STIGQter STIGQter: STIG Summary: Infoblox 7.x DNS Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

Infoblox systems which perform zone transfers to non-Infoblox Grid DNS servers must be configured to limit the number of concurrent sessions for zone transfers.

DISA Rule

SV-214159r612370_rule

Vulnerability Number

V-214159

Group Title

SRG-APP-000001-DNS-000001

Rule Version

IDNS-7X-000010

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Navigate to Data Management >> DNS >> Members/Servers tab.

Click "Edit" to review each member with the DNS service status of "Running".

Toggle Advanced Mode and select General >> Advanced tab.

Configure both inbound and outbound zone transfer to appropriate values.

When complete, click "Save & Close" to save the changes and exit the "Properties" screen.

Perform a service restart if necessary.

Check Contents

Verify inbound and outbound zone transfer limits are configured. These values control the amount of concurrent zone transfers to non-Grid DNS servers.

Navigate to Data Management >> DNS >> Members/Servers tab.

Review each server with the DNS service enabled.
Select each server, click "Edit", toggle Advanced Mode and select General >> Advanced tab.

Verify zone transfer limitations are configured. If all name servers for all zones utilize a single Infoblox Grid, zone data is transferred via the encrypted Infoblox Grid, this is not a finding.

When complete, click "Cancel" to exit the "Properties" screen.

Vulnerability Number

V-214159

Documentable

False

Rule Version

IDNS-7X-000010

Severity Override Guidance

Verify inbound and outbound zone transfer limits are configured. These values control the amount of concurrent zone transfers to non-Grid DNS servers.

Navigate to Data Management >> DNS >> Members/Servers tab.

Review each server with the DNS service enabled.
Select each server, click "Edit", toggle Advanced Mode and select General >> Advanced tab.

Verify zone transfer limitations are configured. If all name servers for all zones utilize a single Infoblox Grid, zone data is transferred via the encrypted Infoblox Grid, this is not a finding.

When complete, click "Cancel" to exit the "Properties" screen.

Check Content Reference

M

Target Key

3995

Comments