UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The network element must have DNS servers defined if it is configured as a client resolver.


Overview

Finding ID Version Rule ID IA Controls Severity
V-3020 NET0820 SV-3020r2_rule ECSC-1 Low
Description
The susceptibility of IP addresses to spoofing translates to DNS host name and IP address mapping vulnerabilities. For example, suppose a source host wishes to establish a connection with a destination host and queries a DNS server for the IP address of the destination host name. If the response to this query is the IP address of a host operated by an attacker, the source host will establish a connection with the attacker’s host, rather than the intended target. The user on the source host might then provide logon, authentication, and other sensitive data.
STIG Date
Firewall Security Technical Implementation Guide 2013-10-08

Details

Check Text ( C-3584r3_chk )
Review the device configuration to ensure DNS servers have been defined if it has been configured as a client resolver (name lookup).
Fix Text (F-3045r2_fix)
Configure the device to include DNS servers or disable domain lookup.