infoblox_threat_defense:geolocation
Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| infoblox_threat_defense:geolocation [2024/12/27 15:10] – created bstafford | infoblox_threat_defense:geolocation [2026/02/25 09:47] (current) – bstafford | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== | + | ====== |
| - | Geolocation | + | =====Geolocation |
| Service providers such as Google, Infoblox, etc, will only forward ECS data to an authoratative DNS server if that domain being queried is in the list of ECS zones. | Service providers such as Google, Infoblox, etc, will only forward ECS data to an authoratative DNS server if that domain being queried is in the list of ECS zones. | ||
| - | * For Infoblox, this list is mostly services Google, YouTube, SalesForce, Netskope, etc. MIcroosft | + | * For Infoblox, this list is mostly services Google, YouTube, SalesForce, Netskope, etc. |
| + | * Microsoft | ||
| * Infoblox forwards the /24 when forwarding ECS data. | * Infoblox forwards the /24 when forwarding ECS data. | ||
| - | * When using an BloxOne | + | * When using an Infoblox |
| * When using an External Network, the public IP is the External Network being used. | * When using an External Network, the public IP is the External Network being used. | ||
| - | * When using a DFP, the public IP used is the public IP that BloxOne | + | |
| + | | ||
| + | |||
| + | You can check what IP the service sees by testing against Google. | ||
| + | < | ||
| Geolocation support uses the EDNS0 ECS (ENDS client subnet) option to pass the public /24 subnet of your IP address to a third-party DNS server. This allows ECS enabled third-party DNS servers to provide appropriate answers based on the geolocation of the source user and direct users to the closest instance of the DNS record being queried. | Geolocation support uses the EDNS0 ECS (ENDS client subnet) option to pass the public /24 subnet of your IP address to a third-party DNS server. This allows ECS enabled third-party DNS servers to provide appropriate answers based on the geolocation of the source user and direct users to the closest instance of the DNS record being queried. | ||
| - | BloxOne | + | Infoblox |
| Note: | Note: | ||
| - | Infoblox maintains a list of domains that support geolocation-based responses. | + | Infoblox maintains a list of domains that support geolocation-based responses. |
| Line 24: | Line 29: | ||
| There is a performance impact on the cache layer due to the overload of the domains in the ECS list. End users shouldn’t really care/know about that. | There is a performance impact on the cache layer due to the overload of the domains in the ECS list. End users shouldn’t really care/know about that. | ||
| + | |||
| + | ===== NIOS-XaaS ===== | ||
| + | When using NIOS-XaaS, if you have DNS and DFP and enable Geolocation, | ||
| + | |||
| + | This is because when you query the XaaS DNS server, it then forwards to the Threat Defense POP. | ||
| ===== Testing ===== | ===== Testing ===== | ||
| + | * google.com | ||
| * 3dzip.org | * 3dzip.org | ||
| - | * www.youtube.com | + | * youtube.com |
| * outlook.office365.com | * outlook.office365.com | ||
| * infoblox.lightning.force.com | * infoblox.lightning.force.com | ||
| * outlook.office365.com | * outlook.office365.com | ||
| - | < | + | To show Google sees EDNS0 data, run the following: |
| + | |||
| + | < | ||
| + | Results | ||
| + | < | ||
| + | " | ||
| + | " | ||
| + | The run again via Infoblox Threat Defense. If Threat Defense has Geolocation enabled, you should get your public subnet in the response. | ||
| + | < | ||
| + | Results | ||
| + | < | ||
| + | " | ||
| + | " | ||
| + | In the example above, | ||
| + | |||
| + | However, if you disable geo-location but then add subnet data to your query (e.g. +subnet=10.10.10.0/ | ||
| + | |||
| + | If geolocation is enabled and you use +subnet, then you value is copied and Threat Defense will not add your actual public IP. | ||
infoblox_threat_defense/geolocation.1735312254.txt.gz · Last modified: by bstafford
