STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS DNS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The platform on which the name server software is hosted must be configured to respond to DNS traffic only.

DISA Rule

SV-265985r1024493_rule

Vulnerability Number

V-265985

Group Title

SRG-APP-000516-DNS-000109

Rule Version

F5BI-DN-300016

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. For any virtual servers listening that are not associated with DNS, check the box next to the virtual server and click "Delete".
4. Click "Delete" again.

Check Contents

If the BIG-IP does not have the role of authoritative DNS server, this is not applicable.

From the BIG-IP GUI:

1. Local Traffic.
2. Virtual Servers.
3. Verify the list of virtual servers are not configured to listen for non-DNS services.

If the BIG-IP appliance is configured to respond traffic other than DNS, this is a finding.

Vulnerability Number

V-265985

Documentable

False

Rule Version

F5BI-DN-300016

Severity Override Guidance

If the BIG-IP does not have the role of authoritative DNS server, this is not applicable.

From the BIG-IP GUI:

1. Local Traffic.
2. Virtual Servers.
3. Verify the list of virtual servers are not configured to listen for non-DNS services.

If the BIG-IP appliance is configured to respond traffic other than DNS, this is a finding.

Check Content Reference

M

Target Key

5638