3.16 Ensure Accept Domain Name over UDP (Queries) is not enabled

Information

The 'Domain Name Over UDP (Queries)' is a global property setting which is used to allow or reject all the UDP-type DNS packets to and from anywhere. These rules are considered as rule zero which are execute before any user-defined rules.

Rationale:

If this rule is set to enable it allows the DNS traffic to pass over the firewall without any control. The security policy is made up of rules in the Firewall Rule Base. Other than the rules defined by the administrator, The Check Point Security Gateway also creates Implied Rules, which are defined in the Firewall Global Properties. The Check Point Security Gateway places the implied rules first, last, or before last in the Firewall Rule Base. The administrator can decide whether or not to log implied rules.

First > The Implicit rule will be placed before the explicit rules.

Last > The Implicit rule will be placed after the explicit rules.

Before Last > The Implicit rule will be placed before the last explicit rule.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Go to the following path and Configured the Accept Accept Domain Name over UDP (Queries).

SmartConsole > Gateways & Servers > select each Gateway > Firewall
Unchecked the Accept Accept Domain Name over UDP (Queries)

See Also

https://workbench.cisecurity.org/files/2828

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-3, CSCv7|11.3

Plugin: CheckPoint

Control ID: c95630e317036616531c7cb192066df1e3b564f9adad313d3ee596b13fcc6bff