<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158261#M36012</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/65619"&gt;@TMACMD&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please help me with the procedure so that I will try it in my environment.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2020 16:48:41 GMT</pubDate>
    <dc:creator>PnaveenKumar</dc:creator>
    <dc:date>2020-08-04T16:48:41Z</dc:date>
    <item>
      <title>ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF system</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158190#M35967</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we perform internal scans on our NetApp Cluster mode storage systems, we found below vulnerabilities.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISC BIND Denial of service&lt;/P&gt;
&lt;P&gt;ISC BIND Service downgrade/reflected DOS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We found these issues on all Netapp clusters except one cluster. Now my task is to&amp;nbsp; compare the configurations on the clusters with one cluster where these vulnerabilities are not found.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What are all the configurations I need to check on my clusters to resolve this ISC BIND issues?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help on this is appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CVE: CVE-2020-8616&lt;BR /&gt;Plugin Name Severity IP Address Protocol Port&lt;BR /&gt;ISC BIND Denial of&lt;BR /&gt;Service High IP Address UDP 53&lt;BR /&gt;Plugin Text:&lt;BR /&gt;Plugin Output:&lt;BR /&gt;Installed version : 9.6.2-P2&lt;BR /&gt;Fixed version : 9.11.19&lt;BR /&gt;Synopsis: The remote name server is affected by an assertion failure vulnerability.&lt;BR /&gt;Description: A denial of service (DoS) vulnerability exists in ISC BIND versions 9.11.18 / 9.11.18-S1 / 9.12.4-P2 / 9.13 / 9.14.11 / 9.15 / 9.16.2 / 9.17 /&lt;BR /&gt;9.17.1 and earlier. An unauthenticated, remote attacker can exploit this issue, via a specially-crafted message, to cause the service to stop responding.&lt;BR /&gt;Solution: Upgrade to the patched release most closely related to your current version of BIND.&lt;BR /&gt;See Also: &lt;A href="https://kb.isc.org/docs/cve-2020-8617" target="_blank"&gt;https://kb.isc.org/docs/cve-2020-8617&lt;/A&gt;&lt;BR /&gt;CVE: CVE-2020-8617&lt;BR /&gt;Plugin Name Severity IP Address Protocol Port&lt;BR /&gt;ISC BIND Service&lt;BR /&gt;Downgrade / Reflected&lt;BR /&gt;DoS&lt;BR /&gt;Medium IP Address UDP 53&lt;BR /&gt;Plugin Text:&lt;BR /&gt;Plugin Output:&lt;BR /&gt;Installed version : 9.6.2-P2&lt;BR /&gt;Fixed version : 9.11.19&lt;BR /&gt;Synopsis: The remote name server is affected by Service Downgrade / Reflected DoS vulnerabilities.&lt;BR /&gt;Description: According to its self-reported version, the instance of ISC BIND 9 running on the remote name server is affected by performance&lt;BR /&gt;downgrade and Reflected DoS vulnerabilities. This is due to BIND DNS not sufficiently limiting the number fetches which may be performed while&lt;BR /&gt;processing a referral response.&lt;BR /&gt;An unauthenticated, remote attacker can exploit this to cause degrade the service of the recursive server or to use the affected server as a reflector in&lt;BR /&gt;a reflection attack.&lt;BR /&gt;Solution: Upgrade to the ISC BIND version referenced in the vendor advisory.&lt;BR /&gt;See Also: &lt;A href="https://kb.isc.org/docs/cve-2020-8616" target="_blank"&gt;https://kb.isc.org/docs/cve-2020-8616&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:58:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158190#M35967</guid>
      <dc:creator>PnaveenKumar</dc:creator>
      <dc:date>2025-06-04T10:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158198#M35972</link>
      <description>&lt;P&gt;So, you need to remember a lot of these scans do in fact provide false positives.&lt;/P&gt;
&lt;P&gt;The reason is roughly because they scan certain elements and assume a particular operating system and version.&lt;/P&gt;
&lt;P&gt;ONTAP is uses different chunks of code for different areas. (like IP/TCP/DNS/etc).&lt;/P&gt;
&lt;P&gt;A lot of scans think ONTAP is FreeBSD. It is not. It is loosely based on it with updated modules.&lt;/P&gt;
&lt;P&gt;So assuming FreeBSD is not good especially if the module in question is already patched.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may be able to correlate the CVE to a NetApp here:&amp;nbsp;&lt;A href="https://security.netapp.com/advisory/" target="_blank"&gt;https://security.netapp.com/advisory/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Which I did here:&amp;nbsp;&lt;A href="https://security.netapp.com/advisory/ntap-20200522-0002/" target="_blank"&gt;https://security.netapp.com/advisory/ntap-20200522-0002/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But also looking:&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Affected Products&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;E-Series SANtricity OS Controller Baseboard Management Controller (BMC) - EF600A&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;NetApp HCI Baseboard Management Controller (BMC) - H410C&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;STRONG&gt;Products Under Investigation&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;NetApp SteelStore Cloud Integrated Storage&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;And I see "&lt;SPAN&gt;Clustered Data ONTAP" under "Not Affected". So, it is very likely that your scanner is detecting an old version of FreeBSD that does not have the patch, however, ONTAP has already been patched and is not affected.