Wireshark-users: Re: [Wireshark-users] DNS traffic - newbie question

From: Stephen Fisher <stephentfisher@xxxxxxxxx>
Date: Mon, 11 Dec 2006 11:48:32 -0800
On Mon, Dec 11, 2006 at 11:33:14AM -0800, Scott Parkis wrote:

> I am looking at my capture. My machine is connected via a swith to the 
> LAN. I have a ton of standard queries coming from my machine going out 
> to the LAN. Not sure why, I am not making the DNS request. It does go 
> to my internal DNS servers. But half of the machines are on the LAN 
> and the other half do not exist.
> 
> What is it that I am seeing here. Thanks,

You're probably seeing DNS requests from Wireshark.  By default, it 
does a DNS lookup on every IP address it sees in the capture that you're 
doing.  This can be disabled under the View -> Name Resolution menu by 
unchecking "Enable for Network Layer."


Steve