Bind 9.4.3 and 2 hr DNS flooding problem
I'm having a problem with my BIND server, where every 2hrs I get flooded with DNS messages such as these:
named: unexpected RCODE (REFUSED) resolving '48x40.com/MX/IN': 18.104.22.168#53
unexpected RCODE (SERVFAIL) resolving 'ns.ryazan.ru/A/IN': 22.214.171.124#53
named: lame server resolving '121gigawatts.net' (in '121gigawatts.NET'?): 126.96.36.199#53
named: FORMERR resolving 'betsgroup.com/MX/IN': 188.8.131.52#53
named: client 184.108.40.206#1031: no more recursive clients: quota reached
The flood seems to last about 40 seconds, and during that time the quantity of DNS messages is actually causing a mini DoS on one of my firewall interfaces. The firewall actually drops some of the UDP DNS requests:
Dropped UDP DNS reply from outside:xx.xx.xx.xx/53 to dmz:xx.xx.xx.xx/59323; packet length 524 bytes exceeds configured limit of 512 bytes
Does anyone have any idea what would cause this DNS flood every two hours, and what I might do to alleviate the problem?
Thanks in advance!