Hi All,<br><br>We run a bunch of authoritative servers and have recently observed activity best described in a post we found here: <a href="https://isc.sans.edu/diary/DNS+ANY+Request+Cannon+-+Need+More+Packets/13261">https://isc.sans.edu/diary/DNS+ANY+Request+Cannon+-+Need+More+Packets/13261</a><br>
<br>Using the iptables rules posted as a comment by <span class="commentauthor">Network Mouse (in the above post), we've been able to reduce the amount of junk being sent to the target host.</span> <span class="commentauthor"><span class="commentauthor">Most of the target hosts seem to be in Asia, just like those mentioned in the Sans post. <br>
<br></span>The question I have for you all is: Is this something affecting other operators? How have you been dealing with it? <br><br>Thanks in advance for your feedback.<br><br>-Rob<br><br><br><br></span>