Blocking public DoH servers with BloxOne
This section of the guide covers how to block public DoH servers with BloxOne. Blocking Public DoH Server requires the use the BloxOne DoH feeds with an existing BloxOne security policy, or with new one, and a BloxOne source that is assigned to that BloxOne Security Policy.
License and Configuration Requirements
To block public DoH servers with BloxOne, you will need the BloxOne Threat Defense Essentials license, or higher.
Create a new Security Policy to block public DoH servers
In order to block public DoH Servers with BloxOne, a security policy with the correct feeds applied is required. This section covers how to create a new security policy and apply the appropriate feeds to it.
If an existing security policy will be used to block public DoH servers, refer to the Use an existing Security Policy to block public DoH servers section.
Navigate to Policies → Security Policies.
Click Create Security Policy.
Give the new security policy a Name.
(Optional) Give the new security policy a Description.
Click Next.
Click Add Source. Then, select the source(s) that this policy will apply to. Repeat this step to add multiple sources.
Click Next.
Click Add Rule. Then, select Feeds and Threat Insight.
Click the Object drop-down, then select Public_DoH near the bottom of the list.
Click Select to confirm the selection of the feed.
Click the Action drop-down. Then, select the action that will be taken whenever this rule is triggered. For more information on the the actions associated with security policy rules please view the Infoblox documentation here.
Click Add Rule. Then, select Feeds and Threat Insight.
Click the Object drop-down, then select Public_DoH_IP near the bottom of the list.
Click Select to confirm the selection of the feed.
Click the Action drop-down. Then, select the action that will be taken whenever this rule is triggered.
Click Finish.
Click Save & Close to confirm the creation of the new security policy
Use an existing Security Policy to block public DoH servers
In order to block public DoH Servers with BloxOne, a security policy with the correct feeds applied is required. This section covers how to apply the appropriate feeds to an existing security policy.
Navigate to Policies → Security Policies.
Click the hamburger icon associated with the security policy that the DoH feeds will be applied to. Then, click Edit.
Click Policy Rules on the left side of the panel.
Click Add Rule. Then, select Feeds and Threat Insight.
Click the Object drop-down, then select Public_DoH near the bottom of the list. Note, if this feed is not visible it may already be selected and applied to the security policy that is currently being edited.
Click Select to confirm the selection of the feed.
Click the Action drop-down. Then, select the action that will be taken whenever this rule is triggered. For more information on the the actions associated with security policy rules please view the Infoblox documentation here.
Click the Object drop-down, then select Public_DoH_IP near the bottom of the list. Note, if this feed is not visible it may already be selected and applied to the security policy that is currently being edited.
Click Select to confirm the selection of the feed.
Click the Action drop-down. Then, select the action that will be taken whenever this rule is triggered.
Click Finish.
Click Save & Close to confirm the addition of the feeds to the security policy.