You can use the Threat Insight Cloud Client object to configure the detection and authentication of domains in the Cloud, and then apply them to on-premises DNS firewall RPZ zones within a configurable time frame.
References to threatinsight:cloudclient are object references.
The name part of the threatinsight:cloudclient object reference has the following components:
- The ‘cloudclient’ string
The object does not support the following operations:
The object cannot be managed on Cloud Platform members.
These fields are actual members of the object; thus, they can be requested by using _return_fields, if the fields are readable.
The basic version of the object contains the field(s): enable, interval.
The RPZs to which you apply newly detected domains through the Infoblox Threat Insight Cloud Client.
Type
A/An zone_rp object array.
This field supports nested return fields as described here.
Create
The default value is empty.
Search
The field is not available for search.
Determines whether the Threat Insight in Cloud Client is enabled.
Type
Bool.
Create
The default value is False.
Search
The field is not available for search.
Notes
The enable is part of the base object.
Force a refresh if at least one RPZ is configured.
Type
Bool.
Create
The default value is undefined.
Search
The field is not available for search.
Notes
force_refresh is not readable.
The time interval (in seconds) for requesting newly detected domains by the Infoblox Threat Insight Cloud Client and applying them to the list of configured RPZs.
Type
Unsigned integer.
Create
The default value is 600.
Search
The field is not available for search.
Notes
The interval is part of the base object.
Field | Type | Req | R/O | Base | Search |
---|---|---|---|---|---|
blacklist_rpz_list | [obj] | N | N | N | N/A |
enable | Bool | N | N | Y | N/A |
force_refresh | Bool | N | N | N | N/A |
interval | Unsigned int | N | N | Y | N/A |