STIGQter STIGQter: STIG Summary: Domain Name System (DNS) Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 23 Oct 2015:

The DNS implementation must limit the number of concurrent sessions for zone transfers to the number of secondary name servers.

DISA Rule

SV-69099r1_rule

Vulnerability Number

V-54853

Group Title

SRG-APP-000001-DNS-000001

Rule Version

SRG-APP-000001-DNS-000001

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DNS primary server to explicitly specify which hosts to which it sends zone transfers.

Check Contents

Review the DNS server configuration and ensure a limit has been defined for the number of outbound zone transfers to only be allowed to the specified secondary name servers.

If the DNS server configuration does not explicitly specify which hosts to which it sends zone transfers, this is a finding.

Vulnerability Number

V-54853

Documentable

False

Rule Version

SRG-APP-000001-DNS-000001

Severity Override Guidance

Review the DNS server configuration and ensure a limit has been defined for the number of outbound zone transfers to only be allowed to the specified secondary name servers.

If the DNS server configuration does not explicitly specify which hosts to which it sends zone transfers, this is a finding.

Check Content Reference

M

Target Key

2355

Comments