Warning! Audit Deprecated
Information
BIND can be configured to ignore requests originating from specified network segments. This is accomplished by implementing the blackhole option in named.conf. It is recommended that this feature be implemented to ignore requests that originate outside of expected network segments.
Rationale:
By ignoring traffic that originates from unexpected locations, the server's exposure to malicious entities is reduced.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Add a blackhole option for multicast and link local addresses, and all private RFC 1918 addresses that are not being used.