We have been noticing repeated LARGE spikes in in-addr.arpa queries for PTR records in arpa zones we are authoritative for. It looks like network scanning, or data mining, perhaps nmap processes or something. It started roughly beginning of December and re-occurs roughly every 16 hours. Im wondering if anyone else who manages a large number of in-addr.arpa zones (read thousands and thousands) have seen similar traffic patterns since the beginning of December.
Jeremy -- Sent from: http://bind-users-forum.2342410.n4.nabble.com/ _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users