Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Unknown log entry...
From: Ian Miller <firewalls @ scientia . com>
Date: Fri, 06 Jun 1997 09:37:27 +0100
To: firewalls @ greatcircle . com
Cc: devin @ TELERAMA . LM . COM"Tod McQuillin, as Technical Contact for zone LM.COM"

At 19:05 05/06/97 -0700, Cihan Subasi <csubasi @
 garanti .
 com .
 tr> wrote:
>I had those two line in my firewall logs, can anybody explain me what
>are they???
>
>--------------------------------------------------
>Jun  2 20:30:49 fw1 sendmail[16650]: gethostby*.getanswer: asked for
>"66.3.196.208.in-addr.arpa IN PTR", got type "CNAME"
>Jun  2 20:30:49 fw1 sendmail[16650]: gethostby*.getanswer: asked for
>"66.3.196.208.in-addr.arpa", got "66.64.3.196.208.in-addr.arpa"
>--------------------------------------------------

Your mail server has tried to do a reverse lookup on IP address 208.196.3.66
(karnov.lm.com)
and has got some VERY odd results.  Reverse lookup on IP address
<a>.<b>.<c>.<d> is done by looking domain <d>.<c>.<b>.<a>.in-addr.arpa.
This should contain PTR (name->IP) records.  However if you look up
208.196.3.66 you get:-
CNAME/ARPA "66.3.196.208.in-addr.arpa" 6h  "66.64.3.196.208.in-addr.arpa"
  CNAME records are name->name (alias) records.  This is wierd for an
in-addr.arpa domain and it has not surprisingly confused your firewall.  If
you follow up the (I think non-sensical CNAME) you get.

PTR/ARPA "66.64.3.196.208.in-addr.arpa" 1d  "karnov.lm.com"

I have no idea why this DNS is set-up this.  

Ian



Follow-Ups:
Indexed By Date Previous: Re: PIX and FW-1 (packet filter Question)
From: Eric Vyncke <evyncke @ cisco . com>
Next: Re: PIX and FW-1 (packet filter Question)
From: Don Lewis <Don . Lewis @ tsc . tdk . com>
Indexed By Thread Previous: Unknown log entry...
From: Cihan Subasi <csubasi @ garanti . com . tr>
Next: Re: Unknown log entry...
From: Neil Readwin <nreadwin @ csksoftware . com>

Google
 
Search Internet Search www.greatcircle.com