STIGQter STIGQter: STIG Summary:

Infoblox 8.x DNS Security Technical Implementation Guide

Version: 1

Release: 3 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-233855r1082600_ruleInfoblox systems that perform zone transfers to non-Grid DNS service members must limit the number of concurrent sessions for zone transfers.
SV-233856r960735_ruleThe Infoblox system must limit the number of concurrent client connections to the number of allowed dynamic update clients.
SV-233857r1082603_ruleThe Infoblox DNS service member must not reveal sensitive information to an attacker. This includes Host Information (HINFO), Responsible Person (RP), Location (LOC) resource, and sensitive text string resource (TXT) record data.
SV-233858r960948_ruleThe Infoblox system audit records must be backed up at least every seven days onto a different system or system component than the system or component being audited.
SV-233859r1156964_ruleAll authoritative DNS service members for a zone must be geographically dispersed.
SV-233860r1156949_ruleRecursion must be disabled on Infoblox DNS service members that are configured as External Authoritative DNS service members.
SV-233861r961863_ruleThe validity period for the Resource Record Signatures (RRSIGs) covering a zone's DNSKEY RRSet must be no less than two days and no more than one week.
SV-233862r1156952_ruleNSEC3 must be used for all DNSSEC signed zones.
SV-233863r1082996_ruleThe Infoblox DNS service member must be configured so that each DNS service member record in a zone file points to an active DNS service member authoritative for the domain specified in that record.
SV-233864r1156953_ruleAll authoritative DNS service members for a zone must be located on different network segments.
SV-233865r1082621_ruleAll authoritative DNS service members for a zone must have the same version of zone information.
SV-233866r1156954_ruleAn External authoritative DNS service member must be configured to enable DNSSEC resource records.
SV-233867r1082626_ruleThe digital signature algorithm used for DNSSEC-enabled zones must be FIPS-compatible.
SV-233868r1082629_ruleFor zones split between the external and internal sides of a network, the resource records (RRs) for the external hosts must be separate from the RRs for the internal hosts.
SV-233869r1082632_ruleIn a split DNS configuration, where separate DNS service members are used between the external and internal networks, the external DNS service member must be configured to not be reachable from inside resolvers.
SV-233870r1082635_ruleIn a split DNS configuration, where separate DNS service members are used between the external and internal networks, the internal DNS service member must be configured to not be reachable from outside resolvers.
SV-233871r1082637_rulePrimary authoritative DNS service members must be configured to only receive zone transfer requests from specified secondary DNS service members.
SV-233872r1156956_ruleThe Infoblox system must use a security policy that limits the propagation of access rights.
SV-233873r1082640_ruleThe DNS implementation must implement internal/external role separation.
SV-233874r1082643_ruleThe Infoblox DNS service member must use current and valid root DNS service members.
SV-233875r1156957_ruleThe Infoblox NIOS version must be at the appropriate version.
SV-233876r1082648_ruleThe IP address for hidden master authoritative DNS service members must not appear in the DNS service members set in the zone database.
SV-233877r1156959_ruleThe Infoblox system must be configured to respond to DNS traffic only.
SV-233878r1082650_ruleThe Infoblox DNS service member must send outgoing DNS messages from a random port.
SV-233879r1156961_ruleThe private keys corresponding to both the Zone Signing Key (ZSK) and the Key Signing Key (KSK) must not be kept on the DNSSEC-aware primary authoritative DNS service member when the DNS service member does not support dynamic updates.
SV-233880r1156962_ruleCNAME records must not point to a zone with lesser security for more than six months.
SV-233882r961863_ruleA secure out-of-band (OOB) network must be used for management of Infoblox Grid Members.
SV-233883r961863_ruleInfoblox systems must enforce current DoD password restrictions.
SV-233884r961863_ruleInfoblox Grid configuration must be backed up on a regular basis.
SV-233885r961863_ruleThe Infoblox system must display the approved DoD notice and consent banner.
SV-233886r961863_ruleThe Infoblox system must display the appropriate security classification information.
SV-233887r961863_ruleThe Infoblox system must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.
SV-233888r1082658_ruleThe Infoblox system must present only approved TLS and SSL cipher suites.
SV-233889r1156946_ruleAn Infoblox DNS service member must strongly bind the identity of the DNS service member with the DNS information using DNSSEC.
SV-233890r1156947_ruleThe Infoblox system must provide the means for authorized individuals to determine the identity of the source of the DNS service member-provided information.
SV-233891r1082667_ruleThe Infoblox system must validate the binding of the other DNS service members' identity to the DNS information for a server-to-server transaction (e.g., zone transfer).
SV-233892r1156948_ruleThe Infoblox system must send a notification in the event of an error when validating the binding of another DNS service member's identity to the DNS information.