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 12:51:53 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158198#M35972</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-08-03T12:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158205#M35975</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/65619"&gt;@TMACMD&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much for your response. The information provided by you is very helpful to me.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I mentioned earlier, we don't see this ISC BIND vulnerability in one of our cluster which is running in the same Ontap version(9.5P6). I don't know what is the difference between this specific cluster compared to remaining clusters. Please review the attached screenshots and kindly respond back if you find anything &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PnaveenKumar_0-1596460409532.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/9924iCD78F638FFE5888B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PnaveenKumar_0-1596460409532.png" alt="PnaveenKumar_0-1596460409532.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PnaveenKumar_1-1596460456779.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/9925iBC197AB6B75FEE36/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PnaveenKumar_1-1596460456779.png" alt="PnaveenKumar_1-1596460456779.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PnaveenKumar_2-1596460509016.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/9926i1BEB04C8910ECB78/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PnaveenKumar_2-1596460509016.png" alt="PnaveenKumar_2-1596460509016.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PnaveenKumar_3-1596460562299.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/9927i5E1E0147D5F0BDDC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PnaveenKumar_3-1596460562299.png" alt="PnaveenKumar_3-1596460562299.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 13:16:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158205#M35975</guid>
      <dc:creator>PnaveenKumar</dc:creator>
      <dc:date>2020-08-03T13:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158207#M35977</link>
      <description>&lt;P&gt;Can’t tell anything from that shot&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i suspect you likely have different visions of ontap on those clusters which is why the response is a little different (refer to my original post about modules)&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 13:24:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158207#M35977</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-08-03T13:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158208#M35978</link>
      <description>&lt;P&gt;BIND is likely being scanned on your data LIFs. We have a feature called "on-box DNS," where the ONTAP LIFs can listen for DNS queries and ONTAP uses BIND to serve DNS requests to data LIFs based on a calculated weight.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You probably have it enabled on the data LIFs for the cluster in question. You can check with the following command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;::*&amp;gt; net int show -listen-for-dns-query true -fields dns-zone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information regarding on-box DNS, see TR-4523.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.netapp.com/us/media/tr-4523.pdf" target="_blank"&gt;https://www.netapp.com/us/media/tr-4523.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 13:24:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158208#M35978</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2020-08-03T13:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158216#M35986</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/65619"&gt;@TMACMD&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All my NetApp Clusters running on the same Ontap version - 9.5P6.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 13:52:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158216#M35986</guid>
      <dc:creator>PnaveenKumar</dc:creator>
      <dc:date>2020-08-03T13:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158217#M35987</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/11621"&gt;@parisi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All my Clusters are configured with On-box DNS. The On-box DNS BIND configuration is same on the cluster where we don't find BIND Vulnerabilities and Where we have BIND vulnerabilities.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am confused, as both of them have same configurations and BIND vulnerability is showing on only one cluster.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No BIND issue Cluster:&lt;/P&gt;
&lt;P&gt;TORNASCLUSTER_MGMT::&amp;gt; network interface show -listen-for-dns-query true -fields dns-zone&lt;BR /&gt;vserver lif dns-zone&lt;BR /&gt;------------- ----- --------------------------&lt;BR /&gt;TORNASCLUSTER NAS01 tornascluster.corp.frk.com&lt;BR /&gt;TORNASCLUSTER NAS02 tornascluster.corp.frk.com&lt;BR /&gt;TORNASCLUSTER NAS03 tornasds.corp.frk.com&lt;BR /&gt;TORNASCLUSTER NAS04 tornasds.corp.frk.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BIND issue Cluster:&lt;/P&gt;
&lt;P&gt;CHENASCLUSTER1_MGMT::&amp;gt; network interface show -listen-for-dns-query true -fields dns-zone&lt;BR /&gt;vserver lif dns-zone&lt;BR /&gt;-------------- ----- ---------------------------&lt;BR /&gt;CHENASCLUSTER1 NAS01 chenascluster1.corp.frk.com&lt;BR /&gt;CHENASCLUSTER1 NAS02 chenascluster1.corp.frk.com&lt;BR /&gt;CHENASCLUSTER1 NAS03 chenasds.corp.frk.com&lt;BR /&gt;CHENASCLUSTER1 NAS04 chenasds.corp.frk.com&lt;BR /&gt;4 entries were displayed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anything I need to take a look &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 13:56:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158217#M35987</guid>
      <dc:creator>PnaveenKumar</dc:creator>
