Collect DNS Queries with Lumu Gateways and Infoblox

Collect DNS Queries with Lumu Gateways and Infoblox

In the scenario where your company uses Infoblox as a DNS server, you have the option to associate the traffic originating from your organization using Lumu's public IP addresses as DNS resolvers while illuminating threats, attacks, and adversaries coming from your network.

In this guide, we show how to configure Infoblox version 8.4+ for forwarding DNS queries to Lumu using a Gateway collector.

For configuring Infoblox with Lumu Virtual Appliance, consult Collect DNS queries with Lumu VA and Infoblox.

Requirements

  1. Infoblox NIOS version 8.4+.

Add a Public Gateway in the Lumu Portal

Remember to first register your public IP address or group of IPs as a Gateway for your company at the Lumu Portal before pointing your DNS to Lumu. 

Configuring DNS forwarders on Infoblox

1. From the main navigation menu, click Data Management and then select the DNS tab. In a Grid view, select the zone you want to configure and expand the toolbar on the right side of the application and click Grid DNS Properties.

2. Click the Forwarders tab, and in the panel that appears, click to add.

Infoblox Grid DNS PropertiesInfoblox Grid DNS Properties
 

3. Enter the Lumu DNS resolvers IPs or the Lumu Virtual Appliance IPs.

Adding forwarders in InfobloxAdding forwarders in Infoblox
Remember that the Lumu DNS resolvers IPv4 addresses are: 
50.17.0.10 
3.87.85.24

4. Click Save & Close to save the configuration, and click Restart if it appears at the top of the screen.