Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Note
titleAdvisory

For information on the recommended Rule Actions to be applied to feeds for the upcoming, August 22, 2023 feed changes, see the topic on Recommended Rule Actions in Preparation for the August Feed Deprecations


For each policy rule, such as custom lists, feed and Threat Insight, and category and application filters, you can define the action or override it as one of the following:

...

Depending on your subscription level, each feed and Threat Insight policy in the Default Global Policy comes with a default action. 

...

titleRecommended Actions

New feed recommendations: It is recommended that you do the following regarding the new feeds:

  • Add Suspicious Domains with one of the policy actions to Block.
  • Add Suspicious Lookalikes with one of the policy actions to  Block.
  • Add Suspicious NOED with one of the policy actions to  Block.

The following table includes the list of feeds that we will be retiring:

...

Feed

...

RPZ Name

...

Retirement Date

...

Reason

...

Bot-IP

...

bot-ip.rpz.infoblox.local

...

4/1/2023

...

IP addresses are frequently reused for multiple sites, and blocking the ones associated with such systems ran the high risk of inadvertent blocking (I.E. False Positive). Many indicators here could be blocked in other ways, so the source is blocked in other similar feeds, making this redundant.

...

Spambot-IP

...

spambot-ip.rpz.infoblox.local

...

4/1/2023

...

ExploitKit_IP

...

exploitkit-ip.rpz.infoblox.local

...

June 2023

...

Ext_ExploitKit_IP

...

ext-exploitkit-ip.rpz.infoblox.local

...

June 2023

...

Ext_TOR_Exit_Node_IP 

...

ext-tor-exit-node-ip.rpz.infoblox.local

...

June 2023

...

NCCIC_Host

...

nccic-host.rpz.infoblox.local

...

As these feeds are being retired, NIOS platforms will no longer be able to download them.  This may present itself as a problem with the Zone transfer. To avoid this issue, these feeds should be removed as soon as possible. As they have been empty for a long time, there will be no negative effect on the organization’s security posture. This only affects NIOS platforms using these RPZ feeds, as cloud-based configurations are updated automatically.  

The curation process for these feeds (I.E. removing false positives) frequently left these feeds empty. The ones that remained are present in other feeds, making these feeds redundant.

NCCIC_IP

nccic-ip.rpz.infoblox.local

June 2023

Note
titleNote

Ensure that you understand the ramification when overriding the default action for any threat feeds and Threat Insight rules before you do so.

The following table lists the default actions and precedence for the feeds and Threat Insight in the Default Global Policy:

Feed NameDefault ActionDefault Precedence
AntiMalware
BaseBlock  – No Redirect1
Base
AntiMalwareBlock  – No Redirect2
DHS
Malware_
AIS_Domain
DGABlock  – No Redirect3
Malware_DGA
RansomwareBlock  – No Redirect4
Ransomware
SURBL_MultiBlock  – No Redirect5
Suspicious
Public_
NOED
DOHBlock  – No Redirect6
Suspicious
Public_DOH_
Lookalikes
IPBlock  – No Redirect7
Suspicious_DomainsBlock  – No Redirect8AntiMalware_IP
Threat Insight - DGAAllow – With Log8
Threat Insight-Data ExfiltrationAllow – With Log9
Bogon
Threat Insight-Fast FluxAllow – With Log10
DHS_AIS_IP
Threat Insight-DNS MessengerAllow – With Log11
Ext_
AntiMalware_IPAllow – With Log12
Ext_Base_AntiMalwareAllow – With Log13
Ext_RansomwareAllow – With Log14
US
Ext_
OFAC
AntiMalware_
Sanctions_
IP
_Embargoed
Allow – With Log15
TOR_Exit_Node_IP
SURBL_FreshAllow – With Log16
Threat Insight-Data Exfiltration
DHS_AIS_DomainAllow – With Log17
Threat Insight - DGA
CryptoCurrencyAllow – With Log18
Threat Insight-DNS MessengerAllow – With Log19Threat Insight-Fast FluxAllow – With Log20CryptoCurrencyAllow – With Log21Spambot_DNSBL_IPAllow – With Log22NOEDAllow – With Log23FarSightNODAllow – With Log24ETQRiskAllow – With Log25ETQRisk
TOR_Exit_Node_IPAllow – With Log
26
19
EECN_IP
Blocklist
Allow
Block  – No
Log27Public_DOHAllow – No Log28Public_DOH_IPAllow – No Log29
Redirect20


For information on adding and removing feeds from a security policy, see the following: