09-08-2017 07:28 AM - edited 09-08-2017 08:53 AM
Infoblox now has a new way to combine RPZ feeds with local RPZ and ADP. This takes an RPZ feed that gets queries and creates a local RPZ entry that, when hit a custom number of times, will create a custom ADP rule to block any new bad queries. The video shows how to set everything up and how it works so that you can start using it.
All the templates that you need are attached in a links below. You may want to rework the templates however the templates below are the ones that are demoed in the video.
The templates require two Extensible Attributes, explained in the video and you will need to generate them in order for the templates to work.
The number of times an entry was hit within an established amount of time, designated by the instance variable “TimeForHits” which is explained in the video. This Extensible Attribute must be a type integer.
This is the last time a variable was hit within a given period of time. This Extensible Attribute must be a type string.
More information is still to come however this should get you started and working.
If you have any questions or suggestions please let me know!
10-10-2018 10:25 PM
For the ADP we need threat rules to download from Threat Insight , and for that we need license .Do we get any portal access or these rules will be downloaded automatically.
Also Do we need seprate ADP license?
ADP will work only on the physical appliance ?
what about the query it will be served first by cahce >>rpz feed >> ADP rule.Can you share the packet inspection detail and sequence.