The Infoblox outbound API is a framework that is used to exchange both IPAM data (such as networks, network containers, hosts, leases) and DNS threat data with external interfaces. It sends object information and conversations to other REST APIs when an event triggers in NIOS. It is important that you receive notifications about the updates to the system. On the other hand, you may sometimes also need to identify and manage low-risk or accidental threats so the endpoint performance is not negatively affected. For example, if a user inadvertently browses to a faulty web site and you have configured RPZ rules to block this site, you may want to receive notifications and take certain actions so the user is not being blocked or quarantined. In addition, when the Infoblox appliance detects a new host or network, the detection might trigger a vulnerability scan by services such as Qualys and a scan for RPZ events configured in NIOS. In this scenario, you might want to configure conditions to capture these events so you can receive outbound notifications and perform appropriate actions to handle the situation.
...
- Ensure that the necessary services and features are configured. These include DHCP, RPZ, Threat Insight, ADP, Network Insight, and BloxOne Infoblox Threat Defense Cloud.
- Create necessary extensible attributes, if required. For more information, see Managing Extensible Attributes.
- Create or download login and logout templates from the Infoblox Community Site at https://community.infoblox.com. Next, add or upload the login and logout templates followed by the session template. Note that you can add a session template or download it from the Infoblox Community Site.
- Download or create notification templates from the Infoblox Community Site at https://community.infoblox.com. Next, add or upload the notification templates.
- Add an endpoint. You can either add REST API or DXL endpoints. For DXL endpoints, you must generate a NIOS client certificate, import DXL certificates and import or add list of DXL brokers. For more information, see Configuring Outbound Endpoints.
- Define notification rules. For more information, see Configuring Notification Rules.
...
License | Event Types |
---|---|
RPZ | DNS RPZ |
DNS and DHCP | DHCP Lease |
Threat AnalyticsInsight | DNS Tunneling |
Advanced DNS Protection | Security ADP |
RPZ and Security Ecosystem | BloxOne Infoblox Threat Defense Cloud |
Network Discovery | Object Change Discovery Data |
For information about how to install licenses, see Managing Licenses in NIOS 9.0.01 and Later.
Administrative Permissions
...