SV-207559r612253_rule
V-207559
SRG-APP-000001-DNS-000001
BIND-9X-001070
CAT II
10
Edit the "named.conf" file.
Add the "transfers" sub statement to each "server" statement block.
The value of the "transfers" option can be increased to a value greater than two based on organizational requirements needed to support DNS operations.
Restart the BIND 9.x process.
If this is not a master name server, this requirement is Not Applicable
Verify that the name server is configured to limit the number of zone transfers from authorized secondary name servers.
Inspect the "named.conf" file for the following:
server <ip_address> {
transfers 2;
};
If each "server" statement does not contain a "transfers" sub statement, this is a finding.
V-207559
False
BIND-9X-001070
If this is not a master name server, this requirement is Not Applicable
Verify that the name server is configured to limit the number of zone transfers from authorized secondary name servers.
Inspect the "named.conf" file for the following:
server <ip_address> {
transfers 2;
};
If each "server" statement does not contain a "transfers" sub statement, this is a finding.
M
2926