/
Recommended Rule Actions in Preparation of the August 2023 Feed Changes

Recommended Rule Actions in Preparation of the August 2023 Feed Changes

In preparation of the August 2023 feed changes, Infoblox recommends the following rule action changes to your feed policy rules.

 Feed Precedence Order

  • When configuring feed precedence order, Please remember to prioritize feeds configured with a Block action (Block - No Redirect, Block - Default Redirect, and/or Block - Redirect - <custom redirect name>) by placing them in positions of higher precedence in your policy compared to feeds configured with an Allow action (Allow - With Log, Allow - No Log, and/or Allow - Local Resolution).Placing Blocked feeds higher in policy precedence order than Allowed feeds ensures that your security policy performs as intended.
  • Ensure that you understand the ramification of overriding the default action for any threat feeds and Threat Insight rules before doing so.

The recommended rule actions are for reference only. They represent the results of lab testing in a controlled environment focused on individual protocol services. Enabling additional protocols, services, cache hit ratio for recursive DNS, and customer environment variables will affect performance. To design and size a solution for a production environment, please contact your Infoblox Solution Architect.


The following table lists the default actions and precedence for the feeds and Threat Insight in the Default Global Policy available May 2024:

Feed NameDefault ActionDefault Precedence
Default Allow ListAllow - No Log1
Default Bloxk ListBlock  – No Redirect2
Infoblox BaseBlock  – No Redirect3
Infoblox Base IPBlock  – No Redirect4
Infoblox High RiskBlock  – No Redirect5
Threat Insight - Zero Day DNSBlock  – No Redirect6
Infoblox Medium RiskBlock  – No Redirect7
Threat insight - DGAAllow – With Log8
Threat Insight-Data ExfiltrationAllow – With Log9
Threat Insight-DNS MessengerAllow – With Log10
Infoblox Low RiskAllow – With Log11
Infoblox InformationalAllow – With Log12
Threat insight - Notional Data ExfiltrationAllow – With Log13


The following table lists the default actions and precedence for the feeds and Threat Insight in the Default Global Policy (to be supported until December 2024 and deprecated after December 2024):

Feed NameDefault ActionDefault Precedence
Base HostnamesBlock  – No Redirect1
AntiMalwareBlock  – No Redirect2
Malware_DGA HostnamesBlock  – No Redirect3
RansomwareBlock  – No Redirect4
Public_DOHBlock  – No Redirect5
Public_DOH_IPBlock  – No Redirect6
DomainAllow – With Log7
Threat Insight-Data ExfiltrationAllow – With Log8
Threat Insight - Notional Data Exfiltration Allow – With Log9
Threat Insight-DNS MessengerAllow – With Log10
AntiMalware_IPAllow – With Log11
Ext_Base_AntiMalwarAllow – With Log12
Ext_RansomwareAllow – With Log13
Ext_AntiMalware_IPAllow – With Log14
DHS_AIS_DomainAllow – With Log15
CryptoCurrencyAllow – With Log16
TOR_Exit_Node_IPAllow – With Log17

For information on adding and removing feeds from a security policy, see the following: 

Related content