3 - Slave DNS servers

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Slave DNS servers are set up to replicate the master servers data. The Slave, along with the master, is also authoritative for its domain, but it gets all of the domain data from the master. Slaves are updated from the master when the version of the domain data changes.

Rationale:

Every DNS architecture should have at least two name servers; a master and one or more slave name servers. There is no easy formula to calculate the number of name servers needed, as it depends on several factors, including; the number of sub-domains, the volume of requests and the geographical distribution of the traffic. For Internet-facing DNS services, at least one slave name server should be geographically remote from the master and connected via a different Internet connection to mitigate DoS attacks, to increase reliability, and to better distribute the DNS traffic. Many ISPs provide inexpensive name server services. Ask about the location and connectivity of the services, and look for one that is remote from your master, as well as reliable and secure. Also, consider getting a remote dedicated server that can be secured and administered remotely by your staff. For large organizations there are several companies specializing in globally distributed and high relability DNS services. Likewise, your internal clients and servers should be configured to query multiple caching and/or forwarding name servers for increased reliability. These redundant name servers should be an integral portion of your network's architecture for reliability and performance and that places a priority on the DNS security.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Verify appropriate slave DNS servers are in use for each external and internal master name server. For the external Internet DNS servers an independent Internet connection or independent ISP hosted DNS service should be used.