---
title: "Configuring On-Prem DNS Firewall Service"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/356614212/Configuring%20On-Prem%20DNS%20Firewall%20Service"
format: markdown
---
Prior to beginning the configuration process, downloading and reviewing the  is recommended. On the On-Prem Firewall Configuration page in the Infoblox Portal (**Security** > **Configuration** > **On-prem Firewall**), click **View Deployment Guide** to download and read the PDF document. <span style="color: #000000">The deployment guide walks through the four-step process of setting up and configuring On-Prem DNS Firewall service. </span>

> ⚠️ <span style="color: #000000">Depending on your licensing type (non-token-based or token-based), refer to the On-Prem DNS Firewall configuration instructions specific to your subscription.</span>

## Token-Based Licensing with Security Tokens

![The four-step On-Prem DNS Firewall configuration set-up process for the token-based subscription model. ](media://a83f50a7-2d43-4c44-b09f-98f3e9c9a79e)

### **Step 1**: **Configure RPZ Feed Details in NIOS** 

Click **View Feeds** followed by clicking **Copy** associated with an RPZ feed to configure the NIOS feed values with the provided feed addresses. Copy these values to a text editor as you will require them later for NIOS configuration. *For more information, see* *[Configuring RPZ Feeds](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/356417624)**. *

Once the feed addresses have been copied, click **Close** and proceed to **Step 2:** **Enter NIOS Grid Member Models**.

### **Step 2**: **Enter NIOS Grid Member Models**

> ℹ️ If you are using the legacy-based, licensing model,** Step 2** does not apply to you. For information on using the legacy-based, licensing model, please refer to the **Non-Token-Based Licensing Model** section.

Click **Enter Information** to add NIOS Grid Member model information. On the *Enter NIOS Grid Member Information To Enable Feeds* screen, select the following from the drop-down option menus:

1. From the *Appliance Series* drop-down list, select the appropriate NIOS Grid Member appliance for your deployment.
2. From the *Appliance Model* drop-down list, select the appropriate NIOS Grid Member appliance for your deployment.
3. From the Primary drop-down list, select the number of servers you are configuring.

> ℹ️ **HA Pair quantity is configuration**:** **
> ℹ️ 
> ℹ️ Primary Quantity refers to Primary node in Grid Member; HA Pair Quantity is any HA node in Grid Member. You can input the HA Pair quantity, but only the primary quantity gets token allocation.

         Once the NIOS Grid Member Information has been added, click **Save & Close** to proceed to Step 3. *[Select Distribution Server and TSIG Details](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35468259)**.*

![Select the appliance series, the number of appliance models to be added, and the number of primary servers to be added. Do note that the HA Pair quantity is system-generated, based off the number of primary servers being added. ](media://bb080da6-cf3d-42b0-aebf-99c59900a107)

### **Step 3**: **Select Distribution Server and TSIG Details**

Configure IP address members to receive notifications and updates (this step is optional, but recommended). Click **View Distribution Server Details** to configure your distribution servers. Both IPv4 and IPv6 IP addresses may be used to serve your feeds, depending on your specific requirements. For more information, see *[Configuring the Distribution Server](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35468259)*.   

Once Step 2 has been completed, proceed to Step 3, *[Configuring Feed Notification Updates](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/356745387)*.

### **Step 4**: **Configure Feed Notifications Updates**

Click **Enter DNS Server Information** to configure your list of threat retrieval members and notifications. You can add and remove members as needed. For more information, see *[Configuring Feed Notification Updates](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/356745387)*.  
  


## Non-Token-Based Licensing Model

![The three-step On-Prem DNS Firewall configuration set-up process.](media://cdd6b559-dc3d-445a-a906-2b7306c52406)

<span style="color: #000000">When ready, complete the following three-step configuration process: </span>

### **Step 1**: <span style="color: #333333">**Configure RPZ Feed Details in NIOS**</span> 

Click **View Feeds** followed by clicking **Copy** associated with an RPZ feed to configure the NIOS feed values with the provided feed addresses. Copy these values to a text editor as you will require them later for NIOS configuration. <span style="color: #000000">*For more information, see*</span><span style="color: #111111"> </span><span style="color: #111111">*[Configuring RPZ Feeds](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/356417624)*</span><span style="color: #111111">*. *</span>

Once the feed addresses have been copied, click **Close** and proceed to Step 2. *[Select Distribution Server and TSIG Details](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35468259)**.*  

### **Step 2**: <span style="color: #292a2e">**Select Distribution Server and TSIG Details**</span>

<span style="color: #000000">Configure IP address members to receive notifications and updates (this step is optional, but recommended). Click </span><span style="color: #000000">**View Distribution Server Details**</span><span style="color: #000000"> to configure your distribution servers. Both IPv4 and IPv6 IP addresses may be used to serve your feeds, depending on your specific requirements. For more information, see </span><span style="color: #000000">*[Configuring the Distribution Server](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35468259)*</span><span style="color: #000000">.   </span>

<span style="color: #000000">Once Step 2 has been completed, proceed to Step 3, </span>*[Configuring Feed Notification Updates](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/356745387)*.

### <span style="color: #000000">**Step 3**</span><span style="color: #000000">: </span><span style="color: #000000">**Configure Feed Notifications Updates**</span>

<span style="color: #000000">Click </span><span style="color: #000000">**Enter DNS Server Information**</span><span style="color: #000000"> to configure your list of threat retrieval members and notifications. You can add and remove members as needed. For more information, see </span>*[Configuring Feed Notification Updates](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/356745387)*.  


<span style="color: #000000">This completes the On-Prem Firewall Service configuration process. </span>

## Sizing Guidelines for DDI Appliances

<span style="color: #172b4d">Infoblox DDI appliances have limits on the number of threat intelligence entries that can be loaded on to each appliance. These recommended per-appliance limitations help achieve acceptable performance and should not be exceeded. </span>For information on sizing DDI appliances, see *[Sizing Guidelines for Trinzic Appliances](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35434905)*.  

## <span style="color: #172b4d">Enabling and Scaling of Custom RPZ Feeds</span>

<span style="color: #111111">When DNS requests are blocked or redirected by a threat feed on the Infoblox Threat Defense, use the option to apply and enable a custom RPZ feed for smaller appliances. For information, see </span><span style="color: #111111">*[Enabling and Scaling of Custom RPZ Feeds](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35402500)*</span><span style="color: #111111">. </span>

## <span style="color: #172b4d">Selecting a TSIG Key Format</span>

<span style="color: #172b4d">For information on choosing a TSIG key format, see </span><span style="color: #172b4d">*[Selecting a TSIG Key Format](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35402519)*</span><span style="color: #172b4d">.   </span>