<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Unbound Querys to NAUGHTY! Servers]]></title><description><![CDATA[<p dir="auto">Why is resolver (unbound) making DNS request to these non root servers?  Furthermore they are in the Spamhaus DROP list.  Glad I have outbound rules that block this nonsense.  But I'd still like to know why it happens.  Happened last night too, about 21 hours prior to this current episode.</p>
<p dir="auto">185.75.56.93<br />
185.75.56.94</p>
<p dir="auto">Resolver config:<br />
Network Interfaces: LAN and Localhost<br />
Outgoing Network Interfaces: WAN<br />
DNSSEC enabled (box checked)<br />
DNS Query Forwarding disabled (box unchecked)<br />
Advanced:<br />
local-zone: "home" static<br />
log-queries: yes</p>
<p dir="auto">Resolver Log:</p>
<pre><code>
Feb 13 20:41:03 unbound  [96826:0] info: 127.0.0.1 93.56.75.185.in-addr.arpa. PTR IN 
Feb 13 20:41:04 unbound  [96826:0] info: 127.0.0.1 93.56.75.185.in-addr.arpa. PTR IN 
Feb 13 20:41:09 unbound  [96826:0] info: 127.0.0.1 94.56.75.185.in-addr.arpa. PTR IN 
Feb 13 20:41:10 unbound  [96826:0] info: 127.0.0.1 94.56.75.185.in-addr.arpa. PTR IN 

</code></pre>
<p dir="auto">Firewall Log:</p>
<pre><code>
Feb 13 20:41:10 filterlog: 86,16777216,,1435562678,bfe0_vlan99,match,block,out,4,0x0,,64,31950,0,none,17,udp,82,&lt;pfsense wan="" if=""&gt;,185.75.56.94,25248,53,62 
Feb 13 20:41:10 filterlog: 86,16777216,,1435562678,bfe0_vlan99,match,block,out,4,0x0,,64,17979,0,none,17,udp,82,&lt;pfsense wan="" if=""&gt;,185.75.56.94,54643,53,62 
Feb 13 20:41:10 filterlog: 86,16777216,,1435562678,bfe0_vlan99,match,block,out,4,0x0,,64,25987,0,none,17,udp,82,&lt;pfsense wan="" if=""&gt;,185.75.56.94,20621,53,62 
Feb 13 20:41:10 filterlog: 86,16777216,,1435562678,bfe0_vlan99,match,block,out,4,0x0,,64,46573,0,none,17,udp,82,&lt;pfsense wan="" if=""&gt;,185.75.56.94,23770,53,62 
Feb 13 20:41:10 filterlog: 86,16777216,,1435562678,bfe0_vlan99,match,block,out,4,0x0,,64,11176,0,none,17,udp,82,&lt;pfsense wan="" if=""&gt;,185.75.56.94,25372,53,62 
Feb 13 20:41:10 filterlog: 86,16777216,,1435562678,bfe0_vlan99,match,block,out,4,0x0,,64,9540,0,none,17,udp,82,&lt;pfsense wan="" if=""&gt;,185.75.56.93,24210,53,62 
Feb 13 20:41:10 filterlog: 86,16777216,,1435562678,bfe0_vlan99,match,block,out,4,0x0,,64,62086,0,none,17,udp,82,&lt;pfsense wan="" if=""&gt;,185.75.56.93,16654,53,62 
Feb 13 20:41:10 filterlog: 86,16777216,,1435562678,bfe0_vlan99,match,block,out,4,0x0,,64,4144,0,none,17,udp,82,&lt;pfsense wan="" if=""&gt;,185.75.56.93,59873,53,62 
Feb 13 20:41:10 filterlog: 86,16777216,,1435562678,bfe0_vlan99,match,block,out,4,0x0,,64,6451,0,none,17,udp,82,&lt;pfsense wan="" if=""&gt;,185.75.56.93,5702,53,62 
Feb 13 20:41:10 filterlog: 86,16777216,,1435562678,bfe0_vlan99,match,block,out,4,0x0,,64,2443,0,none,17,udp,82,&lt;pfsense wan="" if=""&gt;,185.75.56.93,43123,53,62&lt;/pfsense&gt;&lt;/pfsense&gt;&lt;/pfsense&gt;&lt;/pfsense&gt;&lt;/pfsense&gt;&lt;/pfsense&gt;&lt;/pfsense&gt;&lt;/pfsense&gt;&lt;/pfsense&gt;&lt;/pfsense&gt; 
</code></pre>
]]></description><link>https://forum.netgate.com/topic/95493/unbound-querys-to-naughty-servers</link><generator>RSS for Node</generator><lastBuildDate>Fri, 10 Apr 2026 08:29:39 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/95493.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 14 Feb 2016 05:47:16 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Unbound Querys to NAUGHTY! Servers on Sun, 14 Feb 2016 10:47:28 GMT]]></title><description><![CDATA[<p dir="auto">"Why is resolver (unbound) making DNS request to these non root servers?"</p>
<p dir="auto">Because they are the authoritative name servers for some domain something asked for…  You do understand unbound just uses roots to find the authoritative servers for the domain your looking for right - and then goes and asks them directly..</p>
<p dir="auto">;; ANSWER SECTION:<br />
93.56.75.185.in-addr.arpa. 86400 IN    PTR    ns1.maxtv-ks.net</p>
<p dir="auto">So clearly those are the name servers for maxtv-ks.net</p>
<p dir="auto">;; OPT PSEUDOSECTION:<br />
; EDNS: version: 0, flags:; udp: 4096<br />
;; QUESTION SECTION:<br />
;maxtv-ks.net.                  IN      SOA</p>
<p dir="auto">;; ANSWER SECTION:<br />
maxtv-ks.net.          86400  IN      SOA    maxtv-ks.net. root.maxtv-ks.net. 100 3600 60 604800 86400</p>
<p dir="auto">;; AUTHORITY SECTION:<br />
maxtv-ks.net.          86400  IN      NS      ns1.maxtv-ks.net.<br />
maxtv-ks.net.          86400  IN      NS      NS2.maxtv-ks.net.</p>
<p dir="auto">;; ADDITIONAL SECTION:<br />
ns1.maxtv-ks.net.      86400  IN      A      185.75.56.93<br />
NS2.maxtv-ks.net.      86400  IN      A      185.75.56.94</p>
<p dir="auto">;; Query time: 156 msec<br />
;; SERVER: 185.75.56.93#53(185.75.56.93)<br />
;; WHEN: Sun Feb 14 04:47:23 Central Standard Time 2016<br />
;; MSG SIZE  rcvd: 150</p>
<p dir="auto">They may be name servers for lots and lots of other domains as well...  If you don't want unbound doing queries for them, then I would find out what is asking for stuff they are authoritative for..</p>
]]></description><link>https://forum.netgate.com/post/602675</link><guid isPermaLink="true">https://forum.netgate.com/post/602675</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sun, 14 Feb 2016 10:47:28 GMT</pubDate></item></channel></rss>