UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Forwarders are not disabled on the CSS DNS.


Overview

Finding ID Version Rule ID IA Controls Severity
V-4510 DNS0925 SV-4510r3_rule ECSC-1 Medium
Description
CSS DNS is not vulnerable to attacks associated with recursion because it does not support recursion, but does offer a forwarder feature that sends un-resolvable or unsupported requests to another name server. This feature poses a risk because the forwarder feature merely redirects potential attacks to another name server.
STIG Date
CISCO CSS DNS 2011-01-20

Details

Check Text ( C-3423r1_chk )
In the presence of the reviewer, the CSS DNS administrator should enter the following command while in global configuration mode:

show dns-server forwarder

Confirm the DNS server forwarder primary and DNS server forwarder secondary are “Not Configured.” If either of these is configured, then this is a finding.
Fix Text (F-4395r2_fix)
The CSS DNS administrator should disable forwarders by entering the following command while in global configuration mode: no dns-server forwarder primary (if a primary) or no dns-server forwarder secondary (if a secondary).