Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Infoblox Mobile Endpoint is a lightweight mobile cloud service for sending queries over an encrypted channel. Mobile Endpoint communicates with Infoblox Threat Defense by using DNS over Transport Layer Security (DoT). Mobile Endpoint provides visibility into infected and compromised devices detected on the network (including Android, iOS, and ChromeOS), preventing DNS-based data exfiltration and other forms of DNS tunneling, and impedes device communications with botnets and their command-and-control infrastructure. Note that Mobile Endpoint is not a VPN client. 

The Mobile Endpoint client uses on-device VPN by default to intercept the DNS traffic, in case of iOS, the admin can also configure Extension Type as DNS Proxy (this setting is mentioned in the “Installing Mobile Endpoint” section, below).

Supported Devices

...

Mobile Endpoint is designed to route DNS queries directly to Infoblox Threat Defense. If your network setup includes internally hosted domains, you should add them to the bypassed internal domains list; this will ensure uninterrupted access to local resources, such as servers, computers, and printers on your network. After you add internal domains to the list, Mobile Endpoint will direct DNS requests for these internal domains to your local DNS servers, for resolution. For information on how to add domains to the bypass list, see /wiki/spaces/BloxOneThreatDefense/pages/9080650Configuring Internal Domains

By supporting dual-stack IPv4/IPv6 as well as IPv6 DNS configurations, Mobile Endpoint protects all devices, regardless of their network environments. This means Mobile Endpoint will protect roaming clients in different networking environments. When Mobile Endpoint is connected to a network, the endpoint can communicate with Infoblox Platform by using both IP address protocols. Mobile Endpoint in a dual-stack environment is able to proxy IPv6 DNS queries and forward them to Infoblox Platform over IPv4.

...