---
title: "Universal DDI Licensing"
canonical: "https://docs.infoblox.com/space/BloxOneDDI/846954761/Universal%20DDI%20Licensing"
format: markdown
---
Infoblox tailors the Universal DDI Management offerings to suit your specific network architecture and deployment needs, recognizing that different scenarios require distinct solutions. The versatile suite of Universal DDI Management includes Universal DNS Management, Universal DHCP Management, Universal IP Address Management, and Universal Asset Insights.

Before taking advantage of the Universal DDI functionality, ensure that you obtain the necessary tokens from Infoblox. For pricing details and how to calculate token allocations, please contact your Infoblox representative.

> 📝 - The **Monitor** and **Configure** lifecycle navigation of the Infoblox Portal displays features that are accessible through product upgrades. The Infoblox Portal greys out these features based on your Universal DDI token packages, allowing you to decide whether purchasing applicable token packages is suitable for your organizational needs and requirements. For information, see *[Managing the Monitoring Lifecycle](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/827555975)* and *[Managing the Configuring Lifecycle](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/827556029)*.
> 📝 - For information on NIOS-X system requirements and performance data, please see *[Minimum System Requirements for NIOS-X Servers](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneInfrastructure/pages/873758806)*.

# Management Tokens

Management tokens are mandatory for managing the following object types.

> 📝 You must allocate at least one management token pack for Universal DDI to function properly.

- **DDI objects**: These are objects used for managing DNS, DHCP, and IPAM. They include (but are not limited to) DNS Zones/Records, DHCP Ranges, Subnets and DDNS records. The following table includes the list of supported objects:

| **Object Types** | **Supported Objects** |
| --- | --- |
| DNS objects | Views   
Zones  
Applied Access Control Rules (each occurrence of an applied rule)  
DNS Records  
DTC LBDNs  
DTC Servers  
DTC Pools  
DTC Applied Topology Rules (each occurrence of an applied rule)  
DTC Applied Health Checks |
| DHCP objects | Ranges  
Exclusion Ranges  
Applied Filter Rules (each occurrence of an applied rule)  
Applied Options (options that are assigned at any level of the hierarchy)  
DDNS Zones |
| IPAM objects | IP Spaces  
Address Blocks  
Subnets  
Host Records |

- **Active IP addresses**: These are active IP addresses (IPs) being observed in your networking environment and managed by IPAM. Active IPs are de-duplicated based on the IP Spaces with which they are associated. Note that DNS source queries are not counted towards the active IP count. For example, if an IP address is observed via a DHCP lease and is seen sending DNS queries, it will be counted as a single active IP. Active IPs include unique occurrences across the following:
  - IP addresses found in new or renew DHCP leases
  - Discovered IP addresses
  - Reservations (including Network and Broadcast addresses)
  - Fixed Addresses

> 📝 Customers renewing from BloxOne DDI to Universal DDI may notice a decrease in active IP count, as IP addresses found in DNS queries no longer contribute to the active IP count.

- **Managed Assets**: A managed asset that is counted against the management tokens is an identified physical or virtual component on the network that has at least one associated IP address.  Sample asset types with IP addresses include virtual machines, gateways, endpoints, firewalls, switches, routers, and servers.  Asset types without associated IP addresses are also discovered, but they will not be allocated against the management token count.  Sample asset types without IP addresses include security groups, S3 buckets, subnets, and projects.  Assets are de-duplicated to make sure that information from multiple sources is consolidated and only counted as a single asset

> ℹ️ Tokens are only consumed for assets with IP addresses. Certain cloud discovery assets do not consume tokens. For details, see* **[Token-Free Cloud Discovery Assets](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/1501298790)**.*

Each management token is designed to support a specific number of objects. You can purchase management tokens and allocate them based on the objects that are configured and in-use in your network infrastructure. The tokens are designed to be flexible to support different object types. Instead of buying specific objects in specific quantities, you can use the management tokens to support a mix of object types based on your business requirements.

