In preparation of the August 2023 feed changes, Infoblox recommends the following rule action changes to your feed policy rules.
...
title | Alert |
---|
New feed recommendations: It is recommended that you do the following regarding the new feeds:
- Add Suspicious Domains with one of the policy actions to Block.
- Add Suspicious Lookalikes with one of the policy actions to Block.
- Add Suspicious NOED with one of the policy actions to Block.
The following table includes the list of feeds that we will be retiring:
...
Feed
...
RPZ Name
...
Retirement Date
...
Reason
...
Bot-IP
...
bot-ip.rpz.infoblox.local
...
4/1/2023
...
IP addresses are frequently reused for multiple sites, and blocking the ones associated with such systems ran the high risk of inadvertent blocking (I.E. False Positive). Many indicators here could be blocked in other ways, so the source is blocked in other similar feeds, making this redundant.
...
Spambot-IP
...
spambot-ip.rpz.infoblox.local
...
4/1/2023
...
ExploitKit_IP
...
exploitkit-ip.rpz.infoblox.local
...
June 2023
...
Ext_ExploitKit_IP
...
ext-exploitkit-ip.rpz.infoblox.local
...
June 2023
...
Ext_TOR_Exit_Node_IP
...
ext-tor-exit-node-ip.rpz.infoblox.local
...
June 2023
...
NCCIC_Host
...
nccic-host.rpz.infoblox.local
...
June 2023
...
The curation process for these feeds (I.E. removing false positives) frequently left these feeds empty. The ones that remained are present in other feeds, making these feeds redundant.
...
NCCIC_IP
...
nccic-ip.rpz.infoblox.local
...
June 2023
...
.
...
Note | ||
---|---|---|
| ||
|
Info |
---|
The recommended rule actions are for reference only. They represent the results of lab testing in a controlled environment focused on individual protocol services. Enabling additional protocols, services, cache hit ratio for recursive DNS, and customer environment variables will affect performance. To design and size a solution for a production environment, please contact your Infoblox Solution Architect. |
The following table lists the default actions and precedence for the feeds and Threat Insight in the Default Global Policy available May 2024:
Feed Name | Default Action | Default Precedence | |||
---|---|---|---|---|---|
Default Allow List | Allow - No Log | 1 | |||
Default Bloxk List | Block – No Redirect | 2 | |||
Infoblox Base | Block – No Redirect | 3 | |||
Infoblox Base IP | Block – No Redirect | 4 | |||
Infoblox High Risk | Block – No Redirect | 5 | |||
Threat Insight - Zero Day DNS | Block – No Redirect | 6 | |||
Infoblox Medium Risk | Block – No Redirect | 7 | |||
Threat insight - DGA | Allow – With Log | 8 | |||
Threat Insight-Data Exfiltration | Allow – With Log | 9 | Threat Insight-Fast Flux | Allow – With Log | 10 |
Threat Insight-DNS Messenger | Allow – With Log | 1110 | |||
Infoblox Low Risk | Allow – With Log | 1211 | |||
Infoblox Informational | Allow – With Log | 1312 | |||
Threat insight - Notional Data Exfiltration | Allow – With Log | 1413 |
The following table lists the default actions and precedence for the feeds and Threat Insight in the Default Global Policy (to be supported until December 2024 and deprecated after December 2024):
Feed Name | Default Action | Default Precedence | |||
---|---|---|---|---|---|
Base Hostnames | Block – No Redirect | 1 | |||
AntiMalware | Block – No Redirect | 2 | |||
Malware_DGA Hostnames | Block – No Redirect | 3 | |||
Ransomware | Block – No Redirect | 4 | |||
Public_DOH | Block – No Redirect | 5 | |||
Public_DOH_IP | Block – No Redirect | 6 | |||
Domain | Allow – With Log | 7 | |||
Threat Insight-Data Exfiltration | Allow – With Log | 8 | |||
Threat Insight - Notional Data Exfiltration | Allow – With Log | 9 | |||
Threat Insight-Fast Flux | Allow – With Log | 10 | Threat Insight-DNS Messenger | Allow – With Log | 1110 |
AntiMalware_IP | Allow – With Log | 1211 | |||
Ext_Base_AntiMalwar | Allow – With Log | 1312 | |||
Ext_Ransomware | Allow – With Log | 1413 | |||
Ext_AntiMalware_IP | Allow – With Log | 1514 | |||
DHS_AIS_Domain | Allow – With Log | 1615 | |||
CryptoCurrency | Allow – With Log | 1716 | |||
TOR_Exit_Node_IP | Allow – With Log | 1817 |
For information on adding and removing feeds from a security policy, see the following:
...