Ensure that the root domain Alias record routes traffic to an associated Classic, Application, or Network Load Balancer. An Alias record provides a Route 53–specific extension to DNS functionality. Instead of an IP address or a domain name, an Alias record must contain a pointer to your load balancer. Before running this rule by the Trend Micro Cloud One™ – Conformity engine, your root domain name must be configured in the rule settings, on your Conformity account console.
Your Amazon Route 53 hosted zone can hold a special record type called Alias that allows you to create an A record for the root domain and point it to the fully qualified domain (FQDN) of the load balancer associated with your application. In the same way records for all other layers should be created in order to allow flexibility in the application design and avoid hardcoding the FQDN of a resource.
Note: Make sure that you replace all <root_domain_name>
placeholders outlined in the conformity rule content with your own root domain name.
Audit
To determine if your Amazon Route 53 hosted zones contain Alias records that point to your load balancers, perform the following actions:
Remediation / Resolution
To configure Amazon Route 53 to route traffic to your AWS Elastic Load Balancer (Classic, Application, or Network Load Balancer), perform the following actions:
References
- AWS Documentation
- Amazon Route 53 FAQs
- Working with Public Hosted Zones
- Configuring Amazon Route 53 as Your DNS Service
- Routing Traffic to an ELB Load Balancer
- Values for Alias Records
- CIS Amazon Web Services Foundations
- AWS Command Line Interface (CLI) Documentation
- route53
- list-hosted-zones
- list-resource-record-sets
- change-resource-record-sets
- get-change
Unlock the Remediation Steps
Free 30-day Trial
Automatically audit your configurations with Conformity
and gain access to our cloud security platform.
You are auditing:
Check for Root Domain Alias Records that Point to Load Balancers
Risk Level: Medium