      <dc:date>2020-08-03T13:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158221#M35990</link>
      <description>&lt;P&gt;Probably should just do a config comparison between the clusters. As TMAC pointed out, ONTAP isn't exposed to the vulnerability, so it shouldn't be a concern, but there's likely one setting that's different between the two.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 14:34:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158221#M35990</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2020-08-03T14:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158250#M36004</link>
      <description>&lt;P&gt;Can you get details about how the security scanner is finding the "vulnerability"?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 14:40:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158250#M36004</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2020-08-04T14:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158256#M36007</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/45689"&gt;@paul_stejskal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Security team is using Tenable Nessus for these scans. I don't know anything apart from that.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 16:05:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158256#M36007</guid>
      <dc:creator>PnaveenKumar</dc:creator>
      <dc:date>2020-08-04T16:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158257#M36008</link>
      <description>&lt;P&gt;Ahh....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is another method they should use....&lt;/P&gt;
&lt;P&gt;Essentially, you create a nessus user in ONTAP. Allow the scan to connect to ONTAP and scan from inside. This results in far fewer false-positive results.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 16:25:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158257#M36008</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-08-04T16:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158258#M36009</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/65619"&gt;@TMACMD&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any documentation or process to do that?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 16:35:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158258#M36009</guid>
      <dc:creator>PnaveenKumar</dc:creator>
      <dc:date>2020-08-04T16:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158259#M36010</link>
      <description>&lt;P&gt;Yeah the scan is likely signature based and is looking probably for a specific string, not actually performing the DNS attack.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 16:41:52 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158259#M36010</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2020-08-04T16:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158260#M36011</link>
      <description>&lt;P&gt;Exactly. And allowing Nessus to scan from inside ONTAP gets rid of the issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a had a few customer allow this and all the false-positives went away.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 16:44:54 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158260#M36011</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-08-04T16:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158261#M36012</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/65619"&gt;@TMACMD&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please help me with the procedure so that I will try it in my environment.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 16:48:41 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158261#M36012</guid>
      <dc:creator>PnaveenKumar</dc:creator>
      <dc:date>2020-08-04T16:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158262#M36013</link>
      <description>&lt;P&gt;Based on this link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.tenable.com/nessus/compliancechecksreference/Content/NetAppAPIScanRequirements.htm" target="_blank"&gt;https://docs.tenable.com/nessus/compliancechecksreference/Content/NetAppAPIScanRequirements.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Create a user, with admin, read-only, applications: ontapi/http:&lt;/P&gt;
&lt;PRE&gt;security login create -user-or-group-name nessus -application ontapi -authentication-method password -role readonly&lt;BR /&gt;security login create -user-or-group-name nessus -application http -authentication-method password -role readonly&lt;/PRE&gt;
&lt;P&gt;Set the password.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use the API method to Scan ONTAP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cannot help beyond that. I have never run Nessus. I have only assisted in creating the connection-point in ONTAP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 17:02:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158262#M36013</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-08-04T17:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISC BIND Denial of service and ISC BIND Service downgrade/reflected DOS on NetApp FAS and AFF sy</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158268#M36015</link>
      <description>&lt;P&gt;Nessus has correctly identified the BIND version in ONTAP and is flagging known vulnerabilities in it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NetApp security advisories report the exploitability status of our products.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 21:22:54 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ISC-BIND-Denial-of-service-and-ISC-BIND-Service-downgrade-reflected-DOS-on/m-p/158268#M36015</guid>
      <dc:creator>kryan</dc:creator>
      <dc:date>2020-08-04T21:22:54Z</dc:date>
    </item>
  </channel>
</rss>

