UCS is calling the Root-DNS Server permanently

Hi,
I‘ve maintained my firewall with some more restriktive rules and found out, that the UCS is permanently calling the Root-DNS Server with UDP Calls on Port 53.
Is there any reason for this?
Usually the UCS should use the Standard Gateway for DNS requests.
Kind regards,
Frank

I just came across the same issue during the last security audit.

We’ve tightened our internal policies, and now only DoT traffic is allowed through the firewall. We’ve also disabled DNS access from the internal network to the internet. It’s not necessary, after all.
And I observed exactly the same behavior in the firewall log, continuous requests to DNS root servers. Can this behavior be changed? Is there a specific reason why the root servers are being queried constantly?
Because to me, this looks like a data protection issue for those where DoT is relevant.

Thank you very much :slight_smile:

It also lists countries that I wouldn’t want to visit, such as China or Colombia.