Fortigate - DNS - primary server

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The DNS server IP address should be reviewed. A DNS server may return malicious IP addresses in response to requests for domains that are normally good. This provides an avenue to leak information about the appliance or to download untrusted content.

Solution

Use the following command to configure the primary DNS server address:

config system dns
set primary <dns_ipv4>
end

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-20

Plugin: FortiGate

Control ID: 839c1dc596d21a9c628afcbd682e625fc926c3bf7ba9f67274e8dbb7938ff703