When IPv6 protocol is installed, the server must also be configured to answer for IPv6 AAAA records.

From Microsoft Windows 2012 Server Domain Name System Security Technical Implementation Guide

Part of SRG-APP-000516-DNS-000500

Associated with: CCI-000366

SV-73057r3_rule When IPv6 protocol is installed, the server must also be configured to answer for IPv6 AAAA records.

Vulnerability discussion

To prevent the possibility of a denial of service in relation to an IPv4 DNS server trying to respond to IPv6 requests, the server should be configured not to listen on any of its IPv6 interfaces unless it does contain IPv6 AAAA resource records in one of the zones.

Check content

Log on to the DNS server using the Domain Admin or Enterprise Admin account. Locate the “Network Internet Access” icon, right-click on it and select "Open Network & Sharing Center". Click on "Change adapter settings". Right-click on the Ethernet and click “Properties”. If the display shows Microsoft TCP/IP version 6 with a check, but the DNS server is not hosting any AAAA records, this is a finding.

Fix text

Uninstall IPv6 from any LAN interface that is not hosting IPv6 AAAA records within its zones.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer