Infoblox DNS servers must be configured to protect the authenticity of communications sessions for dynamic updates.
An XCCDF Rule
Description
DNS is a fundamental network service that is prone to various attacks, such as cache poisoning and man-in-the middle attacks. If communication sessions are not provided appropriate validity protections, such as the employment of DNSSEC, the authenticity of the data cannot be guaranteed.
- ID
- SV-214175r612370_rule
- Version
- IDNS-7X-000280
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Infoblox Systems can be configured in two ways to limit DDNS client updates.
For clients that support GSS-TSIG, navigate to Data Management >> DNS >> Members/Servers tab.
Review each server with the DNS service enabled.
Select each server, click "Edit", toggle Advanced Mode and select GSS-TSIG.