Results 1 to 4 of 4

Thread: Question regarding traffic from my virginmedia DNS servers shown in zonealarm log.

  1. #1
    lardboy Guest

    Cool Question regarding traffic from my virginmedia DNS servers shown in zonealarm log.

    I have a netgear router but I also run zonealarm on my PC mostly to control what gets access to the internet.

    I've recently noticed entrys in zonealarm's logs along the following lines -

    Protocol - UDP
    Source IP - 194.168.8.100:53 & 194.168.4.100:53
    Destination ports - 52930, 54284, 56559, 58680 & 63131
    Source DNS - cache1.service.virginmedia.net & cache2.service.virginmedia.net

    The source IPs appear to be the DNS servers that I'm using.

    Zonealarm is blocking the traffic but I'm wondering why this hasn't being blocked by the router.

    Is this normal?

    Operating System:Windows XP Home Edition
    Software Version:8.0
    Product Name:ZoneAlarm (Free)

  2. #2
    Join Date
    Dec 2005
    Posts
    9,056

    Default Re: Question regarding traffic from my virginmedia DNS servers shown in zonealarm log.


    <blockquote><hr>lardboy wrote:
    I have a netgear router but I also run zonealarm on my PC mostly to control what gets access to the internet.

    I've recently noticed entrys in zonealarm's logs along the following lines -

    Protocol - UDP
    Source IP - 194.168.8.100:53 & 194.168.4.100:53
    Destination ports - 52930, 54284, 56559, 58680 & 63131
    Source DNS - cache1.service.virginmedia.net & cache2.service.virginmedia.net

    The source IPs appear to be the DNS servers that I'm using.

    Zonealarm is blocking the traffic but I'm wondering why this hasn't being blocked by the router.

    Is this normal?

    Operating System:
    Windows XP Home Edition
    Software Version:
    8.0
    Product Name:
    ZoneAlarm (Free)

    <hr></blockquote>


    These are actually returning inbound connections that were originally started by your computer to the dns servers - this is why this is allowed by the router as the router has seen the initial connections were started by your own computer and just sees these connections from the dns servers as returned connections.
    Basically anyways - a little more is involved but that is a distilled answer.


    Hmmm first of all, I suspect the virginmedia's dns servers are not entered as Trusted into the Zones of the Firewall of the Zone Alarm. This is part of the problem as to why these connections are blocked by the ZA - which they should not.

    Oldsod.
    Best regards.
    oldsod

  3. #3
    lardboy Guest

    Default Re: Question regarding traffic from my virginmedia DNS servers shown in zonealarm log.

    OK Thanks, I'll add the DNS servers to the trusted zone.

  4. #4
    Join Date
    Dec 2005
    Posts
    9,056

    Default Re: Question regarding traffic from my virginmedia DNS servers shown in zonealarm log.

    You are welcome.
    Oldsod.
    Best regards.
    oldsod

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Alerts to Incoming Intrusions Not Shown in ZoneAlarm 9.2.044.000, Etc.
    By zauserthatday in forum ZoneAlarm Free Firewall
    Replies: 0
    Last Post: June 20th, 2010, 01:03 PM
  2. Servers that ZoneAlarm uses
    By dwinston in forum General - Questions that don't fit any other category
    Replies: 0
    Last Post: July 17th, 2008, 10:47 PM
  3. zoney calling home and dead servers question
    By dr_del in forum General - Questions that don't fit any other category
    Replies: 2
    Last Post: December 27th, 2006, 09:23 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •