32 - Do not define a static source port

Information

BIND can be configured to reuse the same source port when communicating with other DNS servers. This capability is made possible through the query-source option. It is recommended that this option not be used.

Rationale:

Enabling the query-source option will increase the probability of an attacker successfully poisoning the DNS cache.

Solution

Ensure the query-source option in not present in named.conf.

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: 084a65a191c1cba8441b0261ea59b3dd0ee75ba2d21d9f133fdd182529186bf2