I have a Cisco Firepower 3110 FTD and discovered some strange traffic while troubleshooting another problem. The Firepower is making DNS PTR queries to Umbrella/OpenDNS from IP addresses outside the configured /23 on the outside interface. I have verified that the queries are coming from the Firepower mac address with many source IP addresses, 1610 on the last packet capture spanning about 1 hour. The queries are occurring about once per second and are made in groups of 10-30 IP addresses from the same block, for example 44 queries to 208.69.36.0/24 over 12 seconds . Does anyone have any idea what is causing this?
The interface is configured with 172.xx.xx.xx/23. It is configured to use Umbrella for DNS resolution.