The following table shows the number of objects that can be managed per object type for each management token. Use the information in this table as guidelines to determine the number of tokens you may need to manage your Universal DDI infrastructure.

|  |  |  |
| --- | --- | --- |
| **Object Type** | **Native Objects** | **NIOS Objects** |
| (Managed directly from the Infoblox Portal) | (Managed from the Infoblox Portal, through NIOS ) |
| **# of Objects per Token** | **# of Objects per Token** |
| DDI objects | 25 | 50 |
| Active IP Addresses | 13 | 25 |
| Assets | 3 | 13 |

#### Legends

- **Native Objects**: Objects that are discovered or managed directly from the Infoblox Portal or via NIOS-X virtual servers or NIOS-X as a Service.  If NIOS is not involved in the management or discovery of an object, the object will be classified as a native object.
- **NIOS Objects**: Objects that are discovered or managed from the Infoblox Portal via the NIOS Grid Manager. These objects are counted separately, such as assets discovered by NIOS Network Insight and sent to the Infoblox Portal via NIOS Grid Connector. This is applicable to all object types: DDI objects, active IPs, and managed assets.

# Server Tokens for NIOS-X Virtual Servers

NIOS-X virtual servers, formerly referred to as BloxOne Hosts, are self-hosted, running on customer-provided private cloud, public cloud, or physical servers (either customer-provided or Infoblox physical servers such as B1-105 and B1-212). You may still purchase Infoblox NIOS-X physical servers if your network infrastructure requires some. Please contact your Infoblox representatives for more information.

NIOS-X servers only require server tokens if you run one or more Universal DDI services on them (see the table below). NIOS-X servers are allocated server tokens based on their performance and capacity rather than the amount of CPU/RAM allocated to them. 

The following table describes the supported NIOS-X virtual server form factors, their specifications, and token allocation. 

> 📝 Token usage is determined by actual usage, not by server specification. For example, you can deploy a NIOS-X server with 8 vCPU and 8 GB RAM and configure it as an XS form factor (using 250 tokens). If server usage increases and exceeds the limit of an XS server (e.g., QPS goes from 9k to 12k), the token consumption of that server will automatically change from XS (250 tokens) to S (470 tokens) without the need to add more CPU/RAM.


| **Form Factor** | **Performance ** | **Objects** | **Tokens** |
| --- | --- | --- | --- |
| **Size** | **kQPS** | **LPS** |
| 2XS | 5 | 75 | 3,000 | 130 |
| XS | 10 | 150 | 7,500 | 250 |
| S | 20 | 200 | 29,000 | 470 |
| M | 40 | 300 | 110,000 | 880 |
| L | 70 | 400 | 440,000 | 1900 |
| XL | 115 | 675 | 880,000 | 2700 |

# Server Tokens for NIOS-X as a Service

NIOS-X as a Service (NIOS-XaaS) is Infoblox-hosted and can include DDI services. If you are hosting DDI services, each NIOS-X form factor has guardrails for peak DNS query performance (kQPS), peak DHCP lease performance (LPS), and object count. If a guardrail is exceeded, a higher NIOS-X form factor is required. 

The following table shows the supported NIOS-XaaS form factors, their specifications, and token allocation. 

| **Form Factor** | **Performance ** | **Capacity** | **Allocated Tokens** | **Objects** |
| --- | --- | --- | --- | --- |
| **Size** | **kQPS** | **LPS** | **Connections** |  |  |
| S | 20 | 200 | 10 | 2,400 | 29,000 |
| M | 40 | 300 | 20 | 4,100 | 110,000 |
| L | 70 | 400 | 35 | 6,100 | 440,000 |
| XL | 115 | 675 | 85 | 8,500  
**Note**: You can add up to 400 additional connections, with each connection costing 100 tokens. | 880,000 |

> 📝 NIOS-X as a Service is limited by the number of connections it can support. A connection is an "Access Location" that may use multiple WAN IP addresses and VPN connections. For more information, see *[Configuring NIOS-X as a Service](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/682852382)*.

# NIOS-X Services and Server Tokens

The following table lists the NIOS-X services and their respective token requirements.

| **NIOS-X Services** | **Server Tokens Required (Yes/No)** | **Comments** |
| --- | --- | --- |
| Access Authentication | No | This service is related to Infoblox Threat Defense, which does not require tokens. |
| Anycast | No | Anycast does not use server tokens on its own. It uses server tokens through the DNS service. |
| Data Connector | No |  |
| DHCP | Yes |  |
| Discovery | No |  |
| DNS | Yes |  |
| DNS Forwarding Proxy | No | This service is related to Infoblox Threat Defense, which does not require tokens. |
| MS AD Sync | No |  |
| NTP | No |  |

# Reporting Tokens

You may purchase reporting tokens and allocate them based on the number of log entries or log events per month. Use reporting tokens for the following options:

- **30-day active search**: All DNS and DHCP logs appear in reports and can be searched and filtered.
- **Logs stored in an S3 bucket**: For asynchronous retrieval.
- **Ecosystem events**: Sent via Cloud Data Connector (CDC) to preferred destinations. Ecosystem reporting tokens are allocated in increments of 10M logs per month.
- **NIOS Source**: NIOS Source is not included in reporting tokens. NIOS Source reporting requires a subscription to **Security Ecosystem Business**, **Infoblox Threat Defense Business On-Premises**, or **Infoblox Threat Defense Advanced**.

