More Info:

Determines if TCP or UDP port 53 for DNS is open to the public.

Risk Level

Medium

Address

Security

Compliance Standards

HITRUST, GDPR, SOC2, NISTCSF, PCIDSS, FedRAMP

Triage and Remediation

Remediation

To remediate the DNS Port Should Not Be Open misconfiguration in GCP using the GCP console, please follow the below steps:

  1. Login to the GCP console.

  2. Navigate to the VPC Network page by clicking on the hamburger menu in the top left corner and then selecting “VPC Network” under the “NETWORKING” section.

  3. Select the VPC network that needs to be remediated.

  4. Click on the “Firewall rules” tab.

  5. Identify the firewall rule that is allowing DNS traffic.

  6. Click on the edit button (pencil icon) for that firewall rule.

  7. In the “Targets” section, select “Specified target tags” and remove the tag that allows DNS traffic.

  8. In the “Protocols and ports” section, remove the port that allows DNS traffic.

  9. Click on the “Save” button to save the changes.

  10. Verify that the DNS port is no longer open by running a port scan on the instance.

By following the above steps, you can remediate the DNS Port Should Not Be Open misconfiguration in GCP using the GCP console.

Additional Reading: