infoblox:licencing
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| infoblox:licencing [2023/01/24 11:56] – bstafford | infoblox:licencing [2024/12/27 15:33] (current) – bstafford | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Infoblox Licencing ====== | ====== Infoblox Licencing ====== | ||
| - | =====BloxOne | + | ===== Infoblox Tokens ===== |
| - | [[https:// | + | |
| + | [[https:// | ||
| + | |||
| + | ==== Reporting Tokens ==== | ||
| + | Reporting tokens are only needed for | ||
| + | * DDI DHCP Lease Log | ||
| + | * DDI Query/ | ||
| + | |||
| + | The following logs are available even if no reporting tokens have been purchased. A data connector VM can be deployed and used to get the logs off the Infoblox Portal (without requiring Server Tokens) | ||
| + | * Audit Log | ||
| + | * Internal Notifications | ||
| + | * Service Log | ||
| + | |||
| + | The following logs are available only to customers of the Infoblox Threat Defense Advanced and Infoblox Threat Defense Business Cloud subscriptions. They do not require reporting tokens as this is covered by the Threat Defense subscription. | ||
| + | * Threat Defense Query/ | ||
| + | * Threat Defense Threat Feeds Hits Logs | ||
| + | |||
| + | |||
| + | ===== Universal | ||
| + | [[https:// | ||
| =====BloxOne Threat Defense ===== | =====BloxOne Threat Defense ===== | ||
| [[https:// | [[https:// | ||
| Line 15: | Line 34: | ||
| * Threat Lookup to research basic attacker data (Dossier is not included in BloxOne Threat Defense Essentials) | * Threat Lookup to research basic attacker data (Dossier is not included in BloxOne Threat Defense Essentials) | ||
| * Predefined Reports (Infoblox reporting appliance is required if On-Prem) | * Predefined Reports (Infoblox reporting appliance is required if On-Prem) | ||
| + | * [[infoblox: | ||
| Line 23: | Line 43: | ||
| * (**Cloud Only**) Web Content Filtering | * (**Cloud Only**) Web Content Filtering | ||
| * Access to the Active indicators tool | * Access to the Active indicators tool | ||
| + | * [[infoblox: | ||
| Line 29: | Line 50: | ||
| * Access to Application Discovery tool | * Access to Application Discovery tool | ||
| * Application filtering | * Application filtering | ||
| + | * [[infoblox: | ||
| - | ===== BloxOne | + | ===== BloxOne |
| - | [[https:// | + | BloxOne DDI data is [[https:// |
| - | Remember, always put the FQDN only feeds above the IP only feeds to improve performance. | + | BloxOne Threat Defence data is [[https:// |
| - | ====Essentials==== | + | |
| - | * Base (FQDN) | + | |
| - | * AntiMalware (FQDN) | + | |
| - | * Ransomware (?) | + | |
| - | * Bogon (IP) | + | |
| - | * DHS AIS_IP (IP) | + | |
| - | * DHS AIS_Hostname (FQDN) | + | |
| - | * DHS AIS NCCIC Watch list Hostnames | + | |
| - | * DHS AIS NCCIC Watch list IPs (IP) | + | |
| - | * Public_DoH (FQDN) | + | |
| - | * Public_DoH_IP (IP) | + | |
| - | ==== Business==== | + | ===== Universal DDI ===== |
| - | Essentials Feeds + | + | |
| - | * Anti-malware IPs (IP) | + | |
| - | * Bot IPs, Exploit kit IPs (IP) | + | |
| - | * Malware DGA hostnames (FQDN) | + | |
| - | * Tor Exit Node IPs (IP) | + | |
| - | * SURBL Multi domains (FQDN) | + | |
| - | * SURBL Multi Lite domains (FQDN) | + | |
| - | * SURBL Fresh domains (FQDN) | + | |
| - | * US OFAC Sanctions IPs (IP) | + | |
| - | * EECN IPs (IP) | + | |
| - | * Cryptocurrency hostnames and domains (FQDN) | + | |
| - | ====Advanced==== | + | NIOS-X QPS calculation: |
| - | Essentials Feeds + Business Feeds + | + | ===== BloxOne Threat Defense License Caveat ===== |
| - | * Extended base & anti-malware | + | From [[https:// |
| - | * Extended malware IPs (IP) | + | |
| - | * Extended TOR Exit Node IPs (IP) | + | |
| - | * Extended ransomware IPs (IP) | + | //BloxOne Threat Defense |
| - | * Extended exploit kit IPs (IP) | + | |
| - | * Spambot IPs (IP) | + | Remember. B1TD Advanced is licensed based on employee count. Why? Because it is simple and it works for the most part. However, the caveat above is in place to protect Infoblox from a 100 employee company protection 10,000 busy servers, etc. |
| - | * Spambot IPs DNSBL (FQDN) | + | |
| - | * Suspicious Domains | + | |
| - | * Suspicious Emergent | + | ===== Sandbox Restriction ===== |
| - | * Suspicious Lookalikes | + | From [[https:// |
| + | |||
| + | //" | ||
| + | |||
| + | ===== Other ===== | ||
| + | NIOS Grid Connector Notes: | ||
| + | * NIOS Grid connector requires NIOS 8.5 and can only export data to BloxOne. The exported data in BloxOne will be read only in BloxOne. | ||
| + | * The NIOS Grid Connector service does not support the importing of DHCP lease data from NIOS Grid. | ||
| + | * NIOS Grid connector requires that the appliance be TE-14xx or higher. | ||
| + | * Only IPv4 objects are imported it seems. See [[https:// | ||
| + | * Data managed by NIOS and synced to BloxOne via NIOS Grid Connector | ||
| + | |||
| + | **Active | ||
| + | * A Fixed (Static) Address - Just IP or does it have to include a MAC address? | ||
| + | * IP Address found in DHCP leases | ||
| + | * Source | ||
| + | **Instance** | ||
| + | * A single online Host running DHCP and/or DNS services | ||
| + | * A pair of hosts configured in co-located DHCP HA groups [A/A or A/P]) - Note, if the pair of hosts configured in a co-located DHCP HA group also run DNS, they are counted as two hosts. Advanced A/P members are counted separately | ||
| + | |||
| + | ===== External Licences ===== | ||
| + | External " | ||
| + | |||
| + | * ProofPoint - Emerging Threats | ||
| + | * Mandiant - APIv4 | ||
| + | * Virus Total | ||
| + | |||
| + | (IF YOU HAVE B1TD ADVANCED) You can also purchase (from Infoblox) licences to allow access to RPZ threat feeds from other sources (these feeds are then accessible via the BloxOne portal along with all the other Infoblox RPZ feeds. | ||
| + | * FarSight - Security Newly Observed | ||
| + | * Proofpoint - Emerging Threats | ||
| + | |||
| + | Note that the following sources of Threat Intelligence and/or Threat Intelligence feeds are no longer supported. | ||
| + | * CrowdStrike | ||
| + | * FireEye - iSight Threat Intelligence | ||
| + | * ThreatTrack - Security BorderPatrol | ||
infoblox/licencing.1674561414.txt.gz · Last modified: by bstafford
