Forum Moderators: Robert Charlton & goodroi
Several very different IP addresses, but all from the Google-plex (looks like an odd distributed bot net, really), running probes for 'dns.latency.google.com/A/IN' over a period of 10 minutes against my DNS services.
Unfortunately, there may be DNS servers around that deny foreign requests, they only reply to queries for the few own zones they are authoritative, they are not public resolvers for the entire internet name space.
To protect my logs from getting bloated with all this 'deny' stuff, offending IP addresses who try this too often are honoured by an automated DROP rule in the firewall.
Wow, am I really entitled to DROP Google -- or is it shooting in my own feet?
Why does Google think that a foreign name server should resolve 'dns.latency.google.com', which that foreign server surely is not authoritative for?
If they want to measure DNS latencies, they perhaps could do a legal query for a domain name the foreign nameserver is authoritative for.
Regards,
R.
- - - - -
Sep 26 23:24:14 ff named[9283]: client 66.249.x.4#2245: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:24:14 ff named[9283]: client 66.249.x.4#2781: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:25:23 ff named[9283]: client 64.233.x.198#23842: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:25:23 ff named[9283]: client 64.233.x.198#23842: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:28:13 ff named[9283]: client 64.233.x.135#10202: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:28:13 ff named[9283]: client 64.233.x.135#10202: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:28:40 ff named[9283]: client 64.233.x.133#25676: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:28:40 ff named[9283]: client 64.233.x.133#25676: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:28:43 ff named[9283]: client 66.102.x.133#26223: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:28:44 ff named[9283]: client 66.102.x.133#26223: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:30:54 ff named[9283]: client 216.239.x.133#15137: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:30:54 ff named[9283]: client 216.239.x.133#15137: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:30:56 ff named[9283]: client 66.249.x.196#30778: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:30:56 ff named[9283]: client 66.249.x.196#30778: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:31:29 ff named[9283]: client 64.233.x.133#28933: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:31:29 ff named[9283]: client 64.233.x.133#28933: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:31:38 ff named[9283]: client 64.233.x.133#48651: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:31:38 ff named[9283]: client 64.233.x.133#48651: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:31:39 ff named[9283]: client 66.249.x.207#5775: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:31:39 ff named[9283]: client 66.249x.207#5775: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:35:15 ff named[9283]: client 72.14.x.133#50843: query (cache) 'dns.latency.google.com/A/IN' denied
Sep 26 23:35:15 ff named[9283]: client 72.14.x.133#50843: query (cache) 'dns.latency.google.com/A/IN' denied