cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
263
Views
2
Helpful
1
Replies

IDS SIG 6057

z_wick
Level 1
Level 1

DNS SIG Overflow from our ISP's DNS server to our internal DNS server. We have Novell 5.1 using DNS and using our ISP's DNS as forwarder. Any Idea why there server would be triggering this signature?

Thank you

1 Reply 1

umedryk
Level 5
Level 5

This alarm triggers when a DNS server response arrives that has a long SIG resource where the length of the resource data is > 2069 bytes OR the length of the TCP stream containing the SIG resource is > 3000 bytes.