SV-69173r1_rule
V-54927
SRG-APP-000516-DNS-000087
SRG-APP-000516-DNS-000087
CAT II
10
Locate all visible (non-hidden) name servers to be on different network segments.
Review the DNS configuration files to determine all of the NS records for each zone. Based upon the NS records for each zone, determine location of each of the name servers. Verify all authoritative name servers are located on different network segments.
If two authoritative name servers are found on the same network segment, and one of those two is hidden, this is not a finding.
If any authoritative name servers are located on the same network segment as another authoritative name server, this is a finding.
V-54927
False
SRG-APP-000516-DNS-000087
Review the DNS configuration files to determine all of the NS records for each zone. Based upon the NS records for each zone, determine location of each of the name servers. Verify all authoritative name servers are located on different network segments.
If two authoritative name servers are found on the same network segment, and one of those two is hidden, this is not a finding.
If any authoritative name servers are located on the same network segment as another authoritative name server, this is a finding.
M
2355