STIGQter STIGQter: STIG Summary: Enterprise Voice, Video, and Messaging Session Management Security Requirements Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The Enterprise Voice, Video, and Messaging Session Manager must be configured to use DNS servers assigned to support the VVoIP system.

DISA Rule

SV-259991r1117236_rule

Vulnerability Number

V-259991

Group Title

SRG-NET-000018

Rule Version

SRG-NET-000018-VVSM-00103

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Consider not using DNS for the VVoIP system unless it is required.

In the event DNS is used in the VVoIP system, ensure the DNS server serving the VVoIP system is dedicated to the VVoIP system and that any DNS server interaction with other DNS servers is limited. Additionally ensure internal system URLs and information is not published to the enterprise WAN or the internet.

NOTE: In the event a DNS server is implemented within the VVoIP system, the DNS STIG must be applied to the server.

Check Contents

Examine the configurations of the DNS server(s) serving the VVoIP system and those outside the system. Attempt to use a system specific URL that should not be published outside the system to see if an IP address is returned.

This is a finding in the event restricted URLs are reachable from outside the restriction zone.

Vulnerability Number

V-259991

Documentable

False

Rule Version

SRG-NET-000018-VVSM-00103

Severity Override Guidance

Examine the configurations of the DNS server(s) serving the VVoIP system and those outside the system. Attempt to use a system specific URL that should not be published outside the system to see if an IP address is returned.

This is a finding in the event restricted URLs are reachable from outside the restriction zone.

Check Content Reference

M

Target Key

5587