SV-233893r1156950_ruleThe Infoblox DNS service member must provide data origin artifacts for internal name/address resolution queries.
SV-233894r1082674_ruleThe Infoblox DNS service member must provide data integrity protection artifacts for internal name/address resolution queries.
SV-233895r1156945_ruleThe Infoblox system must notify the system administrator when a component failure is detected.
SV-233896r1156951_ruleThe Infoblox DNS service member implementation must follow procedures to promote a secondary DNS service member to the role of primary DNS service member in the event the current primary DNS service member permanently loses functionality.
SV-233897r1082679_ruleThe Infoblox system must prohibit or restrict unapproved services, ports, and protocols.
SV-233898r1082682_ruleThe Infoblox system must require devices to reauthenticate for each zone transfer and dynamic update request connection attempt.
SV-233899r1082685_ruleWhen using third-party DNS servers for zone transfers, each DNS server must use TSIG to uniquely identify the other server.
SV-233900r1082688_ruleThe Infoblox DNS service member must authenticate to any external (non-Grid) DNS service members before responding to a server-to-server transaction.
SV-233901r1082691_ruleThe Infoblox DNS service member must authenticate another DNS service member before establishing a remote and/or network connection using bidirectional authentication that is cryptographically based.
SV-233902r1156963_ruleInfoblox systems that communicate with non-Grid DNS service members must use a unique Transaction Signature (TSIG).
SV-233903r1082697_ruleThe Infoblox Grid Master must be configured as a stealth (hidden) domain DNS service member to protect the Key Signing Key (KSK) residing on it.
SV-233904r1083000_ruleThe Infoblox Grid Master must be configured as a stealth (hidden) domain DNS service member in order to protect the Zone Signing Key (ZSK) residing on it.
SV-233905r961062_ruleThe Infoblox system must employ strong authenticators in the establishment of non-local maintenance and diagnostic sessions.
SV-233906r1137676_ruleThe Infoblox DNS service member must implement NIST FIPS-validated cryptography for provisioning digital signatures, generating cryptographic hashes, and protecting unclassified information requiring confidentiality.
SV-233907r961101_ruleThe Infoblox system must provide additional data origin artifacts along with the authoritative data the system returns in response to external name/address resolution queries.
SV-233908r1082705_ruleThe Infoblox DNS service member must provide additional integrity artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries.
SV-233909r1082708_ruleThe Infoblox DNS service member implementation must provide the means to indicate the security status of child zones.
SV-233910r961104_ruleThe validity period for the Resource Record Signatures (RRSIGs) covering the Delegation Signer (DS) RR for a zone's delegated children must be no less than two days and no more than one week.
SV-233911r1082711_ruleThe Infoblox DNS service member implementation must enforce approved authorizations for controlling the flow of information between DNS service members and between DNS service members and DNS clients based on TSIG policies.
SV-233912r1083002_ruleThe Infoblox DNS service member must enable verification of a chain of trust among parent and child domains (if the child supports secure resolution services).
SV-233913r1082717_ruleThe Infoblox DNS service member must request data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources.
SV-233917r1082725_ruleInfoblox DNS service members must protect the authenticity of communications sessions for zone transfers when communicating with external DNS service members (i.e., DNS systems outside the Infoblox grid).
SV-233918r1082728_ruleInfoblox DNS service members must protect the authenticity of communications sessions for dynamic updates.
SV-233919r1082730_ruleInfoblox DNS service members must protect the authenticity of communications sessions for queries.
SV-233920r961125_ruleIn the event of a system failure, the Infoblox system must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes.
SV-233921r1082733_ruleThe Infoblox system must restrict the ability of individuals to use the DNS service member to launch denial-of-Service (DoS) attacks against other information systems.
SV-233922r1082735_ruleThe Infoblox system must manage excess capacity, bandwidth, or other redundancy to limit the effects of information-flooding types of denial-of-service (DoS) attacks.
SV-233923r1082737_ruleThe Infoblox DNS service member must protect the integrity of transmitted information.
SV-233924r1137675_ruleThe Infoblox DNS service member must implement cryptographic mechanisms to detect changes to information during transmission unless otherwise protected by alternative physical safeguards, such as, at a minimum, a Protected Distribution System (PDS).
SV-233925r1082741_ruleThe Infoblox DNS service member implementation must maintain the integrity of information during preparation for transmission.
SV-233926r1082744_ruleThe Infoblox DNS service member implementation must maintain the integrity of information during reception.
SV-233927r961185_ruleThe Infoblox system must notify the ISSO and ISSM in the event of failed security verification tests.
SV-233928r1082747_ruleThe Infoblox DNS service member implementation must log the event and notify the system administrator when anomalies in the operation of the signed zone transfers are discovered.