Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-4510 | DNS0925 | SV-4510r1_rule | ECSC-1 | Medium |
Description |
---|
CSS DNS is not vulnerable to attacks associated with recursion because it does not support recursion, but does offer a forwarder feature that sends un-resolvable or unsupported requests to another name server. This feature poses a risk because the forwarder feature merely redirects potential attacks to another name server. |
STIG | Date |
---|---|
CISCO CSS DNS | 2015-12-29 |
Check Text ( C-3423r1_chk ) |
---|
In the presence of the reviewer, the CSS DNS administrator should enter the following command while in global configuration mode: show dns-server forwarder Confirm the DNS server forwarder primary and DNS server forwarder secondary are “Not Configured.” If either of these is configured, then this is a finding. |
Fix Text (F-4395r1_fix) |
---|
The CSS DNS administrator should disable forwarders by entering the following command while in global configuration mode: no dns-server forwarder primary (if a primary) or no dns-server forwarder secondary (if a secondary). |