> Source: [sk97730](https://support.checkpoint.com/results/sk/sk97730)

# sk97730 - DNS requests are dropped by IPS as "Non Compliant DNS"

| Property | Value |
|----------|-------|
| Solution ID | sk97730 |
| Date Created | 2013-12-16 |
| Last Modified | 2017-09-10 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * DNS resolving fails.  

* SmartView Tracker shows IPS drops as "`Non Compliant DNS`".  

* Kernel debug (`... fw + drop xlate domain`) shows the following reasons for drops:   

  `
  `
  * ... fw_dns_filter_ex: DNS AD/CD flags failed sanity, flags are 120;
  * ... dns_aspii_data_handler: return ASPII_DROP_PACKET;
  * ... dropped by fwpslglue_chain Reason: PSL Drop: ASPII_MT;

## Cause

The DNS query was sent with AD flag set (1), which was not allowed by RFC.  
Recently the RFC was updated, and now such query is allowed.

RFC 6840 - Clarifications and Implementation Notes for DNS Security (DNSSEC)  
5.7 Setting the AD Bit on Queries

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
