4.3.1 Enable Botnet C&C Domain Blocking DNS Filter

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Enable Botnet C&C domain blocking to block botnet access at the DNS name resolving stage

Rationale:

Blocking botnet website access at the DNS resolution stage provides an additional layer of defense.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Review DNS Filter Security Profiles and validate that 'Redirect botnet C&C requests to Block Portal' is enabled and that firewall policies that have DNS traffic have a DNS Filter security profile applied with that option enabled

See Also

https://workbench.cisecurity.org/files/4077

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6

Plugin: FortiGate

Control ID: f8aaaea68f5a47d439db3159e98f719ec220c6d8edb4dd3bab5a6216f0125b9c