...
- Define name servers for the RPZ feed. An RPZ feed must have at least one RPZ source as an external primary name server and at least one Grid secondary name server. For external primary servers, specify the following:
- Name: Enter the zone name of the primary name server.
- Address: Enter the name server IP address provided by Infoblox for the RPZ feed.
- Use TSIG: Select the check box to specify TSIG settings.
- Key Name: Enter the TSIG Key Name provided by Infoblox.
- Key Algorithm: Select hmac-md5.
- Key Data: Enter the TSIG string provided by Infoblox.
Note that either the Grid name server or the DNS view must be recursive for the RPZ feed. You can associate a lead secondary with an RPZ feed. For information on specifying primary and secondary, see Assigning Zone Authority to Name Servers. When you select All Recursive Name Servers from the list, all the recursive name servers in the Grid are added as secondary servers for the zone. For information about all recursive name servers, see Configuring RPZs for All Recursive Servers. For information on specifying name server groups, see About Name Server Groups .
5. Save the configuration and click Next to define extensible attributes. Click Restart if it appears at the top of the screen. For information, see About Extensible Attributes.
Anchor |
---|
| Infoblox Threat Intelligence Feeds |
---|
| Infoblox Threat Intelligence Feeds |
---|
|
Infoblox Threat Intelligence Feeds
Infoblox RPZ feeds are categorized into pure malicious feeds and combination feeds. All the feeds listed below are set to return NXDOMAIN for items in the feed. Threat data changes are pushed every 20 minutes from the DNS servers and significant changes are typically made every two hours.
The following tables list the Infoblox Threat Intelligence feeds:
Table 42.1 Pure Malicious Feeds
...