STIGQter STIGQter: STIG Summary: Infoblox 8.x DNS Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The Infoblox DNS service member must use current and valid root DNS service members.

DISA Rule

SV-233874r1082643_rule

Vulnerability Number

V-233874

Group Title

SRG-APP-000516-DNS-000102

Rule Version

IDNS-8X-400016

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Navigate to Data Management >> DNS >> Grid DNS Properties.
2. Toggle Advanced mode and select the "Root DNS service members" tab.
3. Use the radio button to select "Use custom root DNS service members" and configure the desired root DNS service members.
4. When complete, click "Save & Close" to save the changes and exit the "Properties" screen.
5. Perform a service restart if necessary.

Check Contents

Review the Root DNS service members configured and validate that the entries are correct. "G" and "H" root servers are required on the NIPRNet as a minimum. Note: Validate against the current available DNS root list at the time of check.

1. Validate the current root DNS service member list using external tools at the time of the check.
2. Navigate to Data Management >> DNS >> Grid DNS Properties.
3. Toggle Advanced mode and review the "Root DNS service members" tab to ensure it is configured correctly.

If valid root DNS service members are not configured, this is a finding.

Vulnerability Number

V-233874

Documentable

False

Rule Version

IDNS-8X-400016

Severity Override Guidance

Review the Root DNS service members configured and validate that the entries are correct. "G" and "H" root servers are required on the NIPRNet as a minimum. Note: Validate against the current available DNS root list at the time of check.

1. Validate the current root DNS service member list using external tools at the time of the check.
2. Navigate to Data Management >> DNS >> Grid DNS Properties.
3. Toggle Advanced mode and review the "Root DNS service members" tab to ensure it is configured correctly.

If valid root DNS service members are not configured, this is a finding.

Check Content Reference

M

Target Key

5251