---
title: "Configuring Network Scopes"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35373166/Configuring%20Network%20Scopes"
format: markdown
---
For Infoblox Platform to properly apply a security policy, you must define the network scope so Infoblox Platform knows which external networks, <span style="color: #000000">user groups,</span> DNS Forwarding Proxies, <span style="color: #000000">IPAM</span>, and Infoblox Endpoint groups are affected. All policy rules you define for this security policy will be applied to the entities in the network scope. Any policy rules outlined within this security policy will then be applied to the entities defined in the network scope.

<span style="color: #000000">To set your network scope for the security policy, complete the following:</span>

1. <span style="color: #000000">On the </span><span style="color: #000000">*Network Scope*</span><span style="color: #000000"> page of the </span><span style="color: #000000">*Create New Security Policy*</span><span style="color: #000000"> wizard, click the </span><span style="color: #000000">**Add Source**</span><span style="color: #000000"> menu and choose one of the following options. For each of the options, you can choose the applicable objects from the </span><span style="color: #000000">**AVAILABLE **</span><span style="color: #000000">table and move them to the </span><span style="color: #000000">**SELECTED**</span><span style="color: #000000"> table using the right-pointing arrow) icon. You can click the  the double right-pointing arrows icon to select all the objects. You can also search for a specific object using the </span><span style="color: #000000">**Search**</span><span style="color: #000000"> function. To remove an object from the </span><span style="color: #000000">**SELECTED**</span><span style="color: #000000"> table, click the close icon or the trashcan icon. When you have completed your selection, click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add the objects, or click </span><span style="color: #000000">**Cancel**</span><span style="color: #000000"> to discard your changes.</span>
  - <span style="color: #000000">**External Networks**</span><span style="color: #000000">: Select this to add external networks to the network scope. For more information, see </span><span style="color: #000000">*[Configuring External Networks](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35473665)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**DNS Forwarding Proxy**</span><span style="color: #000000">: Select this to add DNS Forwarding Proxies to your network scope. For more information about DNS Forwarding Proxy, see </span><span style="color: #000000">*[Using DNS Forwarding Proxy](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35436408)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**Endpoint Groups**</span><span style="color: #000000">: Select this to add </span>Infoblox<span style="color: #000000"> Endpoint groups to your network scope. For information about </span>Infoblox<span style="color: #000000"> Endpoint groups, see </span><span style="color: #000000">*[Infoblox Endpoint Group Assignment](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35404893)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**User Groups**</span><span style="color: #000000">: Select this to add user groups to the network scope. The available user groups are those that have been synchronized through the third-party IdP (identify provider) that your admin has configured for access authentication. For more information, see </span><span style="color: #000000">*[Synchronizing User Groups](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/1136721944)*</span><span style="color: #000000">. </span>
  - <span style="color: #000000">**IPAM**</span><span style="color: #000000">: Select this to add internal networks to the network scope. </span><span style="color: #172b4d">When adding tags to IPAM scopes, any tag-based changes in an IPAM scope based on tags can take up to 5 minutes to take effect. </span>  
To associate a security policy with DDI IPAM objects in the DNS query, do the following:
    - <span style="color: #000000">Select an IP Space to add to your security policy (</span>**Network > IPAM or Network **> **DHCP**).
    - Click the horizontal menu item to display the IP Address block(s) associated with the IP Space. From among the listed address blocks, choose an address block to add to your security policy. Make a note of your selected IP space and address block you want associated with your security policy.
  - **IPAM Hosts**<span style="color: #ff0000">: </span><span style="color: #000000">Select this to add IPAM hosts  to your network scope. IPAM hosts and DHCP ranges can also be added to a policy using tags. To associate a security policy with an IPAM host, do the following:</span>  
To associate a security policy with an IPAM host, do the following:
    - Select <span style="color: #000000">an available IPAM host from those listed under AVAILABLE HOSTS on the </span><span style="color: #000000">*Manage IPAM Hosts*</span><span style="color: #000000"> panel to add to your security policy.</span>
    - <span style="color: #000000">Click the right-pointing arrow) to add the IPAM host to your security policy. Or, click the double right-pointing arrows to add all available IPAM Hosts to your policy. To remove a previously selected IPAM hosts, click the trashcan. </span>
    - <span style="color: #000000">Click </span><span style="color: #000000">**Save**</span><span style="color: #000000"> followed by clicking </span><span style="color: #000000">**Finish**</span><span style="color: #000000"> to complete the configuration process, or click </span><span style="color: #000000">**Next**</span><span style="color: #000000"> to proceed to the next step of the configuration process</span>
  - **Tags**: Select <span style="color: #000000">this to add user-defined tags to your network scope. When the network scope includes an object included in multiple policies, then the policy precedence order will determine which policy is enforced. </span>Changes in policy tagging are updated by the system and may take up to 5 minutes to complete. When multiple tagging changes occur to a security policy, the policy will reflect the most recent change to the policy. <span style="color: #000000">Network scope can be defined using tags for DNS Forwarding Proxy, Endpoints, Endpoint Groups, IPAM networks, individual IPs, IPAM Host objects, and ranges. Policy rules can be defined using tags for custom lists as well as application and category filters. For more information on tags, see </span><span style="color: #000000">*[Applying Tags](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35376587)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**Metadata**</span><span style="color: #000000">: Select this to add Metadata to your network scope. Network scope for </span>Infoblox<span style="color: #000000"> Endpoint can be defined using metadata for operating systems and endpoint version. To configure metadata, do the following:</span>
    - <span style="color: #000000">**ATTRIBUTE**</span><span style="color: #000000">:  Select an attribute from among the listed options in the drop-down list. Attributes supported include </span><span style="color: #000000">**Endpoint Location**</span><span style="color: #000000">, </span><span style="color: #000000">**Endpoint Hostname**</span><span style="color: #000000">, and </span><span style="color: #000000">**OS Version.**</span>
    - <span style="color: #000000">**VALUE**</span><span style="color: #000000">: Select a value from among the listed options in the drop-down list to associate with the attribute. You can use the search tool to find a specific value. The values supported for endpoint version include </span><span style="color: #000000">*Current*</span><span style="color: #000000"> and </span><span style="color: #000000">*Previous*</span><span style="color: #000000">. The value supported for endpoint location include </span><span style="color: #000000">*Country*</span><span style="color: #000000">. Multiple countries can be selected when configuring location.  The value supported for endpoint hostname is the </span><span style="color: #000000">*Device name*</span><span style="color: #000000">. The values supported for OS Family  include </span><span style="color: #000000">*Windows*</span><span style="color: #000000">, </span><span style="color: #000000">*MacOS*</span><span style="color: #000000">, </span><span style="color: #000000">*Linux*</span><span style="color: #000000">, </span><span style="color: #000000">*ChromeOS*</span><span style="color: #000000">, </span><span style="color: #000000">*iOS*</span><span style="color: #000000">, and </span><span style="color: #000000">*Android*</span><span style="color: #000000">.</span>  
  
