Hello,
In my RB2011UiAS with router OS version 6.45.7 I have disabled "Allow Remote Requests" in addition to having INPUT filter rule to block DNS requests and yet after I flush the DNS cache I immediately see some strange DNS cache entries that get refreshed every 5 minutes such as the following:
1 name="e221.en25.com" address=209.167.231.221 ttl=52m10s
2 name="mail98.atl91.mcsv.net" address=198.2.130.98 ttl=4h5m8s
3 name="mail.gradualapproach.net" address=198.54.117.200 ttl=21m17s
4 name="mail.gradualapproach.net" address=198.54.117.197 ttl=21m17s
5 name="mail.gradualapproach.net" address=198.54.117.199 ttl=21m17s
6 name="mail.gradualapproach.net" address=198.54.117.198 ttl=21m17s
7 name="mail34.sgml1.com" address=77.74.123.169 ttl=15m28s
9 name="mail.programsmanagement.com" address=204.11.56.48 ttl=4m15s
11 name="mail.servicemailnetwork.com" address=204.11.56.48 ttl=2m1s
13 name="mail.jamesfigurine.com" address=83.167.229.42 ttl=1m18s
I have another Mikrotik router with the same OS version although different models but does not show such entries.
I have to conclude that these are requests that came from the router itself .
Have any of you see such thing?
Should I be alarmed?
How do I find out which model or task withing the routeros is requesting these URLs to be resolved?
Your input is highly appreciated.
Thanks