Infoblox’s global team of threat hunters uncovers a DNS operation with the ability to bypass traditional security measures and control the Great Firewall of China. Read about “Muddling Meerkat” and the many other threat actors discovered by Infoblox Threat Intel here.

BloxOne Threat Defense and Threat Intelligence

Reply

For RPZ policy actions, are there real life use examples for each?

Authority
Posts: 18
1542     0

Hi;

 

For Block (NXDOMAIN), Block (NODATA) and Substitute (DOMAIN), where would you use each action and why?

 

Kindly

Wasfi

Re: For RPZ policy actions, are there real life use examples for each?

Superuser
Posts: 105
1542     0

Hi,

 

In my opinion this is totally options and how you want to override the response.

 

in my use case any rpz rules hits will redirect to a landing page which contain information about why this domain is blocked but this is mostly for domain that usually access by user - category filter (like adult domain, gambling domain, phishing etc)

 

but for domain that categorized as malware or ransomware i will choose to use nxdomain or nodata because the domain is not intentionally query or access by the user, but mostly queried by malware in the background so we dont need redirect to landing page.

 

 

Showing results for 
Search instead for 
Did you mean: 

Recommended for You