SV-214525r557389_rule
V-214525
SRG-NET-000131-ALG-000086
JUSX-AG-000085
CAT II
10
First, remove the DNS stanza. Then re-enter the set security zones and interfaces command without the "dns" attribute. The exact command entered depends how the zone is configured with the authorized attributes, services, and options.
Examples:
[edit]
delete system services dns
set security zones security-zone <zone-name> interfaces <interface-name> host-inbound-traffic
Check both the zones and the interface stanza to ensure DNS proxy server services are not configured.
[edit}
show system services dns
If a stanza exists for DNS (e.g., forwarders option), this is a finding.
V-214525
False
JUSX-AG-000085
Check both the zones and the interface stanza to ensure DNS proxy server services are not configured.
[edit}
show system services dns
If a stanza exists for DNS (e.g., forwarders option), this is a finding.
M
4004