STIGQter STIGQter: STIG Summary: Domain Name System (DNS) Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 23 Oct 2015:

The DNS implementation must implement internal/external role separation.

DISA Rule

SV-69191r1_rule

Vulnerability Number

V-54945

Group Title

SRG-APP-000516-DNS-000101

Rule Version

SRG-APP-000516-DNS-000101

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DNS server to separate internal and external roles to protect private address space.

Check Contents

Review the zone configuration with the DNS administrator and verify whether the zone has records on both the internal and external networks. If the zone is split, verify there is a separate external name server to handle the host records for external address space and an internal name server to handle the host records for internal address space.

If there are split zones and there are not internal and external roles to protect private address space, this is a finding.

Vulnerability Number

V-54945

Documentable

False

Rule Version

SRG-APP-000516-DNS-000101

Severity Override Guidance

Review the zone configuration with the DNS administrator and verify whether the zone has records on both the internal and external networks. If the zone is split, verify there is a separate external name server to handle the host records for external address space and an internal name server to handle the host records for internal address space.

If there are split zones and there are not internal and external roles to protect private address space, this is a finding.

Check Content Reference

M

Target Key

2355

Comments