Thank you, Comcast.

John Kristoff jtk at cymru.com
Fri Feb 26 19:02:22 UTC 2016


On Fri, 26 Feb 2016 07:20:28 +0100 (CET)
Mikael Abrahamsson <swmike at swm.pp.se> wrote:

> I know historically there were resolvers that used UDP/53 as source
> port for queries, but is this the case nowadays?

Empirically from what I've observed, much less than there once was.
Looking at a sample of a few thousand queries on a server set I can
see, I don't need much more than what two hands can count.

I still see the occasional ISP name server, probably having been around
forever and perhaps locked in with the query-source option in BIND.
You also see what is probably as a result of some local oddball policy,
making something easier, such as the queries *.labs.rapid7.com (hi guys)
like to issue for things like VERSION.BIND CH TXT.

John



More information about the NANOG mailing list