Skip to main content
jimmy0460
New Member
February 28, 2025
Question

ISC.BIND.Multiple.Options.Processing.DoS alerts started this morning

  • February 28, 2025
  • 1 reply
  • 563 views

Our FG120G started alerting to ISC.BIND.Multiple.Options.Processing.DoS blocked DNS traffic this morning, just occasionally (let's say 10 alerts in 10 hours), all from different Windows laptop clients talking to our DNS servers at the datacentre.

I don't have any particular insight as to why this might have started. Perhaps a false positive. Perhaps Fortinet updated signatures. Perhaps Windows patches changed something.

Just wondering if anyone else is noticing this issue. Hoping it isn't just me ...

1 reply

firacode
New Member
February 28, 2025

The ISC.BIND.Multiple.Options.Processing.DoS alerts you're seeing could be due to false positives, Fortinet signature updates, or changes in Windows client behavior after recent patches. This typically indicates unusual or potentially malicious DNS traffic, such as malformed DNS requests. To resolve this, check for recent Windows updates, review Fortinet signature changes, and examine DNS query logs for unusual patterns. If the alerts persist, consider fine-tuning your detection rules or consulting Fortinet support for further assistance.