Weird logs in Unbound DNS - aoc.gov?

Started by xpking, September 17, 2023, 10:44:44 AM

Previous topic - Next topic
September 17, 2023, 10:44:44 AM Last Edit: September 17, 2023, 12:24:29 PM by xpking
Dear all,

When I checked the logs of Unbound DNS, it shows me a lot of query and reply of aoc.gov (example below).
Is this normal?
I don't have any DNS issues. But I am feeling weird of these logs.

2023-09-17T16:43:41   Informational   unbound   [38957:2] query: 220.135.223.125 aoc.gov. ANY IN   
2023-09-17T16:43:41   Informational   unbound   [38957:2] reply: 220.135.223.125 aoc.gov. ANY IN NOERROR 0.000000 0 1080   
2023-09-17T16:43:41   Informational   unbound   [38957:2] query: 220.135.223.125 aoc.gov. ANY IN   
2023-09-17T16:43:41   Informational   unbound   [38957:2] reply: 220.135.223.125 aoc.gov. ANY IN NOERROR 0.000000 0 1080   
2023-09-17T16:43:41   Informational   unbound   [38957:2] query: 220.135.223.125 aoc.gov. ANY IN   
2023-09-17T16:43:41   Informational   unbound   [38957:2] reply: 220.135.223.125 aoc.gov. ANY IN NOERROR 0.000000 0 1080   
2023-09-17T16:43:41   Informational   unbound   [38957:2] query: 220.135.223.125 aoc.gov. ANY IN   
2023-09-17T16:43:41   Informational   unbound   [38957:2] reply: 220.135.223.125 aoc.gov. ANY IN NOERROR 0.000000 0 1080   
2023-09-17T16:43:41   Informational   unbound   [38957:2] query: 220.135.223.125 aoc.gov. ANY IN   
2023-09-17T16:43:41   Informational   unbound   [38957:2] reply: 220.135.223.125 aoc.gov. ANY IN NOERROR 0.000000 0 1080   
2023-09-17T16:43:41   Informational   unbound   [38957:2] query: 220.135.223.125 aoc.gov. ANY IN   
2023-09-17T16:43:41   Informational   unbound   [38957:2] reply: 220.135.223.125 aoc.gov. ANY IN NOERROR 0.000000 0 1080   
2023-09-17T16:43:41   Informational   unbound   [38957:2] query: 220.135.223.125 aoc.gov. ANY IN   
2023-09-17T16:43:41   Informational   unbound   [38957:2] reply: 220.135.223.125 aoc.gov. ANY IN NOERROR 0.000000 0 1080   
2023-09-17T16:43:41   Informational   unbound   [38957:2] query: 220.135.223.125 aoc.gov. ANY IN   
2023-09-17T16:43:41   Informational   unbound   [38957:2] reply: 220.135.223.125 aoc.gov. ANY IN NOERROR 0.000000 0 1080   
2023-09-17T16:43:41   Informational   unbound   [38957:2] query: 220.135.223.125 aoc.gov. ANY IN   
2023-09-17T16:43:41   Informational   unbound   [38957:2] reply: 220.135.223.125 aoc.gov. ANY IN NOERROR 0.000000 0 1080   
2023-09-17T16:43:41   Informational   unbound   [38957:2] query: 220.135.223.125 aoc.gov. ANY IN   
2023-09-17T16:43:41   Informational   unbound   [38957:2] reply: 220.135.223.125 aoc.gov. ANY IN NOERROR 0.000000 0 1080

Is that your WAN ip?  I forget the exact format of the Unbound logs for queries but it seems like you might have an open relay.