---
title: "Infoblox Subscriber Insight and Subscriber Policy Enforcement"
canonical: "https://docs.infoblox.com/space/nios85/35416958/Infoblox%20Subscriber%20Insight%20and%20Subscriber%20Policy%20Enforcement"
format: markdown
---
<span style="color: #000000">The Infoblox Subscriber Insight solution provides a mechanism to monitor events related to the subscriber session. This solution allows you to identify subscriber devices, such as laptops, computers, tablets, and smartphones on your data networks that are violating RPZ rules. It can also find the type of domain the subscriber tries to access.</span>

<span style="color: #000000">The Infoblox Policy Enforcement solution analyzes the DNS queries, identifies, subscribers, and correlates the information to enforce the subscriber security policies per subscriber.</span>

<span style="color: #000000">The solution works by receiving RADIUS accounting messages from a RADIUS server through the NAS (Network Access Server) gateway. The DNS server caches the RADIUS accounting messages, which includes subscriber information and subscriber security policies. The subscriber security policy specifies the RPZs that are applicable for a subscriber. DNS RPZs are used to determine bad FQDNs. If a subscriber, who has opted for the service, queries an FQDN that is listed in the RPZ, the DNS resolver performs RPZ actions for the subscriber query.</span>

<span style="color: #000000">Subscribers behind a home gateway network are identified by their local ID or client ID, which is the MAC address of the subscriber device. The local ID is received by the DNS server as part of the RADIUS accounting message. As all subscribers behind a home gateway network will have the same IP address of the home router, the local ID is used to create separate records for each of the subscribers in the subscriber cache. Each subscriber behind the home gateway network can have their own policy. Note that if a guest connects through a home gateway network, then the default home router policy is applied to the guest device.</span>

<span style="color: #000000">The Infoblox Subscriber Insight and Subscriber Policy Enforcement is currently supported on the following Infoblox appliances: IB-1415, IB-1425, IB-2215, IB-2225, PT-1405, PT-2205, IB-4030, IB-4030-10GE, IB-VM-1405, IB-VM-1415, IB-VM-1425, IB-VM-2205, IB-VM-2225, IB-VM-1425, and IB-FLEX. You can enable DNS cache acceleration feature on IB-4030, IB-4030-10GE, and IB-FLEX appliances.</span>

<span style="color: #000000">As illustrated in </span>[*<span style="color: #000000">Figure 46.1</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478252)<span style="color: #000000">, the Infoblox DNS member, with subscriber collection service enabled, receives RADIUS accounting messages, which includes subscriber information and the subscriber security policies, through the NAS gateway. The subscriber security policy specifies the RPZs that are applicable for a subscriber. When a subscriber queries an FQDN that is listed in the RPZ, the DNS resolver performs RPZ actions for the subscriber query. The NIOS appliance logs all RPZ related events, conformed to CEF (Common Event Format), in the syslog. The CEF logs include the subscriber identity information, thus identifying the subscribers that are violating RPZ rules. In a Grid with a reporting server, you can view the </span>*<span style="color: #000000">Detailed RPZ Violations by Subscriber ID</span>*<span style="color: #000000"> report that contains information about RPZ hits by the users. For information, see</span>*<span style="color: #000000"> </span>*[*<span style="color: #000000">Detailed RPZ Violations by Subscriber ID</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35751081/About+Dashboards#AboutDashboards-DetailedRPZViolationsbySubscriberID)<span style="color: #000000">.</span>

> Macro (anchor)

*<span style="color: #000000">Figure 46.1 Infoblox Subscriber Insight and Subscriber Policy Enforcement</span>*

> Macro (drawio)

## > Macro (anchor)

License Requirements and Admin Permissions

<span style="color: #000000">To configure Infoblox Subscriber Services, you must install the </span>**<span style="color: #000000">RPZ</span>**<span style="color: #000000"> license. Although, for IB-FLEX members, the </span>**<span style="color: #000000">RPZ</span>**<span style="color: #000000"> license is included in the </span>**<span style="color: #000000">FLEX Grid Activation</span>**<span style="color: #000000"> license. For information about how to install licenses, see </span>[*<span style="color: #000000">Managing Licenses</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35417954)<span style="color: #000000">.</span>

<span style="color: #000000">Only superusers can configure Infoblox Subscriber Services. Limited-access admin groups can perform this operation only if their administrative permissions are defined. For information about administrative permissions, see </span>[*<span style="color: #000000">About Administrative Permissions</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35979376)<span style="color: #000000">.</span>

