Integrate Device Security with Infoblox IPAM
Integrate Device Security through Cortex XSOAR with Infoblox to import and
maintain IPAM data in real time or on a schedule.
| Where Can I Use This? | What Do I Need? |
|
|
One of the following subscriptions:
Device Security subscription
Precision AI bundle subscription
Device Security X subscription
One of the following Cortex XSOAR setups:
A free, cohosted, limited-featured
Cortex XSOAR instance
AND
A free Cortex XSOAR Engine (on-premises integration)
A full-featured Cortex XSOAR server
|
Infoblox Internet Protocol Address Management (IPAM) provides a means for managing
the IP address space of a network. When you integrate Device Security through
Cortex XSOAR with Infoblox IPAM, you can import all the IP address blocks and
subnets (called containers and networks in Infoblox) into
Device Security and then display them on the Networks page.
You can also specify subnet scopes to limit the IP CIDR blocks and subnets retrieved
from Infoblox.
Device Security supports two methods of integrating with Infoblox:
A direct integration, which is useful for bulk ingestion of data and for
configuring a recurring schedule for the integration jobs.
An integration with the Infoblox Outbound API, which is useful for real-time
synchronization between Infoblox networks and Device Security networks.
The two integration modes are complementary. Use the bulk read integration for the
initial synchronization and as a safety net; enable the Outbound API for near
real-time updates.
Through integration with Infoblox, Device Security can learn the following types
of information about the IP address blocks and subnets on the network:
- Prefix (for example, 10.1.0.0/16)
- Type: Block or
Subnet
- Description (if configured on Infoblox)
- Site (if configured on Infoblox)
- VLAN (subnets only)
Direct Integration
The direct integration uses the Cortex XSOAR Infoblox IPAM integration
instance and a scheduled job to pull all network containers, networks, and extended
attributes, such as Prefix, Type, Description, Site, and VLAN, from the
Infoblox Grid Master on a recurring schedule. This mode is required for the initial
synchronization and provides a full inventory refresh each time the job runs. Even
when you enable the Outbound API, Palo Alto Networks recommends keeping a scheduled
bulk read job as a periodic safety net to reconcile any events that may have been
missed.
Outbound API Integration
The Outbound API integration enables real-time event push from Infoblox to
Device Security. When Infoblox creates or modifies an IPv4 network object, it
sends the change immediately to Device Security through a long-running
Cortex XSOAR webhook listener. This eliminates the delay between a
network change and its appearance in Device Security.
The Outbound API integration supports Network Change IPv4 Create and Modify
operations. For DHCP lease events, use your firewall log sources instead of the
Outbound API.
You still need to set up a
Cortex XSOAR integration instance when you
configure the API integration,
as the
Cortex XSOAR integration instance acts as the webhook listener.