Prefetch DNS Key Support and Suricata Snort Rules
-
When I enabled Prefetch DNS Key Support, I started getting a whole series of Suricata blocks:
[Drop] [] [1:14777:4] PROTOCOL-DNS single byte encoded name response [] [Classification: Misc Attack] [Priority: 2]
…this would cause my whole network to stop working. Only disabling the Prefetch DNS Key Support and a reboot brought my network back to life.
Is anyone aware of why Prefetch DNS Key Support would cause this behavior? Is this a known incompatibility? Google searches lead nowhere on this.
Thanks.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.