large amounts of DNS traffic

Question asked by Neil ZInk on Nov 6, 2017
after upgrading to r80.10,  I started seeing some interesting traffic reported as DNS.   




from the individual session



we have DNS locked down to only a few approved servers.   We have IPS rule in place to look for DNS tunneling.


Any thoughts?