My PIX (ver 8.0) has 'ip audit' turned on and it is logging a lot of messages of this type:
IDS:6053 DNS all records request from <source_ip> to <dest_ip> on interface outside".
This messages indicate that there are dns queries 'type any' going on. My DNS servers are working properly. There are about 30 dns zones hosted on then. So, my questions are:
Is there any attack associated with this type of messages?
Is this type of traffic normal?
Is this type of queries commum?
Thanks in advance.