STIGQter STIGQter: STIG Summary: Infoblox 7.x DNS Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

The Infoblox system must be configured to manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of Denial of Service (DoS) attacks.

DISA Rule

SV-214179r612370_rule

Vulnerability Number

V-214179

Group Title

SRG-APP-000247-DNS-000036

Rule Version

IDNS-7X-000350

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log on to the Infoblox system using the CLI.

Use "set ip_rate_limit [OPTIONS}" to reduce risk of cache poisoning attacks by rate limiting udp/53 traffic.

Use "set dns_rrl" to enable DNS response rate limiting. This helps reduce the risk of DoS attacks by reducing the rate at which authoritative name servers respond to queries, such as a flood.

Check Contents

Infoblox systems have a number of options that can be configured to reduce the ability to be exploited in a DoS attack. Usage of rate limiting can reduce risk from cache poisoning attacks and DoS attacks.

Log on to the Infoblox system and issue the commands:

"show ip_rate_limit" and "show dns_rrl"

Review the output from these commands with the network architecture.

If rate limiting is not configured on the Infoblox system or within the network security architecture, this is a finding.

Note: "set dns_rrl" is only applicable to code version 7.2 and above.

Vulnerability Number

V-214179

Documentable

False

Rule Version

IDNS-7X-000350

Severity Override Guidance

Infoblox systems have a number of options that can be configured to reduce the ability to be exploited in a DoS attack. Usage of rate limiting can reduce risk from cache poisoning attacks and DoS attacks.

Log on to the Infoblox system and issue the commands:

"show ip_rate_limit" and "show dns_rrl"

Review the output from these commands with the network architecture.

If rate limiting is not configured on the Infoblox system or within the network security architecture, this is a finding.

Note: "set dns_rrl" is only applicable to code version 7.2 and above.

Check Content Reference

M

Target Key

3995

Comments