SV-214203r612370_rule
V-214203
SRG-APP-000516-DNS-000084
IDNS-7X-000720
CAT II
10
Navigate to Data Management >> DNS >> Grid DNS Properties.
Toggle Advanced Mode and edit the "DNSSEC" tab.
Ensure "Resource Record Type for Nonexistent Proof" is set to NSEC3.
Re-sign all DNSSEC zones which previously used NSEC.
Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable.
Review the zone configuration and confirm that, if DNSSEC is enabled NSEC3 is utilized.
Review zone data or use Global Search string ".".
Type Equals NSEC Record to verify no undesired NSEC records exists.
If NSEC records exist in an active zone, this is a finding.
V-214203
False
IDNS-7X-000720
Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable.
Review the zone configuration and confirm that, if DNSSEC is enabled NSEC3 is utilized.
Review zone data or use Global Search string ".".
Type Equals NSEC Record to verify no undesired NSEC records exists.
If NSEC records exist in an active zone, this is a finding.
M
3995