infoblox_nios:adp
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| infoblox_nios:adp [2023/04/26 19:04] – bstafford | infoblox_nios:adp [2026/02/16 02:58] (current) – bstafford | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== | ====== | ||
| - | Bear in mind that " | + | [[https:// |
| + | |||
| + | [[https:// | ||
| + | |||
| + | [[https:// | ||
| + | |||
| + | [[https:// | ||
| + | |||
| + | To ensure proper performance, | ||
| + | |||
| + | Bear in mind that " | ||
| * DNS | * DNS | ||
| * DHCP | * DHCP | ||
| Line 15: | Line 25: | ||
| When running ADP on the Grid, to download the latest updates, the Grid Master needs to resolve and access '' | When running ADP on the Grid, to download the latest updates, the Grid Master needs to resolve and access '' | ||
| + | ===== Licence===== | ||
| + | * SW_TP = Threat Protection | ||
| + | * TP_SUB = Threat Protection Update | ||
| + | You cannot install TP_SUB without already having SW_TP installed. | ||
| + | |||
| + | You cannot install ADP on a NIOS appliance that has the MS Management license installed. | ||
| + | |||
| + | ===== Enable Accelerated Networking ===== | ||
| + | Accelerated Networking (sometimes called ' | ||
| + | |||
| + | It can be enabled/ | ||
| + | < | ||
| + | Ideally, don't enable on MGMT. Disabling on MGMT means that SSH can happen to MGMT without going through accelerated networking. | ||
| + | |||
| + | Remember, DoH cannot run on MGMT. DoT can run on MGMT if, and only if, accelerated networking is enabled on MGMT. | ||
| + | ===== Enable ADP ===== | ||
| + | Remember, the option to install the ADP licence is not available until the appliance has the correct resources (RAM/CPU) allocated. See the table below for the RAM/CPU that needs to be allocated per model of NIOS appliance. | ||
| + | |||
| + | Remember, installing ADP licence (" | ||
| + | |||
| + | Remember, enabling the ADP service (" | ||
| + | |||
| + | Remember, you cannot enable ADP on a GM or GMC | ||
| + | |||
| + | Remember, the DNS member running ADP must be using the MGMT interface. | ||
| + | |||
| + | Remember, after enabling DoH and/or DoT, you must manually reboot the member. | ||
| + | |||
| + | Remember, the option to enable DoT and enable DoH is only visible if the member has enough memory allocated (Data Management > DNS > Members > Properties > Queries > Advanced) | ||
| + | |||
| + | Remember, to install the ADP licence and the ADP update licence, the NIOS appliance must have the enough CPU/RAM | ||
| + | |||
| + | ^ NIOS Appliance ^ vCPU ^ Memory ^ | ||
| + | | TE-v1415 | 4 | 32GB| | ||
| + | | TE-v1425 | 4 | 32GB| | ||
| + | | TE-v2215 | 16 | 64GB| | ||
| + | | TE-v2225 | 16 | 64GB| | ||
| + | | TE-v4015 | 28 | 128GB| | ||
| + | | TE-v4025 | 28 | 128GB| | ||
| + | | TE-v926 | 8 | 32GB| | ||
| + | | TE-v1516 | 12 | 64GB| | ||
| + | | TE-v1526 | 16 | 64GB| | ||
| + | | TE-v2326 | 20 | 192GB| | ||
| + | | TE-v4126 | 32 | 284GB| | ||
| ===== Test ADP ===== | ===== Test ADP ===== | ||
| Use a CHAOS query to ask for the running version of Bind. That will trigger a reconnaissance rule | Use a CHAOS query to ask for the running version of Bind. That will trigger a reconnaissance rule | ||
| < | < | ||
| < | < | ||
| + | |||
| + | Another example log where we block a specific domain from being resolved. | ||
| + | * Facility: daemon | ||
| + | * Level: ERROR | ||
| + | * Server: threat-protect-log | ||
| + | * Message: CEF: | ||
| + | ===== DoH ===== | ||
| + | To test DoH on Linux Client, [[https:// | ||
infoblox_nios/adp.1682535861.txt.gz · Last modified: by bstafford
