---
title: "Troubleshooting & FAQ"
canonical: "https://docs.infoblox.com/space/DeploymentGuideDNSInfrastructureProtection/1870921737/Troubleshooting%20%26%20FAQ"
format: markdown
---
Some common issues and their resolution are discussed in this section.

**Unable to download DNS Infrastructure Protection Rules**

You may encounter a situation where the DNS Infrastructure Protection appliance is not able to download DNS Infrastructure Protection rules from [ts.infoblox.com](http://ts.infoblox.com). The troubleshooting steps are as follows,

- Make sure the Grid can resolve the hostname [ts.infoblox.com](http://ts.infoblox.com).
  - A Resolver must be configured for the Grid so that any member involved can resolve the hostname. (Please see **Enabling DNS resolver** section)
- Make sure the Grid can reach the server [ts.infoblox.com](http://ts.infoblox.com).
  - Check to see if any firewall rule is blocking the path to https.
  - Check the proxy setting if applicable.

**Trouble joining the Grid**

If you are having trouble joining a member to the Grid, here are things to look at;

- Member type (Make sure the right member type is selected)
  - Infoblox - for physical PT Appliances, and TE Appliances for Software DNS Infrastructure Protection.
  - Virtual NIOS - for Virtual TE-Appliances for Software DNS Infrastructure Protection.
- **Enable VPN on MGMT Port **has been checked in **Grid Member Properties Editor **>** Network **> **Advanced**
- Make sure the member can ping the Grid Master and verify the firewall is not restricting any access.  For reference, check the NIOS Administration Guide.
- Make sure that you have enable MGMT on the member to join and that MGMT IPs match on member local configuration & grid provisioned member configuration.


**Different rulesets for different  DNS Infrastructure Protection appliances**

**Question: **How can I create two rulesets in  DNS Infrastructure Protection? one for external  DNS Infrastructure Protection appliances and the other for internal  DNS Infrastructure Protection appliances? Both sets need to be tuned differently so I need to apply different tuning to different appliances.

**Answer: **Best practice is to use DNS Infrastructure Protection Profiles.

**Trouble Starting DNS Infrastructure Protection Service**

- The Member cannot be a Grid-Master unless it is a Grid of one.
- The DNS Infrastructure Protection service may not start.

**Understanding a CEF Log message**

Please see **Logging** section in this deployment guide to be able to read the contents of a CEF log message.


**Outbound API**

The Infoblox Outbound API can send outbound notifications to Syslog, DXL (Data Exchange Layer), and REST API endpoints. The DNS Infrastructure Protection *event_type* can trigger on events like: Hits Count, Member IP, Member Name, Query FQDN, Rule Action, Rule Category, Rule Severity, SID, and Source IP. This will notify any solution that will accept indicators that can be acted upon.

These notifications can do a myriad number of things, like triggering client remediation with endpoint security solutions, integration with SOAR solutions, create SOC events, trigger DDoS mitigations, and even opening Service Now tickets. These notifications are vendor neutral.

To use the Outbound API, a Security Ecosystem License is required.

Please defer to the NIOS 8.4 Documentation for details on the Infoblox Outbound API. At [https://docs.infoblox.com](https://docs.infoblox.com), search for “Outbound Notification Overview”