Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jimmy0460
New Contributor

ISC.BIND.Multiple.Options.Processing.DoS alerts started this morning

Our FG120G started alerting to ISC.BIND.Multiple.Options.Processing.DoS blocked DNS traffic this morning, just occasionally (let's say 10 alerts in 10 hours), all from different Windows laptop clients talking to our DNS servers at the datacentre.

I don't have any particular insight as to why this might have started. Perhaps a false positive. Perhaps Fortinet updated signatures. Perhaps Windows patches changed something.

Just wondering if anyone else is noticing this issue. Hoping it isn't just me ...

10.0.0.0.1 192.168.1.254
1 REPLY 1
firacode
New Contributor II

The ISC.BIND.Multiple.Options.Processing.DoS alerts you're seeing could be due to false positives, Fortinet signature updates, or changes in Windows client behavior after recent patches. This typically indicates unusual or potentially malicious DNS traffic, such as malformed DNS requests. To resolve this, check for recent Windows updates, review Fortinet signature changes, and examine DNS query logs for unusual patterns. If the alerts persist, consider fine-tuning your detection rules or consulting Fortinet support for further assistance.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors