BIND-9X-002460 - The BIND 9.x server implementation must have fetches-per-server enabled.

Information

The fetches-per-server option in BIND 9.x configures a limit on the number of outstanding requests (fetches) allowed for a single DNS server. This rate-limiting mechanism helps protect the BIND 9.x server from being overwhelmed by excessive requests to a specific server, particularly when that server is slow or unresponsive.

Solution

Modify the BIND configuration file (/etc/named.conf ).

Add the fetches-per-server option to the "options" section of the configuration file.

fetches-per-server <integer> drop;

After making changes, reload or restart BIND to apply the new settings.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_BIND_9-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-275937r1123965_rule, STIG-ID|BIND-9X-002460, Vuln-ID|V-275937

Plugin: Unix

Control ID: 230d0416d41701f25a735547fee55441de0402d3d014c2d6bb3fc5e3cb7ebf60