---
title: "Best Practices for Endpoint"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/331874469/Best%20Practices%20for%20Endpoint"
format: markdown
---
**Note**

> ⚠️ To improve compatibility with VPN solutions, including on-demand VPN, Infoblox Mobile Endpoint for iOS will be able to use the iOS native DNS proxy framework to intercept all DNS traffic. Requirements: iOS/iPadOS 14.x and later, deployment by an MDM.
> ⚠️ 
> ⚠️ Infoblox does not support any VPN clients running on the same mobile device (iOS/Android) along with Infoblox Mobile Endpoint. The only exception is when the mobile device uses the iOS native DNS proxy framework to intercept all DNS traffic on iOS/iPadOS 14.x and later and is deployed by an MDM.

Before you install Infoblox Endpoint, ensure that you check the following, otherwise endpoint might not function properly:

- When installing Infoblox Endpoint from an install package, do ensure the install package was downloaded from the correct Organization in the Infoblox Portal. The install package contains a Customer ID that defines what organization the endpoint will be assigned.
- It is recommended to not disable or delete any active devices that currently have Infoblox Endpoint installed via the Infoblox Portal. If the device is removed from the Infoblox Portal, the client device will not be protected, and the device will not show up on the Infoblox Portal's Endpoints page.
- Your host machine must have enough capacity to run endpoint. On average, endpoint consumes less than 0.5% of CPU and less than 50 MB of memory. Note that these numbers vary based on the host hardware configuration.
- Your local device is not running any DNS service.
- If your device is running MAC OS X, ensure that you turn off *Internet Sharing*.
- Do not apply any firewall rules to block **TCP port 443** due to the following:
  - Endpoint should be able to access the Infoblox geo-based Anycast IP addresses using **TCP port 443** as mentioned ***[here](https://docs.infoblox.com/space/BloxOneThreatDefense/35408116/Forwarding+DNS+Traffic+to+BloxOne+Threat+Defense)***.
  - Endpoint must be able to access the following using **TCP port 443**:
    - **52.119.40.100**
    - **52.119.41.100**
    - **103.80.5.100**
    - **103.80.6.100**
  - Endpoint must be able to access the following using **TCP port 443**:
    - csp.infoblox.com
    - threatdefense.infoblox.com and its subdomains
  - <span style="color: #111111">Endpoint listens on port 53 on the device's </span><span style="color: #111111">**127.0.0.1**</span><span style="color: #111111"> loopback address for non-MAC devices</span>
  - <span style="color: #111111">Endpoint listens on port 53 on the device's </span><span style="color: #111111">**127.0.0.2**</span><span style="color: #111111"> loopback address for MAC devices, only.</span>
- <span style="color: #111111">Do not apply any firewall rules to block </span><span style="color: #111111">**UDP port 53**</span><span style="color: #111111"> due to the following:</span>
  - Endpoint must be able to access **52.119.40.100** **and 103.80.5.100** using **UDP port 53**. The UDP port 53 query is used to identify (1) the public IP address of the endpoint and (2) the AWS region to which endpoint is connected.
- <span style="color: #172b4d">HTTPS traffic must be permitted to s3.dualstack.us-east-1.amazonaws.com, as this is the endpoint clients must access in order to automatically upgrade.</span>
- If you have a VPN client, ensure that the VPN connection is established in the “Split tunnel” mode for every network protocol (IPv4 or IPv4/IPv6 for dual stack).
- <span style="color: #172b4d">Ensure that SSL Inspection is disabled for all the IP addresses/FQDNs that Infoblox Endpoint uses to connect to the cloud and when resolving DNS queries.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ For any deactivated and deleted devices, endpoint can be re-installed and the devices restored and reconfigured.

### <span style="color: #000000">**No Internet Access Warning Message in Windows**</span>

In some rare circumstances, Infoblox Endpoint can make Windows incorrectly display a “No Internet Access” warning, although the connectivity is working fine. This is caused by a limitation in Microsoft Network Connectivity Status Indicator (NCSI) feature.

NCSI uses Active DNS probes to validate internet connectivity on each network interface. However, these DNS checks are restricted and NCSI will refuse to send them to a DNS server on a different interface (such as the loopback IP). Since Infoblox Endpoint runs a DNS forwarder on the loopback interface as part of its core operation, these specific checks are not compatible with endpoint. This limitation does not cause any problem in majority of the environments, because Windows also performs some other checks to validate the connectivity.

To remedy this situation if it occurs in your configuration, do the following.  NOTE: This fix must be deployed to the Local Group Policy. 

1. Locate gpedit.msc. The setting for gpedit.msc within "**Computer Configuration** > **Administrative Templates** > **Network** > **Network Connectivity Status Indicator**".
2. Enable the '*Specify Global DNS*' setting.
3. Run gpupdate /force.
4. Reboot your system. A reboot is required to clear the existing issue.

### **Certification Revocation List (CRL) Domains**

Certification Revocation List (CRL) domains are used by clients to verify the validity of server certificates. To ensure endpoints can successfully transition to a protected state, the following domains must be allowed through the firewall on Port 80:

- <span style="color: #172b4d">*.digicert.com</span>
- http://crl3.digicert.com/sha2-ha-server-g6.crl
- http://crl4.digicert.com/sha2-ha-server-g6.crl

### **Duplicate Client_id Dashboard and Summary**

**Observation**  
When systems are cloned from a Golden Image, multiple devices may appear under a single Infoblox Portal entry.

**Cause**  
The cloned systems inherit the same `client_id` value. Because the Infoblox Portal relies on this identifier to distinguish devices, duplicate `client_id`s prevent the Infoblox Portal from creating unique entries for each cloned system.

**Issue Resolution**  
The fix introduced in version **2.5.0.3** resolves this issue by detecting cloned devices and assigning them a new `client_id` in the Infoblox Endpoint backend. After the update, each cloned system will display correctly in thre Infoblox Portal with its own details. During this process, the original (master) device entry may be marked as **DELETED** in the database. As a result, the master system may no longer appear in the Infoblox Portal. To restore visibility for these master devices, you must reinstall Infoblox Endpoint on the affected systems.

### Using join tokens with Infoblox Endpoint

The following best practices are recommended when using join tokens with Infoblox Endpoint.

- Before starting a new installation for individual devices or groups via manual setup or MDM, always use a freshly downloaded package from the Infoblox Portal downloads page (**Security** > **Downloads**) to ensure the Join Token is valid.
- Once the Infoblox Endpoint Mass deployment is done and successful using the Join token downloaded from the Infoblox Portal it is recommended that the join token to be disabled or removed.