UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

When IPv6 protocol is installed, the server must also be configured to answer for IPv6 AAAA records.


Overview

Finding ID Version Rule ID IA Controls Severity
V-58627 WDNS-CM-000028 SV-73057r4_rule Medium
Description
To prevent the possibility of a denial of service in relation to an IPv4 DNS server trying to respond to IPv6 requests, the server should be configured not to listen on any of its IPv6 interfaces unless it does contain IPv6 AAAA resource records in one of the zones.
STIG Date
Microsoft Windows 2012 Server Domain Name System Security Technical Implementation Guide 2019-01-04

Details

Check Text ( C-59499r2_chk )
Log on to the DNS server using the Domain Admin or Enterprise Admin account.

Locate the “Network Internet Access” icon, right-click on it and select "Open Network & Sharing Center".

Click on "Change adapter settings".

Right-click on the Ethernet and click “Properties”.

If the display shows Microsoft TCP/IP version 6 with a check, but the DNS server is not hosting any AAAA records, this is a finding.
Fix Text (F-64011r3_fix)
Log onto the DNS server.

Access Group Policy Management.

Edit Default Domain Policy, go to Computer Configuration >> Policies >> Administrative Templates >> Network >> IPv6 Configuration, Open IPv6 Configuration Policy and set on “Disable all IPv6 components”.