- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ISC.BIND.Multiple.Options.Processing.DoS alerts started this morning
Our FG120G started alerting to ISC.BIND.Multiple.Options.Processing.DoS blocked DNS traffic this morning, just occasionally (let's say 10 alerts in 10 hours), all from different Windows laptop clients talking to our DNS servers at the datacentre.
I don't have any particular insight as to why this might have started. Perhaps a false positive. Perhaps Fortinet updated signatures. Perhaps Windows patches changed something.
Just wondering if anyone else is noticing this issue. Hoping it isn't just me ...
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The ISC.BIND.Multiple.Options.Processing.DoS alerts you're seeing could be due to false positives, Fortinet signature updates, or changes in Windows client behavior after recent patches. This typically indicates unusual or potentially malicious DNS traffic, such as malformed DNS requests. To resolve this, check for recent Windows updates, review Fortinet signature changes, and examine DNS query logs for unusual patterns. If the alerts persist, consider fine-tuning your detection rules or consulting Fortinet support for further assistance.
