The DHCP service must not be enabled on an external authoritative name server.

From Infoblox 7.x DNS Security Technical Implementation Guide

Part of SRG-APP-000142-DNS-000014

Associated with: CCI-000382

SV-83111r1_rule The DHCP service must not be enabled on an external authoritative name server.

Vulnerability discussion

The site DNS and DHCP architecture must be reviewed to ensure only the appropriate services are enabled on each Grid Member. An external authoritative name server must be configured to allow only authoritative DNS.

Check content

Navigate to Grid >> Grid Manager >> Services tab. Select "DHCP" and verify only internal Infoblox members have the service enabled. If an external authoritative name server has DHCP enabled this is a finding.

Fix text

Navigate to Data Management >> DHCP >> Members/Servers tab. Select the Infoblox member using the check box and click "Stop" in the toolbar to disable the "DHCP" service.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer