SV-215588r561297_rule
V-215588
SRG-APP-000516-DNS-000095
WDNS-CM-000019
CAT II
10
Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.
Press Windows Key + R, execute dnsmgmt.msc.
On the opened DNS Manager snap-in from the left pane, expand the server name for the DNS server, and then expand Forward Lookup Zones.
From the expanded list, click to select the zone.
Right-click the zone and select “Properties”.
Select the "Zone Transfers" tab.
Select the "Only to servers listed on the Name Server tab" or "Only to the following servers" check box or deselect the "Allow zone transfers" check box.
Click “OK”.
Verify whether the authoritative primary name server is AD-integrated.
Verify whether all secondary name servers for every zone for which the primary name server is authoritative are all AD-integrated in the same Active Directory.
If the authoritative primary name server is AD-integrated and all secondary name servers also part of the same AD, this check is not a finding since AD handles the replication of DNS data.
If one or more of the secondary name servers are non-AD integrated, verify the primary name server is configured to only send zone transfers to a specific list of secondary name servers.
Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.
Press Windows Key + R, execute dnsmgmt.msc.
On the opened DNS Manager snap-in from the left pane, expand the server name for the DNS server, and then expand Forward Lookup Zones.
From the expanded list, click to select the zone.
Right-click the zone and select “Properties”.
Select the “Zone Transfers” tab.
If the "Allow zone transfers:" check box is not selected, this is not a finding.
If the "Allow zone transfers:" check box is selected, verify either "Only to servers listed on the Name Server tab" or "Only to the following servers" is selected.
If the "To any server" option is selected, this is a finding.
V-215588
False
WDNS-CM-000019
Verify whether the authoritative primary name server is AD-integrated.
Verify whether all secondary name servers for every zone for which the primary name server is authoritative are all AD-integrated in the same Active Directory.
If the authoritative primary name server is AD-integrated and all secondary name servers also part of the same AD, this check is not a finding since AD handles the replication of DNS data.
If one or more of the secondary name servers are non-AD integrated, verify the primary name server is configured to only send zone transfers to a specific list of secondary name servers.
Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.
Press Windows Key + R, execute dnsmgmt.msc.
On the opened DNS Manager snap-in from the left pane, expand the server name for the DNS server, and then expand Forward Lookup Zones.
From the expanded list, click to select the zone.
Right-click the zone and select “Properties”.
Select the “Zone Transfers” tab.
If the "Allow zone transfers:" check box is not selected, this is not a finding.
If the "Allow zone transfers:" check box is selected, verify either "Only to servers listed on the Name Server tab" or "Only to the following servers" is selected.
If the "To any server" option is selected, this is a finding.
M
4016