Depending on your subscription level, each feed and Threat Insight policy in the Default Global Policy comes with a default action.
...
The following table lists the default actions and precedence for the feeds and Threat Insight in the Default Global Policy (to be supported until December 2024 and deprecated after December 2024):.
Feed Name | Default Action | Default Precedence |
---|---|---|
Default Allow List | Allow - No log | 1 |
Default Block List | Block – No Redirect | 2 |
Infoblox Base | Block – No Redirect | 3 |
Infoblox Base IP | Block – No Redirect | 4 |
Infoblox High Risk | Block – No Redirect | 5 |
Threat Insight - Zero Day DNS | Block – No Redirect | 6 |
Infoblox Medium Risk | Block – No Redirect | 7 |
Threat insight - DGA | Allow – With Log | 8 |
Threat Insight - Data Exfiltration | Allow – With Log | 9 |
Threat Insight - Fast Flux | Allow – With Log | 10 |
Threat Insight - DNS Messenger | Allow – With Log | 11 |
Infoblox Low Risk | Allow – With Log | 12 |
Infoblox Informational | Allow – With Log | 13 |
Threat Insight - Notional Data Exfiltration | Allow – With Log | 14 |
...
Note | ||
---|---|---|
| ||
|
- Ensure that the precedence order assigned to the Security Policies are properly configured.
- Make sure that Geolocation option is enabled in Security Policy to ensure that the ECS supported domains should get DNS response accordingly from the authoritative nameservers. For more information, see Best Practices for Data Connector.
- Ensure that the precedence order assigned to the Security Policies are properly configured.
Note | ||
---|---|---|
| ||
For information on the recommended Rule Actions to be applied in preparation of the August 22, 2023 feed changes, see the topic on Recommended Rule Actions in Preparation of the August 2023 Feed Changes. For information on recommended rule actions to be applied to feeds as replacement to the deprecated SURBL feeds, see Recommended Feed Configuration to Replace the SURBL Feeds. |
...