STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS DNS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

Primary authoritative name servers must be configured to only receive zone transfer requests from specified secondary name servers.

DISA Rule

SV-265983r1024490_rule

Vulnerability Number

V-265983

Group Title

SRG-APP-000516-DNS-000095

Rule Version

F5BI-DN-300014

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. DNS.
2. Zones.
3. Zone List.
4. Click on the Name of the Zone.
5. Move only Nameservers to the "Active" column under "Zone Transfer Clients" that are allowed to request zone transfers.
6. Click "Update".

Check Contents

If the BIG-IP is transferring zones from another non-BIG-IP DNS server perform the following.

From the BIG-IP GUI:
1. DNS.
2. Zones.
3. Zone List.
4. Click on the name of the Zone.
5. Verify "Zone Transfer Clients" >> "Active" column shows only the nameservers that are allowed to request zone transfers.

If the BIG-IP appliance is not configured to limit the secondary name servers from which an authoritative name server receives zone transfer requests, this is a finding.

Vulnerability Number

V-265983

Documentable

False

Rule Version

F5BI-DN-300014

Severity Override Guidance

If the BIG-IP is transferring zones from another non-BIG-IP DNS server perform the following.

From the BIG-IP GUI:
1. DNS.
2. Zones.
3. Zone List.
4. Click on the name of the Zone.
5. Verify "Zone Transfer Clients" >> "Active" column shows only the nameservers that are allowed to request zone transfers.

If the BIG-IP appliance is not configured to limit the secondary name servers from which an authoritative name server receives zone transfer requests, this is a finding.

Check Content Reference

M

Target Key

5638