Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 26 Next »

Infoblox Trinzic appliances have the following limitations on the number of threat intelligence entries that can be loaded on to each appliance. These recommended per-appliance limitations help achieve acceptable performance and should not be exceeded. To help you prioritize and select threat feeds in the DNS FW configuration, use the entry counts next to the feed in the NIOS setup, and use the following guidelines:

Threat Intelligence Sizing Limitations for Infoblox Trinzic Appliances

SoftwareRPZ Count in Millions
IB-8151.5
IB-8252
IB-9266
IB-14156
IB-14258
IB-151620
IB-152620
IB-221525
IB-222525
IB-232640
IB-401540
IB-402540
IB-412640

Feed Restrictions

  • Low end models (1.5M/2M) - do not receive any of the three Suspicious feeds (Suspicious, Suspicious Lookalikes, Suspicious NOED) the Newly Observed Emergent Domains feed, or the Farsight Newly Observed Domains NOD feed. 
  • Middle end models (6M/8M) – receive some of the Suspicious feeds (but not all three), the Newly Observed Emergent Domains feed, and the Farsight Newly Observed Domains NOD feed. 
  • High end models (20M/40M) – receive all feeds.


RPZ Feed Sizing (new RPZ feeds) 

FeedRPZFor Maximum of 1.5M RecordsFor Maximum of 2M RecordsFor Maximum of  6M RecordsFor Maximum of  20M / 40M Records
Infobox Base
infoblox-base.rpz.infoblox.local

Infoblox Base IP
infoblox-base-ip.rpz.infoblox.local

Infoblox High Risk
infoblox-high-risk.rpz.infoblox.local


Infoblox Medium Risk
infoblox-med-risk.rpz.infoblox.local



Infoblox Low Risk
infoblox-low-risk.rpz.infoblox.local



Infoblox Infomational
infoblox-informational.rpz.infoblox.local



DoH Public Hostnamespublic-doh.rpz.infoblox.local

DoH Public IPspublic-doh-ip.rpz.infoblox.local

Cryptocurrency hostnames and domains
cryptocurrency.rpz.infoblox.local

DHS_AIS_ Hostname
dhs-ais-domain.rpz.infoblox.local

DHS_AIS_IPdhs-ais-ip.rpz.infoblox.local

Bogonbogon.rpz.infoblox.local

EECN IPseecn-ip.rpz.infoblox.local

US OFAC Sanctions IPssanctions-ip.rpz.infoblox.local

Sanctions Medsanctions-med.rpz.infoblox.local

Sanctions Highsanctions-high.rpz.infoblox.local

TOR Exit Node IPstor-exit-node-ip.rpz.infoblox.local

Farsight Newly Observed Domains (NOD)farsightnod.rpz.infoblox.local


RPZ Feed Sizing (old feeds) 

FeedRPZFor Maximum of 1.5M RecordsFor Maximum of 2M RecordsFor Maximum of  6M RecordsFor Maximum of  8M RecordsFor Maximum of  20M / 40M Records
Base Hostnamesbase.rpz.infoblox.local

AntiMalwareantimalware.rpz.infoblox.local

Malware DGA hostnamesmalware-dga.rpz.infoblox.local

Ransomwareransomware.rpz.infoblox.local

Suspicioussuspicious.rpz.infoblox.localNA

NA

NA

NA

Suspicious Lookalikeslookalikes.rpz.infoblox.localNA

Suspicious NOEDsuspicious-noed.rpz.infoblox.localNANANA

DoH Public Hostnamespublic-doh.rpz.infoblox.local

DoH Public IPspublic-doh-ip.rpz.infoblox.local

Newly Observed Emergent Domainsnoed.rpz.infoblox.localNANA

AntiMalware_IPantimalware-ip.rpz.infoblox.local

DHS_AIS_ Hostnamedhs-ais-domain.rpz.infoblox.local

Extended Base & anti-malware Hostnamesext-base-antimalware.rpz.infoblox.local

Extended Ransomware IPsext-ransomware.rpz.infoblox.local

Extended AntiMalware Ipsext-antimalware-ip.rpz.infoblox.local

Cryptocurrency hostnames and domainscryptocurrency.rpz.infoblox.local

TOR Exit Node IPstor-exit-node-ip.rpz.infoblox.local

Bogonbogon.rpz.infoblox.local

DHS_AIS_IPdhs-ais-ip.rpz.infoblox.local

EECN IPseecn-ip.rpz.infoblox.loca

Spambot IPs DNSBLspambot-dnsbl-ip.rpz.infoblox.local

US OFAC Sanctions IPssanctions-ip.rpz.infoblox.local

Sanctions Medsanctions-med.rpz.infoblox.local

Sanctions Highsanctions-high.rpz.infoblox.local

Farsight Newly Observed Domains (NOD)farsightnod.rpz.infoblox.localNANA

Extreme Blockib-extreme-block.rpz.infoblox.localNANANANA

Extreme Logib-extreme-log.rpz.infoblox.localNANANANA

High Blockib-high-block.rpz.infoblox.localNANANANA

High Logib-high-log.rpz.infoblox.localNANANANA

Med Blockib-med-block.rpz.infoblox.localNANANANA

Med Logib-med-log.rpz.infoblox.localNANANANA

Low Blockib-low-block.rpz.infoblox.localNANANANA

Low Logib-low-log.rpz.infoblox.localNANANANA

Pre-configurated Feed Sets

The pre-configured sets – Extreme/High/Med/Low – are supposed to be used by itself. They are not supposed to be used in any combination with other pre-configured options or the above individual RPZs, as it will result in overlap without additional benefit/protection for customers, resulting in ineffective usage of resources.

In summary,

  • Low end models (1.5M/2M)- do not get Suspicious (none of the three), NOED and Farsight NOD
  • Middle end models (6M/8M) – you get NOED, Farsight NOD and some Suspicious (but not all three)
  • High end models (20M/40M) – you get everything.
  • No labels