The following table shows the reporting token allocation for the Reporting and Ecosystem options described above.

| **Pack Size for Reporting** | **S3 Bucket** | **30-day Active Search** | **60-day Reporting Asynchronous** | **One-year Download** |
| --- | --- | --- | --- | --- |
| 10M log events per month | 40 tokens | 80 tokens | Coming Soon | Coming Soon |
| Ecosystem 10M log events per month (via CDC): 40 tokens |

# Token Usage

The following sections describes how Infoblox calculates token usage and where and what you can see in the usage reports.

## Reporting

Current and historic usage of the following is viewable on the **License Entitlement** page of the Infoblox Portal. 

- Management token usage: Split out by DDI objects, IP addresses, and assets.
- Server token usage: Split out by server size and type (Virtual Server or as a Service).
- Reporting token usage: Split out by report logging type and ecosystem.
- Server and as-a-Service highwater marks: On performance (kQPS/LPS) and capacity (per server object count or discovered network device count).
- NIOS Source is not included in reporting tokens.

## Intervals

**Minutes**

- Every five (5) minutes, a management token allocation snapshot will be taken.  This will reflect the total number of managed DDI objects, IP addresses, and assets at the time of the snapshot.
- Every five (5) minutes, a server token allocation snapshot will be taken.  This will reflect the total count, size, and type of the servers deployed at the time of the snapshot.
- Every five (5) minutes, for each server deployed (NIOS-X virtual Server or NIOSXaaS), DNS queries per second (kQPS), DHCP leases per second (LPS), and capacity count (objects or discovered assets) will be calculated and recorded.

**Calendar Month**

- The highest five-minute value for management token allocation across the month will be recorded as the monthly management token high watermark.
- The highest five-minute value for server token allocation across the month will be recorded as the monthly server token high watermark.
- For each server, the highest five-minute value for each of kQPS, LPS, and capacity count (objects or discovered assets) across the month will be recorded as the monthly kQPS, LPS and capacity (object count or discovered asset count) high watermark.

**Rolling Three Month Average**

- The average of the monthly management token high watermarks, taken across the previous three calendar months, will be recorded monthly as the Management Token rolling three-month average.  This value will be compared with the purchased Management Token count.
- The average of the monthly server token high watermarks, taken across the previous three calendar months, will be recorded monthly as the Server Token rolling three-month average.  This value will be compared with the purchased Server Token count.
- For each server, the average of the monthly kQPS, LPS, and capacity count (objects or discovered assets) high watermark, taken across the previous three calendar months, will be recorded monthly as the server’s kQPS, LPS, and capacity count (objects or discovered assets) rolling three-month average. These values will be compared against the Server size guardrail values for each server.

## Usage Reports

The current and historic usage of the following are viewable on the **License Entitlement** page of the Infoblox Portal.

- Management token usage grouped by DDI objects, IP addresses, and assets
- Server token usage grouped by server size and type (NIOS-X virtual Server or NIOS-XaaS)
- Server and as-a-Service highwater marks on performance (kQPS/LPS) and capacity (per server object count or discovered network device count).

### Object Count Visibility in Universal DDI Licensing

Universal DDI now provides enhanced visibility into object usage and licensing limits to help administrators monitor deployment capacity more effectively. This feature helps ensure that administrators can proactively manage license usage, address capacity constraints, and maintain compliance with their Universal DDI license terms.

The **Licensing** page displays the **total number of objects allowed **and the **actual number of objects currently in use** for the specific deployment type. This allows you to easily compare the configured capacity with the actual consumption. 

When the actual object count exceeds the licensed limit, Universal DDI automatically displays a message on the **Licensing** page stating **“x Servers Exceeding Capacity.”** 

For details on the warning message and how to view exceeded capacity values, see [Server Exceeding Capacity Warning](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186713872).