All,
Times UTC in this post:
root@OpenWrt:~# tcpdump -vv -i eth0.2 proto 4 and host 89.229.166.34
15:30:07.246887 IP (tos 0x0, ttl 64, id 658, offset 0, flags [DF], proto IPIP (4), length
492)
pool-173-66-138-124.washdc.fios.verizon.net > host-89-229-166-34.dynamic.mm.pl:
IP (tos 0x0, ttl 63, id 37286, offset 0, flags [DF], proto TCP (6), length 472)
dns-mdc.ampr.org.53 > sq4bjo.ampr.org.49277: Flags [.], cksum 0x198a (correct), seq
1:421, ack 52, win 227, options [nop,nop,TS val 644116773 ecr 886448869], length 420 61816
q: DS?
ampr.org. 0/6/1 ns: org. SOA a0.org.afilias-nst.info. noc.afilias-nst.info.
2013855735 1800 900 604800 86400, org. RRSIG,
atjop9o5etdmctlc3gics8odi0er6i6k.org.
RRSIG[|domain]
15:30:07.247010 IP (tos 0x0, ttl 64, id 659, offset 0, flags [DF], proto IPIP (4), length
410)
pool-173-66-138-124.washdc.fios.verizon.net > host-89-229-166-34.dynamic.mm.pl:
IP (tos 0x0, ttl 63, id 37287, offset 0, flags [DF], proto TCP (6), length 390)
dns-mdc.ampr.org.53 > sq4bjo.ampr.org.49277: Flags [P.], cksum 0xe3e8 (correct), seq
421:759, ack 52, win 227, options [nop,nop,TS val 644116773 ecr 886448869], length 338
41210 op6 NotZone|$ [8240q] q: Type40139 (Class 56493)?
?QtHM-;M-q_^^^BM-%M-h^DM-^HzM-@M-|^@2^@^A^@^@^CM-^D^@&^A^A^@^A^DM-SM-^YM-jM-+^TWj}[wpe^WM-^?j^V'M-^[M-^QM-^AM-<M-^Q~^?M-s^@^F@^@^@^@^@^B
h9p7u7tr2u91d0v0ljs9l1gidnp90u3hM-A;^@.^@^A^@^@^CM-^D^@M-^W^@2^G^B^@^AQM-^@^M-^HM-'M-Q^lM-jAM-^AM-9^Corg.,
q:[|domain]
I've seen little DNS traffic that I'd define as "normal"...
- KB3VWG