STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS DNS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

A BIG-IP DNS server implementation must provide additional data origin artifacts along with the authoritative data the system returns in response to external name/address resolution queries.

DISA Rule

SV-265988r1024496_rule

Vulnerability Number

V-265988

Group Title

SRG-APP-000213-DNS-000024

Rule Version

F5BI-DN-300028

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

DNSSEC Keys:

From the BIG-IP GUI:
1. DNS.
2. Zones.
3. DNSSEC Zones.
4. DNSSEC Zone List.
5. Click the name of the zone.
6. Move a key for both "Zone Signing Key" and "Key Signing Key" into the "Active" column.
7. Click "Update".
Note: To create a Zone Signing Key and/or Key Signing Key go to DNS >> Delivery >> Keys >> DNSSEC Key List.

DNS Profile:
1. DNS.
2. Delivery.
3. Profiles.
4. DNS.
5. Click the name of the DNS profile being used by the listener.
6. Under DNS Features set "DNSSEC" to "Enabled".
Note: If the setting is grayed out click the box to the right of the setting and then change it.
7. Click "Update".

Check Contents

From the BIG-IP Console, type the following commands:

Note: Assuming you are checking a DNSSEC Zone, from the command line of a management computer, run:
dig +dnssec @<DNS Server IP> <DNSSEC zonename>

#verify the existence of an RRSET for each zone, which will include, at a minimum, an RRType RRSIG (Resource Record Signature) as well as an RRType DNSKEY and RRType NSEC (Next Secure).

DNS Profile:
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Profiles.
4. DNS.
5. Click the name of the DNS profile being used by the listener.
6. Under DNS Features verify "DNSSEC" is set to "Enabled".

If the BIG-IP DNS appliance is not configured to provide additional data origin artifacts along with the authoritative data the system returns in response to external name/address resolution queries, this is a finding.

Vulnerability Number

V-265988

Documentable

False

Rule Version

F5BI-DN-300028

Severity Override Guidance

From the BIG-IP Console, type the following commands:

Note: Assuming you are checking a DNSSEC Zone, from the command line of a management computer, run:
dig +dnssec @<DNS Server IP> <DNSSEC zonename>

#verify the existence of an RRSET for each zone, which will include, at a minimum, an RRType RRSIG (Resource Record Signature) as well as an RRType DNSKEY and RRType NSEC (Next Secure).

DNS Profile:
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Profiles.
4. DNS.
5. Click the name of the DNS profile being used by the listener.
6. Under DNS Features verify "DNSSEC" is set to "Enabled".

If the BIG-IP DNS appliance is not configured to provide additional data origin artifacts along with the authoritative data the system returns in response to external name/address resolution queries, this is a finding.

Check Content Reference

M

Target Key

5638