---
title: "Deployment Architecture"
canonical: "https://docs.infoblox.com/space/DeploymentGuideDNSInfrastructureProtection/1869905934/Deployment%20Architecture"
format: markdown
---
DNS Infrstructure Protection appliances support standalone or grid member deployments. The DNS Infrastructure Protection feature is not supported on the Grid Manager (GM) or Grid Manager Candidate (GMC) servers. DNS Infrastructure Protection Appliances should always be deployed using out of band management and typically would use anycast for availability and redundancy. The intent is that any attack traffic should be contained to the network that the LAN1 interface is connected to.

If reporting is enabled, reporting traffic must be configured to use the management interface.

No extra configuration is needed if the DNS Infrastructure Protection member’s management interface and Reporting member’s LAN1 interface share the same subnet. However, a route needs to be added in the DNS Infrastructure Protection members network configuration to enable connectivity to the Reporting server if the two are on different subnets.