SV-215581r561297_rule
V-215581
SRG-APP-000516-DNS-000087
WDNS-CM-000012
CAT II
10
For non-AD-integrated Windows DNS Servers, distribute secondary authoritative servers on separate network segments from the primary authoritative server.
Windows DNS Servers that are Active Directory-integrated must be located where required to meet the Active Directory services.
If all of the Windows DNS Servers are AD-integrated, this check is not applicable.
If any or all of the Windows DNS Servers are stand-alone and non-AD-integrated, verify with the System Administrator their geographic dispersal.
If all of the authoritative name servers are located on the same network segment, and the master authoritative name server is not "hidden", this is a finding.
V-215581
False
WDNS-CM-000012
Windows DNS Servers that are Active Directory-integrated must be located where required to meet the Active Directory services.
If all of the Windows DNS Servers are AD-integrated, this check is not applicable.
If any or all of the Windows DNS Servers are stand-alone and non-AD-integrated, verify with the System Administrator their geographic dispersal.
If all of the authoritative name servers are located on the same network segment, and the master authoritative name server is not "hidden", this is a finding.
M
4016