STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS DNS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP DNS implementation must protect the authenticity of communications sessions for zone transfers.

DISA Rule

SV-265990r1024864_rule

Vulnerability Number

V-265990

Group Title

SRG-APP-000219-DNS-000028

Rule Version

F5BI-DN-300036

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. DNS.
2. Zones.
3. Click on the Zone Name.
4. Under the TSIG section, select a "Server Key" from the drop-down menu.
5. Click "Update".

From the BIG-IP Console, type the following commands:
tmsh modify ltm dns zone <zone name> server-tsig-key <TSIG key name>
tmsh save sys config

Check Contents

If the BIG-IP is transferring zones from another non-BIG-IP DNS server perform the following.

From the BIG-IP GUI:
1. DNS.
2. Zones.
3. Click on the Zone Name.
4. Under the TSIG section verify a "Server Key" is selected.

From the BIG-IP Console, type the following commands:

tmsh list ltm dns zone <name> server-tsig-key

Note: Must return a value other than "none".

If the BIG-IP appliance is not configured to protect the authenticity of communications sessions for zone transfers, this is a finding.

Vulnerability Number

V-265990

Documentable

False

Rule Version

F5BI-DN-300036

Severity Override Guidance

If the BIG-IP is transferring zones from another non-BIG-IP DNS server perform the following.

From the BIG-IP GUI:
1. DNS.
2. Zones.
3. Click on the Zone Name.
4. Under the TSIG section verify a "Server Key" is selected.

From the BIG-IP Console, type the following commands:

tmsh list ltm dns zone <name> server-tsig-key

Note: Must return a value other than "none".

If the BIG-IP appliance is not configured to protect the authenticity of communications sessions for zone transfers, this is a finding.

Check Content Reference

M

Target Key

5638