32 - Do not define a static source port

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

BIND can be configured to reuse the same source port when communicating with other DNS servers. This capability is made possible through the query-source option. It is recommended that this option not be used.

Rationale:

Enabling the query-source option will increase the probability of an attacker successfully poisoning the DNS cache.

Solution

Ensure the query-source option in not present in named.conf.

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: 084a65a191c1cba8441b0261ea59b3dd0ee75ba2d21d9f133fdd182529186bf2