SV-215587r561297_rule
V-215587
SRG-APP-000516-DNS-000093
WDNS-CM-000018
CAT II
10
Configure the internal DNS server's firewall policy, or the network firewall, to block queries from external hosts.
Consult with the System Administrator to review the internal Windows DNS Server's HBSS firewall policy.
The inbound TCP and UDP ports 53 rule should be configured to only allow hosts from the internal network to query the internal DNS server.
If the HBSS firewall policy is not configured with the restriction, consult with the network firewall administrator to confirm the restriction on the network firewall.
If neither the DNS server's HBSS firewall policy nor the network firewall is configured to block external hosts from querying the internal DNS server, this is a finding.
V-215587
False
WDNS-CM-000018
Consult with the System Administrator to review the internal Windows DNS Server's HBSS firewall policy.
The inbound TCP and UDP ports 53 rule should be configured to only allow hosts from the internal network to query the internal DNS server.
If the HBSS firewall policy is not configured with the restriction, consult with the network firewall administrator to confirm the restriction on the network firewall.
If neither the DNS server's HBSS firewall policy nor the network firewall is configured to block external hosts from querying the internal DNS server, this is a finding.
M
4016