The following feed policy configuration is recommended after the SURBL feeds deprecation in mid-August.
Info | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| |||||||||||||||||||||||||||
New feed recommendations: It is recommended that you do the following regarding the new feeds:
The following table includes the list of feeds that we will be retiring:
As these feeds are being retired, NIOS platforms will no longer be able to download them. This may present itself as a problem with the Zone transfer. To avoid this issue, these feeds should be removed as soon as possible. As they have been empty for a long time, there will be no negative effect on the organization’s security posture. This only affects NIOS platforms using these RPZ feeds, as cloud-based configurations are updated automatically. For information on adding and removing feeds from a security policy, see the following: |
Note | ||
---|---|---|
| ||
|
The following table lists the default actions and precedence for the feeds and Threat Insight in the Default Global Policy:
Feed Name | Default Action | Default Precedence | |
---|---|---|---|
AntiMalwareBase | Block – No Redirect | 1 | Base|
AntiMalware | Block – No Redirect | 2 | |
Malware_ | AIS_DomainDGA | Block – No Redirect | 3 | Malware_DGA
Ransomware | Block – No Redirect | 4 | |
RansomwarePublic_DOH | Block – No Redirect | 5 | |
SuspiciousPublic_DOH_NOEDIP | Block – No Redirect | 6 | |
Suspicious_LookalikesThreat | Block Allow – No RedirectWith Log | 7 | |
Suspicious_Domains | Block – No Redirect | 8 | |
AntiMalware_IPThreat Insight-Data Exfiltration | Allow – With Log | 8 | |
Threat Insight-Fast Flux | Allow – With Log | 9 | |
BogonThreat Insight-DNS Messenger | Allow – With Log | 10 | |
DHS_AISAntiMalware_IP | Allow – With Log | 11 | |
Ext_AntiMalwareBase_IPAntiMalwar | Allow – With Log | 12 | |
Ext_Base_AntiMalwareRansomware | Allow – With Log | 13 | |
Ext_RansomwareAntiMalware_IP | Allow – With Log | 14 | |
USDHS_OFAC_Sanctions_IP_EmbargoedAIS_Domain | Allow – With Log | 15 | |
TOR_Exit_Node_IPCryptoCurrency | Allow – With Log | 16 | |
Threat Insight-Data Exfiltration | Allow – With Log | 17 | |
Threat Insight - DGA | Allow – With Log | 18 | |
Threat Insight-DNS Messenger | Allow – With Log | 19 | |
Threat Insight-Fast Flux | Allow – With Log | 20 | |
CryptoCurrency | Allow – With Log | 21 | |
Spambot_DNSBL_IP | Allow – With Log | 22 | |
NOED | Allow – With Log | 23 | |
FarSightNOD | Allow – With Log | 24 | |
ETQRisk | Allow – With Log | 25 | |
ETQRiskTOR_Exit_Node_IP | Allow – With Log | 26 | |
EECN_IP | Allow – No Log | 27 | |
Public_DOH | Allow – No Log | 28 | |
Public_DOH_IP | Allow – No Log | 2917 |
For information on adding and removing feeds from a security policy, see the following:
...