NIOS RPZ feed recommendations to use after the feed revamp release in December 2024.
...
Feed Availability | |||
---|---|---|---|
Feed Name | Essentials | Business On-Prem | Advanced |
Infoblox Base | ✔ | ✔ | ✔ |
Infoblox Base IP | NA | ✔ | ✔ |
Infoblox High Risk | NA | NA | ✔ |
Infoblox Medium Risk | NA | NA | ✔ |
Infoblox Low Risk | NA | NA | ✔ |
Infoblox Informational | NA | ✔ | ✔ |
For information for adding the new feeds and sizing requirements to your appliance, see Sizing Guidelines for Trinzic Appliances.
...
Before adding the new NIOS RPZ feeds, you must first identify and remove the existing feeds approaching EOS. To do this, follow these steps:
In NIOS Grid Manager, navigate to Data Management > DNS > Response Policy Zones.
Identify the current NIOS feeds for removal. These can be identified by their
...
names:
base.rpz.infoblox.local
antimalware.rpz.infoblox.local
...
ransomware.rpz.infoblox.local
malware-dga.rpz.infoblox.local
antimalware-ip.rpz.infoblox.local
...
suspicious-med.rpz.infoblox.local
...
suspicious-lookalikes.rpz.infoblox.local
...
suspicious-noed.rpz.infoblox.local
...
noed.rpz.infoblox.local
...
Note: The
...
availability of the new RPZ feeds is dependent on subscription level.
Note: If you have a large number of RPZs, use the search function to locate the feeds to be removed.
Select the checkbox associated with one of the feeds to be removed.
Click the trash can icon or the Delete button in the toolbar.
Click Yes in the Delete Confirmation dialogue.
If you are removing multiple feeds, repeat steps 3-5 for each.
Deletion of RPZs requires a service restart. Click Restart located in the top, yellow banner to perform a system restart.
In the Restart Grid Services dialog, adjust Restart Method if desired and click Restart.
Adding the New NIOS RPZ Feeds to be Released on April 2024
...
In NIOS Grid Manager, navigate to Data Management > DNS > Response Policy Zones.
Click the add icon or the Add button in the toolbar.
On Step 1 of the Add Response Policy Zone Wizard, select Add Response Policy Zone Feed.
Click Next.
On Step 2, paste the Name of the feed, as copied from the Infoblox Portal.
Optionally, adjust Policy Override and Severity. Note: This should reflect the policy used on the SURBL feeds being replaced.
Click Next.
On Step 3, use the Add button dropdown to select External Primary. Note: To save time, you can instead use a nameserver group configured with the external primary and any Grid secondaries to be used for all RPZs. Refer to NIOS Documentation for additional information on creating nameserver groups.
Enter a Name. Note: This field is for reference purpose only, use any name you choose.
Enter the Address of the distribution server as copied from the Infoblox Portal.
Select the box for Use TSIG.
Enter the Key Name as copied from the Infoblox Portal.
Select the Key Algorithm as noted from the Infoblox Portal.
Enter the Key Data as copied from the Infoblox Portal.
Click Add.
Use the Add button followed by selecting Grid Secondary from among the menu option choices.
Click Select followed by choosing the NIOS member to update. Note: You can configure a single secondary to be “Lead Secondary”. If you select this, then that member will be the only one to reach out to the external primary. The feed is then redistributed between members using zone transfers.
Click Add.
(Optional) Repeat Steps 17 and 18 to add additional NIOS appliances as secondaries.
Click Save & Close.
Repeat steps 2-20 for each feed you are adding.
When adding an RPZ a service restart is In the banner at the top of the Grid Manager window, click on Restart.
In the Restart Grid Services dialog, adjust Restart Method if desired and click Restart.
(Optional) Once you have added all feeds, use the Order Response Policy Zones button in the Toolbar to change the order feeds are applied.
In the Order Response Policy Zones dialog, use the arrows to change the
Click OK when complete.
Image: Configuring Order Response Zones for the new NIOS RPZ feeds.
Changing the order of RPZs requires a service restart to take effect. In the banner at the top of the Grid Manager window, click on Restart.
In the Restart Grid Services dialog, adjust Restart Method if desired and click Restart.
...