Scenario
To extend Threat Defense coverage to roaming users, your organization is planning to enable Infoblox Endpoint protection on client devices such as company-managed laptops, company-managed smartphones, and handheld devices. This secures DNS traffic from mobile and remote endpoints outside the corporate network. You are tasked to deploy the Infoblox Endpoint agent on a single Windows machine for testing, create a new Endpoint Group, and add the deployed endpoint to this group. The Endpoint Group will later be added to a security policy for testing and validation.
Estimated Completion Time
-
20 to 30 mins
Prerequisites
-
Administrative access to the Infoblox Portal
Tasks
-
Install the Infoblox Endpoint agent on a Windows VM.
-
Create an Endpoint Group in Infoblox Portal.
-
Add the Windows Endpoint to the Endpoint Group.
Task 1: Installing Infoblox Endpoint
In testing-windows, open the Tools folder on the Desktop and run the interface-static-internet.bat file as an administrator. This sets a static IP address for the VM. Please re-enter the command if the VM does not get an IP address the first time.
Use your lab’s testing-windows VM to launch a web browser. Use your Education Infoblox Portal Credentials to log into the Infoblox Portal. Download and install the correct Endpoint version for your Windows machine, verify that the Endpoint was added.
Task 2: Creating an Endpoint Group
In the Infoblox Portal, create an endpoint group named Techblue Endpoints.
Task 3: Adding the Windows endpoint to Techblue-Endpoints
In the Infoblox Portal, add the testing-windows Endpoint into the Techblue Endpoints Endpoint Group.
Solutions
Task 1 Solution: Installing Infoblox Endpoint
Extract all files in the same folder, or the installation process will fail. The included files contain the information required to connect the endpoint agent to your Infoblox Threat Defense tenant, such as the Join Token; without them, the installation cannot succeed.
In this task, we will download the Windows installation package for the Infoblox Endpoint client from the Infoblox Portal, extract it, and install it on one of our lab’s virtual machines, testing-windows. We are logging in to the Infoblox Portal from the testing-windows VM as it is the easiest method to download the zip file on the VM. In a production deployment we can rely on some domain orchestration tool such as Microsoft Endpoint Configuration Manager or PDQ Deploy to mass deploy the agent.
-
Log into your lab’s testing-windows, with the credentials (training / infoblox).
-
Open the Tools folder on the Desktop and run the interface-static-internet.bat as an administrator.
-
This file is used to set an IP address for the VM in a subnet simulating a direct internet connection.
-
-
In testing-windows, open a browser and use your Education Infoblox Portal Credentials to log into the Infoblox Portal.
-
Navigate to System → Downloads → Threat Defense → Endpoint.
-
Expand the Endpoint client drop-down list using the arrow on the right-hand side.
-
Download the correct Endpoint version for your Windows machine.
-
Extract the zip components into one folder using 7-Zip.
-
Right-click the zip file and choose 7-Zip → Extract Here.
-
Install Infoblox Endpoint Agent using the .msi executable.
-
In the Infoblox Portal, navigate to Security → Threat Defense → Endpoints.
-
Verify that the Endpoint was added.
Task 2 Solution: Creating an Endpoint Group
In this task, we will create a new Endpoint Group named Techblue Endpoints, to use later as a Security Policy Network Scope. We must add our endpoint to an Endpoint Group because single endpoints cannot serve as network scopes.
By default, all endpoints will be added a system default Endpoint Group named Default Endpoint Group. We will be not using it and will create our organization’s own Endpoint Group.
-
In the Infoblox Portal, navigate to Security → Threat Defense → Endpoints → Endpoint Groups.
-
Click Vertical Ellipsis (⋮) icon.
-
Choose Create from the drop down list.
-
Under the Overview tab:
-
Give the new Endpoint Group the name Techblue Endpoints.
-
Optionally, give the group a description.
-
Ensure the Endpoint Group Sate is Enable Endpoints (default)
-
Log level is set to INFO (default): this sets the individual log level for each endpoint in the group. Setting it to INFO means that every endpoint will log events at the INFO level and above.
-
The Remove after inacitivty (days) option should be set to 100 (default): this set the number of consective inactive days an individual endpoint needs to have before automatically getting removed from the group. Setting it to 0, disabled the option.
-
-
Under Authentication Settings, we will leave all settings as default.
-
Authentication Settings attach an authentication profile, which uses SAML or OpenID Connect with a third-party IdP. With that profile in place, endpoint users have to sign in through SSO, and they then get the security policy assigned to their synced IdP user group. By default this feature is disabled.
-
-
Under Schedule Updates, we will leave all settings as default.
-
This tab enables us configure how endpoint upgrades are managed. we can choose to install updates automatically when they become available (default), schedule upgrades for a specific date and time, or defer upgrades for up to 28 days.
-
-
Under Network Settings:
-
Ensure the IP Address field is empty; this field can be used to change the default loopback address every endpoint in the group will use, the default IP address is 127.0.0.1 for non MAC devices and 127.0.0.2 for MAC devices. This IP address can be changed to any loopback address, if needed.
-
Ensure Auto Selection under POP Settings is set to ON. When enabled, endpoints connect to the healthiest Threat Defense Point-of-Presence (POP). When disabled, admins can manually select the desired POP.
-
Under the Internal DNS Resolvers section (this section allows admins to configure endpoint groups with internal namer reslovers for internal domain lists):
-
Click Add.
-
Select Default Detection Bypass Domains, from the Domain Lists drop down list.
-
Enter 10.100.0100, for the FQDN/IP Address field.
-
Click Add.
-
-
Under the Fallback DNS Resolvers section (this section allows admins to set a fallback DNS server, when the connection between Endpoints in the group and Threat Defense is disrupted):
-
Click Add.
-
Enter 10.100.0100, for the FQDN/IP Address field.
-
Toggle the status to Enabled.
-
Leave the Encrypted DNS toggle to its default Prefer Encryption state. Prefer Encryption allows endpoints to establish an encrypted TLS tunnel with the configured fallback server when feasible. If the encrypted tunnel cannot be established, endpoints can still connect to the server without encryption. When set to Enforce Encryption, the endpoint will connect to the server only if the encrypted tunnel can be established.
-
-
-
Click Save.
Task 3 Solution: Adding the Windows endpoint to Techblue-Endpoints
In this task, we will move our endpoint, which we installed earlier on the testing-windows VM, from the Default Endpoint Group to Techblue Endpoints. We are moving the endpoint because we will use the newly created Endpoint Group, Techblue Endpoint, as a Network Scope for our organization’s security policy.
-
In the Infoblox Portal, navigate back to Security → Threat Defense → Endpoints.
-
Select the testing-windows endpoint, and click Move.
-
Select Techblue Endpoint Group and click Save.