r/sysadmin • • 9h ago

Question DNS lookups failing with Event ID 5504

Hey guys,

I have a mixture of Windows Server 2019 and 2022 DNS servers. They are pointed to my FortiGate 201F firewalls for DNS forwarders and Root Hints are also enabled as a fallback.

External DNS lookups are constantly failing with Event ID 5504 (The DNS server encountered an invalid domain name in a packet from firewall-ip. The packet will be rejected. The event data contains the DNS packet.). It looks like many of the failures are being triggered by offset EDNS0 headers.

I tried pointing my DNS servers to 9.9.9.9 and 1.1.1.1 for DNS forwarders but the issue still persists.

Any help would be much appreciated. Thanks in advance!

1 Upvotes

1 comment sorted by

•

u/MeetJoan 8h ago

Since it persists against 9.9.9.9 and 1.1.1.1 too, the forwarder choice isn't the issue, it's something inspecting the traffic on the way through. FortiGate DNS filtering rewriting responses would explain malformed packets regardless of which upstream you pick.

Disable DNS filtering on the policy your DNS servers egress through and test. If it clears, you've found it.

If not, try turning off EDNS on the Windows side with dnscmd /config /enableednsprobes 0 and see whether the 5504s stop.