Integrate Device Security with Infoblox IPAM
Focus
Focus
Device Security

Integrate Device Security with Infoblox IPAM

Table of Contents

Integrate Device Security with Infoblox IPAM

Integrate Device Security through Cortex XSOAR with Infoblox to import and maintain IPAM data in real time or on a schedule.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
  • (Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
  • Device Security subscription
  • Precision AI bundle subscription
  • Device Security X subscription
One of the following Cortex XSOAR setups:
  • A free, cohosted, limited-featured Cortex XSOAR instance
    AND
    A free Cortex XSOAR Engine (on-premises integration)
  • A full-featured Cortex XSOAR server
Infoblox Internet Protocol Address Management (IPAM) provides a means for managing the IP address space of a network. When you integrate Device Security through Cortex XSOAR with Infoblox IPAM, you can import all the IP address blocks and subnets (called containers and networks in Infoblox) into Device Security and then display them on the Networks page. You can also specify subnet scopes to limit the IP CIDR blocks and subnets retrieved from Infoblox.
Device Security supports two methods of integrating with Infoblox:
  • A direct integration, which is useful for bulk ingestion of data and for configuring a recurring schedule for the integration jobs.
  • An integration with the Infoblox Outbound API, which is useful for real-time synchronization between Infoblox networks and Device Security networks.
The two integration modes are complementary. Use the bulk read integration for the initial synchronization and as a safety net; enable the Outbound API for near real-time updates.
Through integration with Infoblox, Device Security can learn the following types of information about the IP address blocks and subnets on the network:
  • Prefix (for example, 10.1.0.0/16)
  • Type: Block or Subnet
  • Description (if configured on Infoblox)
  • Site (if configured on Infoblox)
  • VLAN (subnets only)
For a full list of attributes that Device Security can learn through the integration, see Infoblox Attribute Reference.
Integrating with Infoblox requires either a full-featured Cortex XSOAR™ server or the activation of a Device Security free cohosted Cortex XSOAR instance.

Direct Integration

The direct integration uses the Cortex XSOAR Infoblox IPAM integration instance and a scheduled job to pull all network containers, networks, and extended attributes, such as Prefix, Type, Description, Site, and VLAN, from the Infoblox Grid Master on a recurring schedule. This mode is required for the initial synchronization and provides a full inventory refresh each time the job runs. Even when you enable the Outbound API, Palo Alto Networks recommends keeping a scheduled bulk read job as a periodic safety net to reconcile any events that may have been missed.
When you configure the direct integration, you can enter the subnet scope to limit the IP CIDR blocks and subnets retrieved from Infoblox.

Outbound API Integration

The Outbound API integration enables real-time event push from Infoblox to Device Security. When Infoblox creates or modifies an IPv4 network object, it sends the change immediately to Device Security through a long-running Cortex XSOAR webhook listener. This eliminates the delay between a network change and its appearance in Device Security.
The Outbound API integration supports Network Change IPv4 Create and Modify operations. For DHCP lease events, use your firewall log sources instead of the Outbound API.
You still need to set up a Cortex XSOAR integration instance when you configure the API integration, as the Cortex XSOAR integration instance acts as the webhook listener.