> Macro (inline-media-image)
    - For each source you have added, click **Add**<span style="color: #000000">. The source appears in the table. You can click the </span>**Add Source**<span style="color: #000000"> menu again to choose another source for your network scope.</span>
    - After you define your network scope, you can proceed to add policy rules, set precedence order and bypass codes.
    - To edit metadata, select Policy Rules, then click **Manage**.
    - Click **Next** in the wizard to define policy rules. For more information, <span style="color: #000000">see </span>*[Adding Policy Rules and Setting Policy Precedence](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35403288)*<span style="color: #000000">.</span>

<span style="color: #000000">2. From the </span><span style="color: #000000">*Hosts*</span><span style="color: #000000"> page (</span>**Network > IPAM or Network **> **DHCP**), perform a search in the search field on the IP address to locate any host(s) already associated with the IP space. If a host is not yet associated with the IP space, you will have to associate the  host with the IP space by selecting the host and editing it. If an host is not associated with the IP space, then the configuration will not work within the security policy. When the *Edit Infoblox Container* dialogue appears, in the IP Space field, select the chosen IP space from among the list of  host options from which to associate with the IP Space you have previously selected.

<span style="color: #000000">3. Once an IP space has been associated with the host, click </span><span style="color: #000000">**Save & Close**</span><span style="color: #000000"> to save the configuration.</span>  
<span style="color: #000000">4. Next, go to </span><span style="color: #000000">**Security**</span><span style="color: #000000"> > </span><span style="color: #000000">**Configure**</span><span style="color: #000000"> > </span><span style="color: #000000">**Security**</span><span style="color: #000000"> </span><span style="color: #000000">**Policies**</span><span style="color: #000000"> to create the security policy to be associated with the security policy and with the chosen address block.</span>  
<span style="color: #000000">5. In the Network Scope section of the </span><span style="color: #000000">*Create New Policy*</span><span style="color: #000000"> dialogue, click </span><span style="color: #000000">**Add Source **</span><span style="color: #000000">and select IPAM from among the drop-down menu choices.</span>  
<span style="color: #000000">6. On the Manage IPAM page, locate your chosen IP space and select it. From the listed IPAM objects on the page, select those IPAM object(s) you want to be associated with it (in this case, the IP address block). Once you have made your selections, click Add followed by Save to save the configuration. For more information about IPAM, see DHCP in the Infoblox Universal DDI documentation. </span>  
<span style="color: #000000">7. For each source you have added, click </span><span style="color: #000000">**Add**</span><span style="color: #000000">. The source appears in the table. You can click the </span><span style="color: #000000">**Add Source**</span><span style="color: #000000"> menu again to choose another source for your network scope.</span>  
<span style="color: #000000">8. After you define your network scope, you can proceed to add policy rules, set precedence order and bypass codes.</span>  
<span style="color: #000000">9. Click </span><span style="color: #000000">**Next**</span><span style="color: #000000"> in the wizard to define policy rules. For more information, see </span><span style="color: #000000">*[Adding Policy Rules and Setting Policy Precedence](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35403288)*</span><span style="color: #000000">.</span>  


<span style="color: #000000">For information on using overlapping subnets to define policy scope, see </span>*[Allowing Overlapping Internal and External Subnets When Defining Security Policy Scope](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/409338224)*.

> ⚠️ ### Note
> ⚠️ 
> ⚠️ <span style="color: #000000">A security policy can also be applied to a specific fixed IP address or reserved address. Both fixed addresses and reserved addresses can be added to IPAM within an address block residing on your server. To do this, select  the IP block and drill down until the fixed or reserved IP address is displayed. Once you have located the fixed or reserve IP address to which you are interested in applying the security policy, click Add to apply the policy to the fixed IP address or hostname.</span>

  
<span style="color: #000000">For information about other tasks in creating a new security policy, see the following:</span>

- <span style="color: #000000">*[Configuring Security Policies](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35371559)*</span>
- <span style="color: #ff0000">*[Creating Security Policies](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469750)*</span>
- <span style="color: #ff0000">*[Adding Policy Rules and Setting Policy Precedence](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35403288)*</span>
- <span style="color: #ff0000">*[Adding Bypass Codes to a Security Policy](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35373231)*</span>