SV-207557r612253_rule
V-207557
SRG-APP-000516-DNS-000110
BIND-9X-001059
CAT III
10
Edit the "named.conf" file.
Configure the BIND 9.x server to only use the "port" flag with the "listen-on" and "listen-on-v6" statements:
options {
listen-on port 53 { <ip_address>; };
listen-on-v6 port 53 { <ip_v6_address>; };
};
Restart the BIND 9.x process.
Verify that the BIND 9.x server does not limit outgoing DNS messages to a specific port.
Inspect the "named.conf" file for the any instance of the "port" flag:
options {
listen-on port 53 { <ip_address>; };
listen-on-v6 port 53 { <ip_v6_address>; };
};
If any "port" flag is found outside of the "listen-on" or "listen-on-v6" statements, this is a finding.
V-207557
False
BIND-9X-001059
Verify that the BIND 9.x server does not limit outgoing DNS messages to a specific port.
Inspect the "named.conf" file for the any instance of the "port" flag:
options {
listen-on port 53 { <ip_address>; };
listen-on-v6 port 53 { <ip_v6_address>; };
};
If any "port" flag is found outside of the "listen-on" or "listen-on-v6" statements, this is a finding.
M
2926