Forum Discussion

Nikoolayy1's avatar
Mar 21, 2021

Is there F5 ip intelligence based on domain/FQDN (domain intelligence)?

I ask this question because for example for email security an email can be blocked if the source IP and/or source domain (DNS FQDN) are in a blacklist. From what I read the F5 Ip intelligence provides only a feed for bad IP addresses but there are attackers that use DYNAMIC DNS: DATA EXFILTRATION can change the domain related ip addresses very often and this could a usefull feature if not present at the moment.

  • Yea! I'm using this codeshare with great sucess!

    https://devcentral.f5.com/s/articles/dns-interception-protecting-the-client

    this code validates the query FQDN with URL Feed and also can validate the response with IPI.