STIGQter STIGQter: STIG Summary: Infoblox 8.x DNS Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

All authoritative DNS service members for a zone must be geographically dispersed.

DISA Rule

SV-233859r1156964_rule

Vulnerability Number

V-233859

Group Title

SRG-APP-000218-DNS-000027

Rule Version

IDNS-8X-400001

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the authoritative DNS service members to be geographically dispersed.

Most optimal to least optimal (to provide context):
- DNS service members are located on different continents.
- DNS service members are located on the same continent, with greatest possible geographic dispersity.
- DNS service members are located in different states/provinces.
- DNS service members are located in different cities.
- DNS service members are located in different buildings.
- DNS service members are located in different data centers.
- DNS service members are located at opposite ends of the same data center.
- If moving DNS service members is not feasible, reconfigure one of the co-located service members to be a hidden primary.

Check Contents

1. Navigate to Data Management >> DNS >> Zones tab.
2. Review each zone by clicking "Edit" and inspecting the "DNS service members" tab.
3. Review the DNS service member records for each zone hosted and confirm that each authoritative DNS service member is located at a different physical location than the remaining DNS service members.
4. Infoblox supports designation as a "stealth" DNS service member, which will not have an NS record.

If all DNS service members for which NS records are published within a zone are not physically at different locations, this is a finding.

Vulnerability Number

V-233859

Documentable

False

Rule Version

IDNS-8X-400001

Severity Override Guidance

1. Navigate to Data Management >> DNS >> Zones tab.
2. Review each zone by clicking "Edit" and inspecting the "DNS service members" tab.
3. Review the DNS service member records for each zone hosted and confirm that each authoritative DNS service member is located at a different physical location than the remaining DNS service members.
4. Infoblox supports designation as a "stealth" DNS service member, which will not have an NS record.

If all DNS service members for which NS records are published within a zone are not physically at different locations, this is a finding.

Check Content Reference

M

Target Key

5251