STIGUI
V-285238CAT II — Medium severitySV-285238r1258664_rule

The Infoblox system must be configured to prohibit or restrict unapproved ports and protocols.

Rule version IDNS-9X-000150 · STIG v1 · 2026-08-14

Discussion

To prevent unauthorized connection of devices, unauthorized transfer of information, or unauthorized tunneling (i.e., embedding of data types within data types), organizations must disable or restrict unused or unnecessary physical and logical ports/protocols on information systems.

Infoblox systems provide DNS, Dynamic Host Configuration Protocol (DHCP), and IP Address Management (DDI) services. Some of the functions and services provided may not be necessary to support essential organizational operations. Additionally, it is sometimes convenient to provide multiple services from a single component (e.g., DNS and DHCP); however, doing so increases risk over limiting the services provided by any one component. This risk may be increased depending on placement in the network. Internal systems often provide DNS and DHCP; however, external systems or those in a DMZ provide only DNS.

Satisfies: SRG-APP-000142-DNS-000014, SRG-APP-000383-DNS-000109, SRG-APP-000516-DNS-000500

Check

Verify Infoblox is configured to prohibit or restrict unapproved ports and protocols.

By default, all services other than those required for management are disabled. Validate that no additional services have been configured for DNS members.

1. Navigate to Infoblox Grid >> Grid Manager >> or to System >> System Manager >> System Properties if using a stand-alone configuration. 2. Select the "Services" tab and review each service at the top of the panel and "Service Status" for each member.

Depending on purchased options, Infoblox DNS service members may be running DNS and optionally running services supporting DNS and security operations such as DNS Traffic Control, Threat Defense, Threat Analytics, and TAXII services.

Use of these additional Infoblox services is not a finding.

If any unnecessary services such as file distribution services are enabled on the DNS members, this is a finding.

Note: DNSSEC is intended for third-party authenticity determination. Attempting to utilize DNSSEC internally was never an intended use case as it would require every consumer to have a third-party validating resolver installed along with a mechanism for periodic trust anchor distribution/update.

Fix

1. Navigate to Infoblox Grid >> Grid Manager or to System >> System Manager >> System Properties if using a stand-alone configuration. 2. Select the "Services" tab. 3. Select each available service at the top of the panel and review the service status. 4. Click on the member and disable unnecessary services.

Identifiers

Group ID
V-285238
Group title
SRG-APP-000142-DNS-000014
Rule ID
SV-285238r1258664_rule
Check ID
C-89807r1258413_chk
Fix ID
F-89712r1258414_fix