Fortigate - DNS - primary server

Information

The DNS server IP address should be reviewed. A DNS server may return malicious IP addresses in response to requests for domains that are normally good. This provides an avenue to leak information about the appliance or to download untrusted content.

Solution

Use the following command to configure the primary DNS server address:

config system dns
set primary <dns_ipv4>
end

See Also

https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/612504/hardening-your-fortigate

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-20

Plugin: FortiGate

Control ID: 422e1e04bfac156974cf882d93a6a1bd627e7d8322de23ac4f20e74531994dd9