Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Version History

« Previous Version 26 Next »


Advisory

For information on the recommended Rule Actions to be applied in preparation of the August 22, 2023 feed changes, see the topic on Recommended Rule Actions in Preparation of the August 2023 Feed Changes

For information on recommended rule actions to be applied to feeds as replacement to the deprecated SURBL feeds, see Recommended Feed Configuration to Replace the SURBL Feeds

For each policy rule, such as custom lists, feed and Threat Insight, and category and application filters, you can define the action or override it as one of the following:

  • Allow – With Log: Grants traffic access to a domain or IP address that hits a particular feed or security policy, and logs the queries to all relevant reports.
  • Allow – No Log: Grants traffic access to a domain or IP address that hits a particular feed or security policy, but does not log the queries to any reports.
  • Allow - Local Resolution: This rule action is only available when configuring an application filter. It allows web applications to bypass DNS and resolve on the local host.  
  • Block – No Redirect: Denies traffic access to a domain or an IP address if it matches that of a particular feed.
  • Block – Default Redirect: Routes traffic to the default Infoblox page or a custom message that you have configured for the Redirect Page.
  • Block – Redirect – <custom redirect name>: Routes traffic to a destination based on the IP address or domain you have configured for the Redirect Page. For information about how to configure a custom redirect page, see Defining the Redirect Page.

Depending on your subscription level, each feed and Threat Insight policy in the Default Global Policy comes with a default action. 

Note

  • Given that IP addresses can be reused over a period of time, blocking IP addresses is riskier than blocking domains or hostnames. So, to avoid false positives, for those external or third-party IP-based feeds like DHS_AIS_IP that are added to policy through voluntary addition (other than what’s provided by default), Infoblox recommends only an Allow-With Log policy action and not a Block policy action.

The following table lists the default actions and precedence for the feeds and Threat Insight in the Default Global Policy offered by Infoblox as of August 31, 2023. The default actions and precedence described applies only to new accounts created on or after August 31, 2023. Accounts created and configured prior to August 31, 2023 will not be affected by the new default actions and/or precedence described. In the case of prior existing accounts , the actions and precedence in effect at the time of custom list creation will not be altered. Ensure that you understand the ramification of overriding the default action for any threat feeds and Threat Insight rules before doing so.

For information on best practices when configuring feed precedence order, see Best Practices for Configuring Feed Precedence.


Feed NameDefault ActionDefault Precedence
Default Allow ListAllow - No log1
Default Block ListBlock  – No Redirect2
Base HostnamesBlock  – No Redirect3
AntiMalwareBlock  – No Redirect4
Malware DGA HostnamesBlock  – No Redirect5
RansomwareBlock  – No Redirect6
Threat Insight - Rapid Domain TriageBlock  – No Redirect7
SuspiciousBlock  – No Redirect8
Suspicious LookalikesBlock  – No Redirect9
Suspicious NOEDBlock  – No Redirect10
DOH Public Hostnames Block  – No Redirect11
DOH Public IPsBlock  – No Redirect12
Newly Observed Emergent DomainsAllow – With Log13
Threat Insight - DGAAllow – With Log14
Threat Insight-Data ExfiltrationAllow – With Log15
Threat Insight-Fast FluxAllow – With Log16
Threat Insight-DNS MessengerAllow – With Log17
AntiMalware_IPAllow – With Log18
Threat Insight - Notional Data ExfiltrationAllow – With Log19
Extended Base and Anti-malware HostnamesAllow – With Log20
Extended Ransomware IPsAllow – With Log21
Extended AntiMalware IPsAllow – With Log22
DHS_AIS_ HostnameAllow – With Log23
Cryptocurrency hostnames and domainsAllow – With Log24
TOR Exit Node IPsAllow – With Log25

For information on adding and removing feeds from a security policy, see the following: 

  • No labels