Description |
This article explains why FortiOS DNS services respond with NOTIMP (Not Implemented) to DNS queries of type ANY (QTYPE=255) when the FortiGate is acting as a DNS server. This behavior is intentional, in line with modern DNS best practices, and serves both security and performance goals. |
Scope |
FortiOS DNS applies to both IPv4 and IPv6 DNS queries. |
Solution |
What is a DNS ANY Query. A DNS query of type ANY (QTYPE=255) asks for all record types (A, AAAA, MX, TXT, etc.) associated with a domain name. Though originally intended for diagnostics, ANY queries are now considered unreliable, deprecated, and often exploited in DNS amplification attacks.
FortiOS Behavior. When FortiOS receives a DNS query of type ANY, it responds with the response code NOTIMP (RCODE 4), indicating that the query type is not implemented.
FortiOS Respond with NOTIMP. This behavior is intentional and aligns with:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.