STIGQter STIGQter: STIG Summary: Domain Name System (DNS) Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 23 Oct 2015:

In a split DNS configuration, where separate name servers are used between the external and internal networks, the internal name server must be configured to not be reachable from outside resolvers.

DISA Rule

SV-69183r1_rule

Vulnerability Number

V-54937

Group Title

SRG-APP-000516-DNS-000093

Rule Version

SRG-APP-000516-DNS-000093

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DNS configuration on internal name servers to only accept queries from internal resolvers.
Configure DNS configuration on external name servers to only accept queries from external resolvers.
Configure network perimeter devices to block query resolution traffic from external resolvers to internal name servers and from internal resolvers to external name servers.

Check Contents

Review the DNS implementation and ensure internal DNS name servers are not reachable by external resolvers.

If the internal DNS name servers can be reached by external resolvers, this is a finding.

Vulnerability Number

V-54937

Documentable

False

Rule Version

SRG-APP-000516-DNS-000093

Severity Override Guidance

Review the DNS implementation and ensure internal DNS name servers are not reachable by external resolvers.

If the internal DNS name servers can be reached by external resolvers, this is a finding.

Check Content Reference

M

Target Key

2355

Comments