SV-233902r1156963_rule
V-233902
SRG-APP-000176-DNS-000076
IDNS-8X-500005
CAT II
10
1. Navigate to Data Management >> DNS >> Zones tab.
2. Select a zone identified in the Check and click "Edit".
3. Click on the "Name Servers" tab and configure a unique TSIG key for each non-Grid DNS service member, designated as type Ext.
4. Verify that the same TSIG key (Algorithm and Key Data) are configured on both DNS service members.
5. Click on the "Zone Transfers" tab.
6. If the DNS service member configured above is not present, click "Override" for the "Allow Zone Transfers to" section. Use the radio button to select "Set of ACEs" and the "Add" drop-down to configure the DNS service member configured above.
7. When complete, click "Save & Close" to save the changes and exit the "Properties" screen.
8. Repeat for any other zones identified in the Check as noncompliant.
9. Perform a service restart if necessary.
10. Verify zone transfers are operational after configuration of TSIG.
Note: HMAC-SHA256 is the preferred algorithm to generate TSIG keys and should be used unless the External DNS service member only supports HMAC-MD5.
1. Navigate to Data Management >> DNS >> Zones tab.
2. Review each zone by clicking "Edit" and inspecting the "NAME Servers" tab.
3. If the all entries in the "Type" column are configured as "Grid", this check is Not Applicable.
4. Verify that all DNS service members of type Ext (Primary or Secondary) have a TSIG key configured.
5. Each zone that contains Ext non-Grid DNS service members must also be verified by inspection of the "Zone Transfers" tab and configuration of an Access Control Entry (ACE) that limits access to only the TSIG configured DNS service members.
6. When complete, click "Cancel" to exit the "Properties" screen.
If there is an external non-Grid system that uses zone transfers but does not have a DNS service member with a unique TSIG key, this is a finding.
V-233902
False
IDNS-8X-500005
1. Navigate to Data Management >> DNS >> Zones tab.
2. Review each zone by clicking "Edit" and inspecting the "NAME Servers" tab.
3. If the all entries in the "Type" column are configured as "Grid", this check is Not Applicable.
4. Verify that all DNS service members of type Ext (Primary or Secondary) have a TSIG key configured.
5. Each zone that contains Ext non-Grid DNS service members must also be verified by inspection of the "Zone Transfers" tab and configuration of an Access Control Entry (ACE) that limits access to only the TSIG configured DNS service members.
6. When complete, click "Cancel" to exit the "Properties" screen.
If there is an external non-Grid system that uses zone transfers but does not have a DNS service member with a unique TSIG key, this is a finding.
M
5251