---
title: "Prerequisites for Infoblox–CrowdStrike Integration with Quarantine Enforcement"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDCrowdstrikeEDR/1564246025/Prerequisites%20for%20Infoblox%E2%80%93CrowdStrike%20Integration%20with%20Quarantine%20Enforcement"
format: markdown
---
## **1.Access & Licensing Requirements**

1. **Infoblox Cloud Security Portal**
  - Valid user account with appropriate administrative access.
  - Permissions to configure services like DFP, Data Connector, and setting up the Traffic flow.
2. **Infoblox Threat Defense™ and DDI**
  - Active subscription with required licenses for enabling DFP, Soc Insights, DHCP and IPAM.
3. **CrowdStrike Falcon Platform**
  - Active Falcon subscription.
  - Required modules enabled:
    - Endpoint Detection and Response (EDR)
    - Falcon LogScale (with valid license)
  - Administrative access to configure quarantine policies and API integrations.

## **2. Endpoint & Security Requirements**

4. **CrowdStrike Falcon Agent**
  - Must be installed on all endpoints.
  - Endpoints must be successfully registered in CrowdStrike.
  - Device must be online and visible in the Falcon console before quarantine actions can be applied or removed.
5. **Endpoint Detection and Response (EDR)**
  - CrowdStrike EDR must be the active authentication and authorization solution for monitored endpoints.

## **3. Infoblox Infrastructure Requirements**

6. **NIOS-X Server**
  - Must be deployed and operational.
  - The following services must be installed:
    - DHCP and DNS Forwarding Proxy (DFP) services need to be enabled **on the same host**:
    - Data Connector Service
7. **DHCP and DNS Configuration**
  - DHCP leases must be issued by the DHCP server.
  - DNS queries must be forwarded by the **DFP service** to Infoblox Cloud.
  - DFP service must be added and registered in the Infoblox Portal.
8. **Data Connector Service**
  - Must be running on the NIOS-X server.
  - Must be successfully added to the Infoblox Portal.
  - Proper connectivity to CrowdStrike Falcon LogScale.

## **4. Logging Requirements**

9. **MAC Address Visibility**
  - All required log types must contain MAC addresses.
  - The following services must be enabled to ensure MAC retrieval:
    - DFP Service Logs with DHCP Service enabled.
    - DFP Service Logs with Access (SSO) Authentication Service enabled.

## **5. Network & Connectivity Requirements**

- Outbound HTTPS connectivity from NIOS-X to Infoblox Cloud.
- API connectivity between Infoblox and CrowdStrike.
- Proper firewall rules permitting required service communication.