What does "Unknown: Malform Packet" in Nebula logs mean, and how is it handled?
Zyxel Employee
Question:
What does "Unknown: Malform Packet" in Nebula logs mean, and how is it handled?
Answer:
The log message "Unknown: Malform Packet" indicates that DNS Threat Filter has detected a DNS packet that does not conform to the expected format.
A DNS packet is considered malformed under these specific conditions:
- The number of entries in the question count field in the DNS header is 0.
- An error occurs when parsing the domain name in the question field.
- The length of the domain name exceeds 255 characters.
These malformed DNS packets are detected by the DNS Threat Filter service, which is designed to identify and manage potentially harmful or improperly formatted DNS traffic.
Under the "Malform DNS packets" setting, you can define the Action (e.g., drop to block the packet) and whether to Log the event (e.g., log to record it in your event logs). The appearance of "Unknown: Malform Packet" in your logs means that the logging option for malformed DNS packets is enabled.
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 237 Nebula Ideas
- 6.8K Security
- 740 USG FLEX H Series
- 376 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 319 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 91 About Community
- 119 Security Highlight

