP/IP".

    If it is truly the DNS resolution that you want turned off.  It can be done in NTA 3.1, but you'll need to have Tech Support walk you through how to do it.

    Hope this helps,

    David

  • yeah, unfortunately this is DNS traffic, as the destination packets to the DNS server are UDP 53.   I'll have to open a case then.

     

    Thanks,

    George