Set Up Infoblox for Outbound API Integration
Focus
Focus
Device Security

Set Up Infoblox for Outbound API Integration

Table of Contents

Set Up Infoblox for Outbound API Integration

Configure Infoblox Grid Manager to push Network Change IPv4 events to Device Security in real time using the Outbound API.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
  • (Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
  • Device Security subscription
  • Precision AI bundle subscription
  • Device Security X subscription
One of the following Cortex XSOAR setups:
  • A free, cohosted, limited-featured Cortex XSOAR instance
    AND
    A free Cortex XSOAR Engine (on-premises integration)
  • A full-featured Cortex XSOAR server
You need the Infoblox Ecosystem to use the Infoblox Outbound API integration with Device Security. You need to configure the Infoblox API through Infoblox Ecosystem for the API to send information to Device Security.
To enable real-time network change notifications from Infoblox to Device Security, configure three components in the Infoblox Grid Manager:
  • A REST Event Template that defines the event payload
  • An Outbound Endpoint that specifies where to send events
  • A Notification Rule that triggers the endpoint when a Network Change IPv4 event occurs
Before you begin, ensure that your Infoblox environment allows outbound HTTPS traffic from the Grid Master to your Cortex XSOAR server URL. If your network enforces outbound firewall rules, add an allow rule for the Cortex XSOAR endpoint URL before proceeding.
This integration supports Network Change IPv4 Create and Modify operations only. For DHCP lease events, use your firewall log sources instead of the Outbound API.
  1. Create a REST Event Template.
    The REST Event Template defines the JSON payload that Infoblox sends to Device Security when a Network Change IPv4 event occurs.
    1. Select GridEcosystemTemplates, and then click Add Template.
    2. In the Add Template dialog, use the file picker to upload the REST Event Template JSON file below.
      Before uploading, open the JSON file and replace YOUR_DEVICE_SECURITY_API_KEY in the Authorization field with your Device Security API key.
      The siteOverwrite and dataOverwrite values default to true, which causes Infoblox site and non-site data to overwrite existing Device Security data for matching networks. Change either value to false if you do not want Infoblox data to overwrite existing Device Security data.
      { "name": "Device Security Webhook Network Change IPv4", "vendor_identifier": "Palo Alto Networks", "version": "6.0", "type": "REST_EVENT", "content_type": "application/json", "quoting": "JSON", "action_type": "Device Security Webhook", "event_type": [ "NETWORK_IPV4" ], "steps": [ { "name": "send_to_device_security", "operation": "POST", "override_headers": true, "headers": { "Content-Type": "application/json", "Authorization": "YOUR_DEVICE_SECURITY_API_KEY" }, "body_list": [ "{", "\"type\":\"network_change_ipv4_event\",", "\"event_type\":\"${E:A:event_type}\",", "\"operation\":\"${E:A:operation_type}\",", "\"timestamp\":\"${E:A:timestamp}\",", "\"network\":\"${E:A:values{network}}\",", "\"network_container\":\"${E:A:values{network_container}}\",", "\"description\":\"${E:A:values{comment}}\",", "\"extattrs\":\"${E:A:values{extattrs}}\",", "\"options\":\"${E:A:values{options}}\",", "\"siteOverwrite\":true,", "\"dataOverwrite\":true,", "\"asset_type\":\"subnet\"", "}" ] } ] }
    3. Click Add, and then close the confirmation prompt.
      Verify that the template appears in the template list.
  2. Configure an Outbound Endpoint.
    The Outbound Endpoint defines the Cortex XSOAR server URL that Infoblox sends events to.
    1. Select GridEcosystemOutbound Endpoint, and then click Add.
    2. Enter the following settings:
      • URI: Enter the URL-encoded Cortex XSOAR server endpoint for Device Security. Replace your-xsoar-server with your Cortex XSOAR server hostname or IP address:
        https://<your-xsoar-server>/instance/execute/PANW%20IoT%203rd%20Party%20Integration%20Instance/infoblox/send-events-to-device-security
        Example: https://xsoar.com/instance/execute/PANW%20IoT%203rd %20Party%20Integration%20Instance/infoblox/send-events-to device-security
      • Name: Enter a name for this outbound endpoint configuration.
      • Vendor Type: Choose None.
      • Server Certificate Validation: Configure as required for your environment. For production deployments, a CA certificate is recommended.
    3. Click Test Connection to check that the configuration is correct.
    4. Click Save & Close.
  3. Create a Notification Rule for Network Change IPv4.
    The Notification Rule defines which network scope Infoblox monitors and which template formats the event payload.
    1. Select GridEcosystemNotifications, and then click Add notification rule.
    2. Enter the following settings in the first panel:
      • Name: Enter a name for this notification rule.
      • Target: Select the Outbound Endpoint that you created in the previous step.
    3. Click Next.
    4. In the Rule panel, set the network scope for the notification. This defines which networks Infoblox monitors for changes.
    5. Click Next.
    6. Optional Configure Event Deduplication.
    7. Click Next.
    8. In the Template panel, click Select Template and choose the REST Event Template that you created.
    9. Click Save & Close.
      The notification rule is now active. When Infoblox detects a Network Change IPv4 Create or Modify event in the configured scope, it sends the event to Device Security through the outbound endpoint.