Once upon a time, Ken A <ka at pacific.net> said:
> Chris Adams wrote:
> >In our case, it appears to all be coming from customer DSL routers.
> >Even when running NAT, a number of models of consumer routers appear to
> >proxy DNS requests made on the WAN interface back to our nameservers.
> Are they listening on udp 53 on the wan interface? Do you know which dsl 
> router models are doing this? Sounds like a bug that needs to be fixed.

I asked one of our DSL guys to dig a little, and he found that the Zoom
X5 DSL (and I believe X6 DSL router with wireless) router will listen on
the WAN interface for DNS requests by default _if_ they have DNS servers
configured or receive them as part of PPP negotiation.

There is an option to turn this off under the advanced settings.

