I continue to receive query traffic as follows:
They're hitting my server(s) like A DOS attack.
over the past months, these arrive approx. every thirty seconds. whois reverals that they come from28-Feb-2018 08:24:19.885 queries: info: client 192.168.1.1#35561 (6.43.186.222.in-addr.arpa): query: 6.43.186.222.in-addr.arpa IN PTR + (192.168.1.73)
28-Feb-2018 08:24:52.169 queries: info: client 192.168.1.1#32016 (6.43.186.222.in-addr.arpa): query: 6.43.186.222.in-addr.arpa IN PTR + (192.168.1.73)
28-Feb-2018 08:25:27.664 queries: info: client 192.168.1.1#28753 (6.43.186.222.in-addr.arpa): query: 6.43.186.222.in-addr.arpa IN PTR + (192.168.1.73)
With apologies, I do not know to interpret the format of the logged data, and I cannot find a clear, concise record layout for the logged data. It looks (to me) like they are looking for a PTR record . . .but why and how can I prevent this from constantly recurring every thirty seconds? Their IP address may change if and when I add the address to a "black-ball" list.inetnum: 222.184.0.0 - 222.191.255.255
netname: CHINANET-JS
descr: CHINANET jiangsu province network
descr: China Telecom
descr: A12,Xin-Jie-Kou-Wai Street
descr: Beijing 100088
country: CN
They're hitting my server(s) like A DOS attack.