SV-215575r561297_rule
V-215575
SRG-APP-000383-DNS-000047
WDNS-CM-000005
CAT II
10
Configure a local or network firewall to only allow specific IP addresses/ranges to send inbound TCP and UDP port 53 traffic to a DNS caching server.
Note: If Windows DNS server is not serving in a caching role, this check is Not Applicable.
Verify the Windows DNS Server will only accept TCP and UDP port 53 traffic from specific IP addresses/ranges.
This can be configured via a local or network firewall.
If the caching name server is not restricted to answering queries from only specific networks, this is a finding.
V-215575
False
WDNS-CM-000005
Note: If Windows DNS server is not serving in a caching role, this check is Not Applicable.
Verify the Windows DNS Server will only accept TCP and UDP port 53 traffic from specific IP addresses/ranges.
This can be configured via a local or network firewall.
If the caching name server is not restricted to answering queries from only specific networks, this is a finding.
M
4016