# <span style="color: #000000">Guidelines for Using Infoblox Subscriber Insight and Subscriber Policy Enforcement</span>

<span style="color: #000000">The following are some guidelines to take into consideration when using Infoblox Subscriber Threat Insight and Subscriber Policy Enforcement:</span>

- <span style="color: #000000">A Grid member can be associated with only one subscriber site.</span>
- <span style="color: #000000">The Grid members in the subscriber site must be added as primary or secondary name servers for all RPZs.</span>
- <span style="color: #000000">The subscriber collection service does not support an IPv6 only Grid member.</span>
- <span style="color: #000000">All NAS gateways in a subscriber site must be configured for IPv4 only and must use the same port.</span>
- <span style="color: #000000">The subscriber data is not persistent and will be cleared from the subscriber cache if you stop the subscriber collection service on all the members of a subscriber site.</span>
- <span style="color: #000000">The NAS gateways can send the RADIUS accounting messages to only one Grid member (collector member) in a subscriber site.</span>
- <span style="color: #000000">Overlapping networks are not supported in the </span><span style="color: #000000">Subscriber Insight and Subscriber Policy Enforcement solutions.</span>

# Configuring Infoblox Subscriber Insight and Subscriber Policy Enforcement

To set up Infoblox Subscriber Insight and Subscriber Policy Enforcement, you must install a Grid-wide or a member level **RPZ** license and configure the Grid members to serve recursive DNS queries. Note that for IB-FLEX members, you do not need to install an **RPZ** license as the **FLEX Grid Activation** license includes the **RPZ** license. You must also configure a subscriber site and add Grid members (collector members and RPZ members) and NAS (Network Access Server) gateways to receive RADIUS accounting messages from a RADIUS server. The RADIUS accounting messages include subscriber information (such as subscriber source IP address, subscriber ID, and local ID for networks with overlapping IP addresses) and subscriber security policies. The source IP address, subscriber ID, local ID, and the subscriber security policy is mapped in the DNS cache. The collector member caches the subscriber information and the policies, which are replicated to all Grid members within the subscriber site. The RPZ members in the subscriber site applies policies for incoming subscriber queries and performs RPZ actions.

The DNS Cache Acceleration processes incoming EDNS0 packets that contain the local ID. The NIOS appliance matches the local ID against the DNS server as part of the RADIUS accounting message and populates the subscriber cache in DNS Cache Acceleration with the parental control policy information. The DNS Cache Acceleration answers all queries that come from the DNS Cache Acceleration for each of these subscribers listed in the subscriber cache. These changes are valid for individual IP addresses with local ID only and the subnet local ID is considered as 0. For more information, see <span style="color: #0000ff">[*Using the NIOS CLI*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35477821)</span> and <span style="color: #0000ff">[*Viewing the DNS Accelerator Cache*](https://infoblox-docs.atlassian.net/wiki/spaces/DAAG/pages/10748016/Clearing+DNS+Cache#ClearingDNSCache-ViewingtheDNSAcceleratorCache)</span> in the *Infoblox DNS Cache Acceleration Administrator Guide*.

Note the following while configuring Infoblox Subscriber Insight and Subscriber Policy Enforcement:

- You can configure up to a total of 32 RPZs in the default view and set the priorities for the RPZs. Subscribers with subscriber security policies can set the policy to any of the 32 RPZs and the RPZs are applied to selective subscribers depending on the subscriber security policies. Although, for subscribers who have not opted for the service, only the first five (top priority) RPZs are applied. Note that once the first hit matches, the rest of the RPZs will not be looked up.
- For DNS queries received from unknown subscriber source IP addresses, the DNS server processes the queries based on the standard DNS query processing.

To configure the Infoblox Subscriber Insight and Subscriber Policy Enforcement on supported Infoblox appliances, complete the following:

