Patrick Whittle said:
When a Vista computer comes on the LAN, our DNS server has to look to the
IP address: 4.2.2.2 (forwarding) for a name server. Is this
because the number of computers that are powered-on, changes? It seems
that Vista is trying to take priority over DNS.
http://pwhittle.dlinkddns.com/gateway/NAT.htm
Since you posted the firewall logs in your link, I was curious as to what a
reverse lookup would provide on some of the IPs just to rule out any viruses
or bad sites. Running nslookup on a sample of some the IPs in the log,
(posted below), other than the ones that don't have a PTR, which I don't
know what sites they are (which would need to be queried at
http://arin.net
for more info), the rest of the samples I used resolve to legit sites, such
as Facebook, Yahoo, Google, possibly Microsoft
(deploy.akamaitechnologies.com), uablerta, Frontiernet, etc. From what I've
found, it appears what you are seeing is legit. If this is all generated
from starting your Vista computer, it would appear there are many items
initializing at startup that are accessing the internet. Some things that
will generate this type of traffic can include instant messenger apps,
Windows Updates, an antivirus and/or antispyware app seeking updates from
their vendors, and other internet based apps.
Are you seeing any errors or problems on your Vista workstation?
Server: london.nwtraders.msft
Address: 192.168.100.200
Name: 64-208-176-34.nas1.mon.ny.frontiernet.net
Address: 64.208.176.34
Server: london.nwtraders.msft
Address: 192.168.100.200
Name: mojofarm.mediaplex.com
Address: 216.34.207.157
Server: london.nwtraders.msft
Address: 192.168.100.200
*** london.nwtraders.msft can't find 205.128.84.126: Non-existent domain
Server: london.nwtraders.msft
Address: 192.168.100.200
*** london.nwtraders.msft can't find 65.55.15.244: Non-existent domain
Server: london.nwtraders.msft
Address: 192.168.100.200
Name: www-11-01-snc2.facebook.com
Address: 69.63.181.12
Server: london.nwtraders.msft
Address: 192.168.100.200
Name: openbsd.sunsite.ualberta.ca
Address: 129.128.5.191
Server: london.nwtraders.msft
Address: 192.168.100.200
Name: a204-2-225-165.deploy.akamaitechnologies.com
Address: 204.2.225.165
Server: london.nwtraders.msft
Address: 192.168.100.200
*** london.nwtraders.msft can't find 198.63.231.42: Non-existent domain
Server: london.nwtraders.msft
Address: 192.168.100.200
Name: channel26.01.05.sf2p.facebook.com
Address: 69.63.176.186
Server: london.nwtraders.msft
Address: 192.168.100.200
*** london.nwtraders.msft can't find 8.18.94.122: Non-existent domain
Server: london.nwtraders.msft
Address: 192.168.100.200
Name: pw-in-f190.google.com
Address: 74.125.53.190
Server: london.nwtraders.msft
Address: 192.168.100.200
Name: webcs102.msg.ac4.yahoo.com
Address: 98.136.113.251
Server: london.nwtraders.msft
Address: 192.168.100.200
Name: 64-208-176-40.nas1.mon.ny.frontiernet.net
Address: 64.208.176.40
Server: london.nwtraders.msft
Address: 192.168.100.200
*** london.nwtraders.msft can't find 76.74.140.165: Non-existent domain
Server: london.nwtraders.msft
Address: 192.168.100.200
*** london.nwtraders.msft can't find 64.236.79.54: Non-existent domain
--
Ace
This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.
Please reply back to the newsgroup or forum for collaboration benefit among
responding engineers, and to help others benefit from your resolution.
Ace Fekay, MCT, MCTS 2008, MCTS Exchange, MCSE, MCSA 2003 & 2000, MCSA
Messaging
Microsoft Certified Trainer
For urgent issues, please contact Microsoft PSS directly. Please check
http://support.microsoft.com for regional support phone numbers.