Page 1 of 1

Huge number of DOMAIN UDP traffic to/from EFA

Posted: 09 Mar 2018 13:08
by ulfthomas
Hi.

I identified the above situation just yesterday and on my firewall it presents as follows. The data is extracted from my firewall and it shows traffic on the EFA for a 24 hour period:

1 DOMAIN (UDP) - IN: 55MB, OUT: 7MB, Connections: 94.000 (!!!), % of overall traffic: 97.90%

The DNS is recursive and does not forward to another DNS server. Further more I am running a mail server on the inside for which EFA both receives and sends but the volume is in barely in the hundreds.

Is this expected behavior?

Regards,

Ulf Thomas

Re: Huge number of DOMAIN UDP traffic to/from EFA

Posted: 10 Mar 2018 13:52
by shawniverson
How much email are you receiving each day and from how many approximate remote sources?

Re: Huge number of DOMAIN UDP traffic to/from EFA

Posted: 10 Mar 2018 21:07
by ulfthomas
About a hundre each day - but I do get many that are RBL'ed or otherwise turned away.

As for remote sources - I have no data on that.