STIGQter STIGQter: STIG Summary: Infoblox 7.x DNS Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

The Infoblox system must utilize valid root name servers in the local root zone file.

DISA Rule

SV-214213r612370_rule

Vulnerability Number

V-214213

Group Title

SRG-APP-000516-DNS-000102

Rule Version

IDNS-7X-000850

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate Data Management >> DNS >> Grid DNS Properties.

Toggle Advanced mode and select the "Root Name Servers" tab.
Use the radio button to select "Use custom root name servers" and configure the desired root name servers.
When complete, click "Save & Close" to save the changes and exit the "Properties" screen.

Perform a service restart if necessary.

Check Contents

Review the entries within the root hints file and validate that the entries are correct. "G" and "H" root servers are required on the NIPRNet, as a minimum. All default settings on servers must be verified and corrected if necessary.

If valid root name servers are not configured, this is a finding.

Navigate Data Management >> DNS >> Grid DNS Properties.

Toggle Advanced mode and review "Root Name Servers" tab to ensure it is configured correctly.

Note: Validate against the current available DNS root list at the time of check.

Vulnerability Number

V-214213

Documentable

False

Rule Version

IDNS-7X-000850

Severity Override Guidance

Review the entries within the root hints file and validate that the entries are correct. "G" and "H" root servers are required on the NIPRNet, as a minimum. All default settings on servers must be verified and corrected if necessary.

If valid root name servers are not configured, this is a finding.

Navigate Data Management >> DNS >> Grid DNS Properties.

Toggle Advanced mode and review "Root Name Servers" tab to ensure it is configured correctly.

Note: Validate against the current available DNS root list at the time of check.

Check Content Reference

M

Target Key

3995

Comments