1. Obtain and install a valid Grid-wide or member level **RPZ** license. But for IB-FLEX members, the **RPZ** license is included in the **FLEX Grid Activation** license. For information about licenses, see <span style="color: #0000ff">[*License Requirements and Admin Permissions*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478252)</span>. You can also configure a reporting appliance in the Grid to see subscriber reports that contain statistics about RPZ related events.
2. Configure admin permissions so admin users can manage the Infoblox Subscriber Service related tasks. For information about how to configure admin permission, see <span style="color: #0000ff">[*About Administrative Permissions*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35979376)</span>.
3. Create a subscriber site with at least one Grid member and a NAS gateway. For information, see <span style="color: #0000ff">[*Adding Subscriber Sites*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35481042/Scaling+Using+Subscriber+Sites#ScalingUsingSubscriberSites-AddingSubscriberSites)</span>. It is recommended to add more than one Grid member to the subscriber site for redundancy. You can add a maximum of five Grid members to the subscriber site.
4. Start the subscriber collection service on all the members in the subscriber site, as described in <span style="color: #0000ff">[*Starting and Stopping the Subscriber Collection Service*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478252)</span>.
5. Create RPZs in the default DNS view and specify the order of RPZs. Note that only the default DNS view is supported for configuring RPZs for Subscriber Services. For information about creating RPZs, see <span style="color: #0000ff">[*Configuring Local RPZs*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35914743)</span>. For information about specifying the order of RPZs, see <span style="color: #0000ff">[*Reordering RPZs*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35784844/Managing+RPZs#ManagingRPZs-ReorderingRPZs)</span>. You can create a total of 32 RPZs. Subscribers with subscriber security policies can set the policy to any combination of the 32 RPZs and the RPZs are applied to selective subscribers depending on the subscriber security policies. Although, for subscribers who have not opted for the service, only the first five (top priority) RPZs are applied. The NAS gateways must provide the subscriber security policies that enable the selection of RPZs applicable for the subscriber.
6. Enable all the members in the Grid to respond to recursive queries, as described in <span style="color: #0000ff">[*Enabling Recursive Queries*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35448674)</span>.
7. Enable RPZ logging in the *Member DNS Properties* editor for each member of the subscriber site, to ensure that all events related to RPZ are logged to the syslog. Note that you can also enable logging of queries and responses, but it might significantly affect system performance. For information about how to set logging categories, see <span style="color: #0000ff">[*Setting DNS Logging Categories*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35784616/Using+a+Syslog+Server#UsingaSyslogServer-SettingDNSLoggingCategories)</span>.
8. After completing the DNS configuration on the Grid members, start the DNS service on the Grid members. For information about how to start and stop the DNS service, see <span style="color: #0000ff">[*Starting and Stopping the DNS Service*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35786027)</span>.
9. Add AVPs that are not available in the list of predefined AVPs. For information, see <span style="color: #0000ff">[*Adding AVPs*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35751288/Managing+AVPs+Attribute+Value+Pairs#ManagingAVPs(AttributeValuePairs)-AddingAVPs)</span>.
10. Configure the subscriber ID settings to associate an AVP with the subscriber in the Subscriber Services Properties editor, as described in <span style="color: #0000ff">[*Configuring Subscriber Services Properties*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478252)</span>.

After you set up the Infoblox Subscriber Insight and Subscriber Policy Enforcement, you can perform the following:

- View the subscriber sites, as described in <span style="color: #0000ff">[*Viewing Subscriber Sites*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35481042/Scaling+Using+Subscriber+Sites#ScalingUsingSubscriberSites-ViewingSubscriberSites)</span>.
- View the NAS gateway message rates for the accounting servers of the subscriber site, as described in <span style="color: #0000ff">[*Viewing NAS Gateway Message Rates*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35481042/Scaling+Using+Subscriber+Sites#ScalingUsingSubscriberSites-ViewingNASGatewayMessageRates)</span>.
- Monitor RPZ related events and subscriber policy violations using predefined reports and the syslog, as described in <span style="color: #0000ff">[*Monitoring Subscriber Policy Violations*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35751177)</span>.
- Configure Infoblox Subscriber Parental Control solution, as described in <span style="color: #0000ff">[*Infoblox Subscriber Parental Control*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35417031)</span>.

# > Macro (anchor)

Starting and Stopping the Subscriber Collection Service

To start the subscriber collection service, you must have at least one **RPZ** license installed (it can be a Grid-wide license or a member-level license.) You can also stop the service when necessary.

To start or stop the subscriber collection service, complete the following:

1. From the **Grid** tab -> **Grid Manager** tab -> **Services** tab, click the **Subscriber Collection** link. Grid Manager displays only the members that are running the subscriber collection service. Select the member checkbox.
2. From the Toolbar, click **Start** to start the service or **Stop** to stop the service.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ The subscriber data is not persistent and will be cleared from the subscriber cache if you stop the subscriber collection service on all the members of a subscriber site.


# > Macro (anchor)

Configuring Subscriber Services Properties

To configure the subscriber services properties, complete the following:

1. From the **Data Management** tab -> **DNS** tab -> **Subscriber Services Deployment** tab, expand the Toolbar and click **Subscriber Services Properties**.
2. In the **General** tab, complete the following:

> Macro (legacy-content)