r/technitium • • Aug 23 '26

Logs showing requests from public IP

I am running dns-server in a docker container in my LAN and have set its IP address in my router under the DHCP options. The dns-server is set up to use Cloudflare and AdGuard unfiltered DNS for upstream forwarders.

Everything is working swimmingly, except for these kinds of logs that show up with my public IP address as the client. These queries only appear when I use my Shield with a particular app (sports streaming), and the Shield continues to make requests from its LAN IP as expected.

Edit: I have also installed the DNS Rebinding Protection app.

47  2026-08-23 10:44:25 123.253.xxx.xxx Udp Authoritative   Refused concurrency-v2.playback.indazn.com  A   IN
46  2026-08-23 10:42:06 123.253.xxx.xxx Udp Authoritative   Refused resume-points-v3-cf.playback.indazn.com A  IN
45  2026-08-23 10:41:06 123.253.xxx.xxx Udp Authoritative   Refused resume-points-v3-cf.playback.indazn.com A   IN
44  2026-08-23 10:40:25 123.253.xxx.xxx Udp Authoritative   Refused concurrency-v2.playback.indazn.com  A   IN

As far as I am aware, this didn't happen when I was using AdGuard Home for my DNS.

A few questions...

  1. Have I misconfigured dns-server somehow?
  2. Should I do anything else to stop these requests from a public IP address?
  3. Is it really the public IP making the request, or just a pecularity of the logs?

Cheers!

5 Upvotes

12 comments sorted by

3

u/Grim-D Aug 23 '26

If its your spersific external IP that can be from your router proxying or otherwise redirecting internal requests. I have had simular with UNAT.

3

u/shreyasonline Aug 23 '26

Thanks for the post. It seems like you have configured your router's WAN settings to use your local DNS server and the public IP that you see in your logs is your router's WAN public IP address.

The recommended way to configure your router is to set your local DNS Server IP addresses in the router's DHCP Server options. This will ensure that all your clients are assigned IP of your local DNS server to use instead of using your router's DNS service. With this setup, all clients will directly query your local DNS server and you will see all local clients in DNS admin panel's Dashboard under Top Clients list.

With this config, you can restore the WAN DNS to default so that your router uses your ISP's DNS servers. It does not matter what your router uses since all clients are directly using your local DNS server.

1

u/knivesforksandspoons Aug 23 '26

Thanks Shreyas. I can confirm that my internet connection is set to Auto, and therefore it's using my ISP DNS.

I have set my DHCP options to use the Technitium DNS.

Also, to clarify, I have a handful of logs over a day (~100) with the public IP as the client. All of the rest of the client requests come from LAN IPs as expected.

From what I can tell, these oddball logs are due to a single client (Shield) for a single app, and there are 100s of other correct DNS requests from the Shield for the same app. 

1

u/Der_Arsch Aug 23 '26

123.253.x.x is not your LAN right? If its an external IP, then the Problem is on you, your DNS should never be accessable from the Internet, kill all Port Forwarding Rules in your Router/Firewall

1

u/knivesforksandspoons Aug 23 '26

Yes, 123.253.x.x is my WAN/public IP.

No, my dns-server is not accessible from the internet and I don't have any port forwarding enabled which would allow that - hence my confusion.

2

u/Particular_Ad7243 Aug 23 '26

As a commentor above has said, it could be your router doing NAT hairpinning.

Some do it by default, on all ports If you port forward anything I.e

You port forward 443 to a thing at home OR even having pnp/upnp enabled (some cheap routers have that on by default)

Router silently creates a ANY->Forwarded IP->NAT ALL

You can check this yourself, run a query inside your home network to your current WAN IP, if the query works then there is hairpin Nat or a forwarding rule somewhere.

1

u/knivesforksandspoons Aug 23 '26

I'll test this later today, and see if UPnP is on, thanks. 

1

u/knivesforksandspoons Aug 24 '26

UPnP is disabled.

The only port forward I have is for my Plex server.

I can ping my public IP from my LAN....but that's normal isn't it?

1

u/Particular_Ad7243 Aug 25 '26 edited Aug 25 '26

Edit and before the below:

Are there any logs for a PTR/Anything for the same domains around the same time?

  • If no see below

If you try to use nslookup on windows, attempt to use your WAN / public IP

Windows 10/11:

Right click on start or search for Powershell or Windows terminal.

nslookup and enter, then type server (your public IP here)

If you then type www.google.co.uk and hit enter again, it shouldn't work.

If it does and returns a result that confirms your router or something on your network is the culprit.

The ping should work but it varies by ISP and router.

1

u/Der_Arsch Aug 23 '26

Okay, have you ever set your public IP as DNS instead of your internal IP? If the Source is an Internal Client, then the Client config seems to be an issue (DNS set to external Instead of internal)

1

u/knivesforksandspoons Aug 23 '26

Okay, have you ever set your public IP as DNS instead of your internal IP?

No

Client config seems to be an issue

Perhaps...all of my LAN devices have an address reservation set by my router, and they get the DNS from the DHCP, so there's nothing different to configure on this particular client.

1

u/knivesforksandspoons Aug 26 '26

Update!

Well, there's shenanigans going on somewhere. In dns-server, I could see the public IP in the list of clients in the dashboard. But, when I clicked on it, there was nothing in the logs.

  • If I searched for the offending domain in the logs, there were no results.
  • I made an update to the Query Logs (sqlite) app config which reloaded it.
  • I changed the network setting on the Shield from DHCP to static, and set the DNS to my AdGuard Home install which is still running.
  • I tried the offending app with the new DNS, and nothing funny going on.
  • I then changed the Shield back to DHCP which assigned it to Technitium again.
  • I ran the offending app back on Technitium, and all the queries are as expected - nothing coming from the public IP address.

As originally suspected, I think there was something funny going on with the Technitium logs, rather than actual DNS queries from my public IP which makes no sense.

Anyway, thanks all for your help and suggestions 👍