Support Center > Search Results > SecureKnowledge Details
DNS traffic is dropped by IPS with log "Attack Information: Bad Resource Record format, Illegal EDNS0 RR"
Symptoms
  • DNS traffic is dropped by IPS with log "Attack Information: Bad Resource Record format, Illegal EDNS0 RR".

    Example:
    Type: Log
    Action: Drop
    Service: domain-udp (53)
    Protocol: udp
    Attack Type: Non Compliant DNS
    Attack Information: Bad Resource Record format, Illegal EDNS0 RR
    Product: IPS Software Blade
    Protection ID: DnsProtocolEnforcement
    Protection Name: Non Compliant DNS
    Protection Type: Protocol Anomaly DNS
    
Cause

IPS drops DNS packets whose "Z" field is not null (in the OPT Record TTL field, refer to RFC 6891).


Solution
Note: To view this solution you need to Sign In .