3.1.8.3 DNS Policy Validation
The DNS Policy configured at the server level has certain restrictions. The following table describes the valid settings:
DNS_RPC_POLICY_LEVEL |
DNS_RPC_POLICY_TYPE allowed |
DNS_RPC_POLICY_ACTION_TYPE allowed |
DNS Policy Content |
---|---|---|---|
DnsPolicyZoneLevel |
DnsPolicyQueryProcessing |
DnsPolicyDeny DnsPolicyIgnore |
There MUST be no DNS Policy content specified. |
DnsPolicyZoneLevel |
DnsPolicyQueryProcessing |
DnsPolicyAllow |
The DNS Policy content field MUST be populated with zone scopes configured for the zone. |
DnsPolicyZoneLevel |
DnsPolicyZoneTransfer |
DnsPolicyDeny DnsPolicyIgnore |
There MUST be no DNS Policy content specified. |
DnsPolicyServerLevel |
DnsPolicyQueryProcessing |
DnsPolicyDeny DnsPolicyIgnore |
There MUST be no DNS Policy content specified for DNS Policy at the server level. |
DnsPolicyServerLevel |
DnsPolicyRecursion |
DnsPolicyDeny DnsPolicyIgnore |
There MUST be no DNS Policy content specified. |
DnsPolicyServerLevel |
DnsPolicyRecursion |
DnsPolicyAllow |
The DNS Policy content field MUST be populated with server scopes. |
DnsPolicyServerLevel |
DnsPolicyZoneTransfer |
DnsPolicyDeny DnsPolicyIgnore |
There MUST be no DNS Policy content specified. |
DnsPolicyServerLevel |
DnsPolicyDynamicUpdate |
DnsPolicyDeny DnsPolicyIgnore |
There MUST be no DNS Policy content specified. |
DnsPolicyServerLevel |
DnsRRLExceptionList |
DnsPolicyDeny |
There MUST be no DNS Policy content specified. |