I've a Nameserver behind my ipchains-firewall and the log says something about incoming connections to port 53 from port 53. What kind of Nameserver-service is that? I've searched, but found nothing concerning this connections.
It could just be a nameserver querying your nameserver while the source port to use has been configured to 53. This isn't usually the case, but some admin just might have thought that it is a good idea. I wouldn't do it because it obfuscates the logs. If it's tcp and not udp, then someone might have tried to get zone files from you. Then it is interesting, _who_ did that, with which reason.
Thanks for help. Max
Thanks, Roman. -- - - | Roman Drahtmüller <draht@suse.de> // "Caution: Cape does | SuSE GmbH - Security Phone: // not enable user to fly." | Nürnberg, Germany +49-911-740530 // (Batman Costume warning label) | - -