Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-33924 | SRG-NET-000031-DNS-NA | SV-44377r1_rule | Medium |
Description |
---|
Allowing traffic to bypass the security checkpoints such as firewalls and intrusion detection systems puts the network infrastructure and critical data at risk. Malicious traffic could enter the network undetected and attack a key network element or the server farm. Hence, it is imperative all tunneled traffic entering the network terminate prior to the content checking devices. Enforcement of limitations on embedding of data types is not a function of DNS. |
STIG | Date |
---|---|
Domain Name System (DNS) Security Requirements Guide | 2012-10-24 |
Check Text ( C-41933r1_chk ) |
---|
This is not a function of DNS. |
Fix Text (F-37837r1_fix) |
---|
This requirement is NA for DNS. No fix required. |