Skip to content

Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Nonroutable IPv6 link-local scope addresses must not be configured in any zone.

    IPv6 link-local scope addresses are not globally routable and must not be configured in any DNS zone. Like RFC1918 addresses, if a link-local scope address is inserted into a zone provided to clien...
    Rule Medium Severity
  • SRG-APP-000516-DNS-000500

    Group
  • SRG-APP-000158-DNS-000015

    Group
  • The Windows DNS Server must uniquely identify the other DNS server before responding to a server-to-server transaction.

    Without identifying devices, unidentified or unknown devices may be introduced, thereby facilitating malicious activity. This applies to server-to-server (zone transfer) transactions only and is pr...
    Rule Medium Severity
  • SRG-APP-000394-DNS-000049

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules