STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS DNS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP DNS implementation must prohibit recursion on authoritative name servers.

DISA Rule

SV-265980r1024486_rule

Vulnerability Number

V-265980

Group Title

SRG-APP-000383-DNS-000047

Rule Version

F5BI-DN-300011

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the BIG-IP has the role of authoritative DNS server, then configure as follows.

From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Profiles.
4. DNS.
5. Click the name of the profile used for the authoritative listener.
6. Configure the following settings:
a. Use BIND Server on BIG-IP: Disabled
b. DNS Cache: Disabled
7. Click "Update".

Check Contents

If the BIG-IP does not have the role of authoritative DNS server, this is not applicable.

From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Profiles.
4. DNS.
5. Click the name of the profile used for the authoritative listener.
6. Verify the following settings:
a. Use BIND Server on BIG-IP: Disabled
b. DNS Cache: Disabled

If the BIG-IP appliance is not configured to prohibit recursion on authoritative name servers, this is a finding.

Vulnerability Number

V-265980

Documentable

False

Rule Version

F5BI-DN-300011

Severity Override Guidance

If the BIG-IP does not have the role of authoritative DNS server, this is not applicable.

From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Profiles.
4. DNS.
5. Click the name of the profile used for the authoritative listener.
6. Verify the following settings:
a. Use BIND Server on BIG-IP: Disabled
b. DNS Cache: Disabled

If the BIG-IP appliance is not configured to prohibit recursion on authoritative name servers, this is a finding.

Check Content Reference

M

Target Key

5638