STIGQter STIGQter: STIG Summary:

F5 BIG-IP TMOS DNS Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 26 Sep 2024

CheckedNameTitle
SV-265980r1024486_ruleThe F5 BIG-IP DNS implementation must prohibit recursion on authoritative name servers.
SV-265981r1024487_ruleThe validity period for the RRSIGs covering a zone's DNSKEY RRSet must be no less than two days and no more than one week.
SV-265982r1024488_ruleAn authoritative name server must be configured to enable DNSSEC Resource Records.
SV-265983r1024490_rulePrimary authoritative name servers must be configured to only receive zone transfer requests from specified secondary name servers.
SV-265984r1024858_ruleThe F5 BIG-IP DNS must use valid root name servers in the local root zone file.
SV-265985r1024493_ruleThe platform on which the name server software is hosted must be configured to respond to DNS traffic only.
SV-265986r1024860_ruleThe digital signature algorithm used for DNSSEC-enabled zones must be set to use RSA/SHA256 or RSA/SHA512.
SV-265987r1024862_ruleThe F5 BIG-IP DNS server implementation must validate the binding of the other DNS server's identity to the DNS information for a server-to-server transaction (e.g., zone transfer).
SV-265988r1024496_ruleA BIG-IP DNS server implementation must provide additional data origin artifacts along with the authoritative data the system returns in response to external name/address resolution queries.
SV-265989r1024498_ruleThe validity period for the RRSIGs covering the DS RR for a zones delegated children must be no less than two days and no more than one week.
SV-265990r1024864_ruleThe F5 BIG-IP DNS implementation must protect the authenticity of communications sessions for zone transfers.
SV-265991r1024501_ruleThe F5 BIG-IP DNS server implementation must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks.