SV-265991r1024501_rule
V-265991
SRG-APP-000247-DNS-000036
F5BI-DN-300039
CAT II
10
This requires the AFM license or can be implemented using another firewall's ACL.
From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand DNS and do the following for each:
a. Check the box at the top of the list of signatures to select all.
b. Set "Set State" to "Mitigate".
c. Click "Commit Changes to System".
Note: Sites must operationally test, adjust thresholds, or initially use learning mode prior to turning on mitigation to prevent operational impacts, particularly in implementations with large traffic volumes.
From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand DNS and verify the "State" is set to "Mitigate" for all signatures.
If the BIG-IP appliance is not configured to restrict the ability of individuals to use the DNS server to launch DoS attacks against other information systems, this is a finding.
V-265991
False
F5BI-DN-300039
From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand DNS and verify the "State" is set to "Mitigate" for all signatures.
If the BIG-IP appliance is not configured to restrict the ability of individuals to use the DNS server to launch DoS attacks against other information systems, this is a finding.
M
5638