[root@monitor ~]# tcpdump -nnvvi eth0 host 192.168.10.14 and port 53 tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes 11:13:29.460828 IP (tos 0x0, ttl 128, id 10709, offset 0, flags [none], proto UDP (17), length 73) 192.168.3.223.54134 > 192.168.10.14.53: [udp sum ok] 15534+ [1au] A? www.sensoray.com. ar: . OPT UDPsize=4096 (45) 11:13:29.461229 IP (tos 0x0, ttl 64, id 27270, offset 0, flags [none], proto UDP (17), length 73) 192.168.10.14.58286 > 74.82.42.42.53: [udp sum ok] 14107+% [1au] A? wwW.SeNSorAy.COm. ar: . OPT UDPsize=4096 OK (45) 11:13:30.946166 IP (tos 0x0, ttl 57, id 47796, offset 0, flags [DF], proto UDP (17), length 92) 74.82.42.42.53 > 192.168.10.14.58286: [udp sum ok] 14107 q: A? wwW.SeNSorAy.COm. 2/0/0 wwW.SeNSorAy.COm. CNAME SeNSorAy.COm., SeNSorAy.COm. A 192.254.184.23 (64) 11:13:30.946554 IP (tos 0x0, ttl 64, id 64243, offset 0, flags [none], proto UDP (17), length 69) 192.168.10.14.64634 > 8.8.8.8.53: [udp sum ok] 51194+% [1au] A? SEnsoray.com. ar: . OPT UDPsize=4096 OK (41) 11:13:30.131235 IP (tos 0x0, ttl 58, id 18335, offset 0, flags [none], proto UDP (17), length 85) 8.8.8.8.53 > 192.168.10.14.64634: [udp sum ok] 51194 q: A? SEnsoray.com. 1/0/1 SEnsoray.com. A 192.254.184.23 ar: . OPT UDPsize=512 OK (57) 11:13:30.131470 IP (tos 0x0, ttl 64, id 4809, offset 0, flags [none], proto UDP (17), length 87) 192.168.10.14.53 > 192.168.3.223.54134: [udp sum ok] 15534 q: A? www.sensoray.com. 1/0/1 www.sensoray.com. CNAME sensoray.com. ar: . OPT UDPsize=4096 (59) 11:13:37.592653 IP (tos 0x0, ttl 128, id 10714, offset 0, flags [none], proto UDP (17), length 69) 192.168.3.223.54135 > 192.168.10.14.53: [udp sum ok] 59670+ [1au] A? sensoray.com. ar: . OPT UDPsize=4096 (41) 11:13:37.592781 IP (tos 0x0, ttl 64, id 4810, offset 0, flags [none], proto UDP (17), length 69) 192.168.10.14.53 > 192.168.3.223.54135: [udp sum ok] 59670 q: A? sensoray.com. 0/0/1 ar: . OPT UDPsize=4096 (41) 8 packets captured 8 packets received by filter 0 packets dropped by kernel [root@monitor ~]#