STIGQter STIGQter: STIG Summary: Microsoft Windows 2012 Server Domain Name System Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 23 Apr 2021:

The Windows 2012 DNS Server must be configured to prohibit or restrict unapproved ports and protocols.

DISA Rule

SV-215598r561297_rule

Vulnerability Number

V-215598

Group Title

SRG-APP-000142-DNS-000014

Rule Version

WDNS-CM-000029

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Re-install DNS.

Check Contents

By default, the Windows 2012 DNS Server listens on TCP 53 and opens UDP ports 53. Also by default, Windows 2012 DNS Server sends from random, high-numbered source ports 49152 and above.

To confirm the listening ports, log onto Windows 2012 DNS Server as an Administrator.
Open a command window with the “Run-as Administrator” option.

In the command window, type the following command:
netstat -a -b |more <enter>

The result is a list of all services running on the server, with the respective “LISTENING TCP” and “OPEN UDP” ports being used.

Find Windows 2012 DNS Server service and verify the State is "LISTENING" on TCP port 53 and that UDP 53 is listed (indicating it is OPEN).

If the server shows UDP 53 in results list and shows TCP port 53 as “LISTENING”, this is not a finding.

Vulnerability Number

V-215598

Documentable

False

Rule Version

WDNS-CM-000029

Severity Override Guidance

By default, the Windows 2012 DNS Server listens on TCP 53 and opens UDP ports 53. Also by default, Windows 2012 DNS Server sends from random, high-numbered source ports 49152 and above.

To confirm the listening ports, log onto Windows 2012 DNS Server as an Administrator.
Open a command window with the “Run-as Administrator” option.

In the command window, type the following command:
netstat -a -b |more <enter>

The result is a list of all services running on the server, with the respective “LISTENING TCP” and “OPEN UDP” ports being used.

Find Windows 2012 DNS Server service and verify the State is "LISTENING" on TCP port 53 and that UDP 53 is listed (indicating it is OPEN).

If the server shows UDP 53 in results list and shows TCP port 53 as “LISTENING”, this is not a finding.

Check Content Reference

M

Target Key

4016

Comments