STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS DNS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP DNS server implementation must validate the binding of the other DNS server's identity to the DNS information for a server-to-server transaction (e.g., zone transfer).

DISA Rule

SV-265987r1024862_rule

Vulnerability Number

V-265987

Group Title

SRG-APP-000349-DNS-000043

Rule Version

F5BI-DN-300020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Nameservers.
4. Click the Name of the Nameserver.
5. Select a value from the "TSIG Key" drop-down menu.
Note: To create a TSIG Key, go to DNS >> Delivery >> Keys >> TSIG Key List.
6. Click "Finished".

Check Contents

From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Nameservers.
4. Click the Name of the Nameserver.
5. Verify that a value is selected for "TSIG Key".

If the BIG-IP appliance is not configured to validate the binding of the other DNS server's identity to the DNS information for a server-to-server transaction (e.g., zone transfer), this is a finding.

Vulnerability Number

V-265987

Documentable

False

Rule Version

F5BI-DN-300020

Severity Override Guidance

From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Nameservers.
4. Click the Name of the Nameserver.
5. Verify that a value is selected for "TSIG Key".

If the BIG-IP appliance is not configured to validate the binding of the other DNS server's identity to the DNS information for a server-to-server transaction (e.g., zone transfer), this is a finding.

Check Content Reference

M

Target Key

5638