Download presentation
Presentation is loading. Please wait.
Published byCharlene Maxwell Modified over 8 years ago
1
© 2013 Unicomp Inc. All Rights Reserved. Infoblox Basic Works 1 By Unicomp
2
© 2013 Unicomp Inc. All Rights Reserved. Agenda 2 Overviews System Setting HA & Grid Setting DNS Overview DNS configuration Others Overviews System Setting HA & Grid Setting DNS Overview DNS configuration Others
3
© 2013 Unicomp Inc. All Rights Reserved. Agenda 3 Overviews System Setting HA & Grid Setting DNS Overview DNS configuration Others Overviews System Setting HA & Grid Setting DNS Overview DNS configuration Others
4
© 2013 Unicomp Inc. All Rights Reserved. Overviews 4 Solutions Integrated DNS, DHCP and IP Address Management on hardened physical and virtual appliances that offer resiliency, security, redundancy and world-class performance Patented Grid™ technology delivers high scalability and a level of network services availability unique to Infoblox Seamless integration with VMware and Microsoft servers delivers IPAM for your entire environment, without any negative impact
5
© 2013 Unicomp Inc. All Rights Reserved. Overviews 5 DNS Discovery Network Switch/Routers IP Endpoints DHCP Integrated DNS, DHCP & IP Address Management
6
© 2013 Unicomp Inc. All Rights Reserved. Overviews 6 Automated Disaster Recovery Grid Master Member Infoblox Grid Grid Master Candidate Member is disconnected from master: Changes maintained by member and then synchronized with master upon reconnection Catastrophic failure of Master (both devices fail): Admin may promote any ‘Grid Master Candidate’ to Master – members re-synch automatically Device failure in HA: Failover to secondary device via VRRP—applies to members and master Individual device failover: Plug in new device and it instantly inherits all attributes of previously deployed device via master Member
7
© 2013 Unicomp Inc. All Rights Reserved. Overviews 7 Delegated Administration Internal Grid Members Grid Master Virtual Environment Internal Grid Members Grid Master Virtual Environment Internal Grid Members Grid Master Virtual Environment Multi-Grid Master Candidate Master Grid Single view of Global IPv4 and IPv6 data Multi-version and Upgrade Management High Availability, Disaster Recovery & System Integrity Massive Scalability Reporting, Logging & Monitoring Centrally manage up to 50 Grids, each Grid with up to 250 members for a total of 12,500 members Centrally manage up to 50 Grids, each Grid with up to 250 members for a total of 12,500 members
8
© 2013 Unicomp Inc. All Rights Reserved. Agenda 8 Overviews System Setting HA & Grid Setting DNS Overview DNS configuration Others Overviews System Setting HA & Grid Setting DNS Overview DNS configuration Others
9
© 2013 Unicomp Inc. All Rights Reserved. System Setting 9 Appliance Hardware Serial Port - Login with default username and password. ▪ username : admin, password : infoblox MGMT - Shutdown in default USB - Disabled, reserved for future use Serial Port - Login with default username and password. ▪ username : admin, password : infoblox MGMT - Shutdown in default USB - Disabled, reserved for future use Serial port MGMT Lan1 HA Lan2
10
© 2013 Unicomp Inc. All Rights Reserved. System Setting 10 System login Default account and password : admin / infoblox Default management interface is shutdown. Default Lan1 address is 192.168.1.2/24 Use command “show network” to show the network setting. Use command “set network” to modify the Lan1 address. The system would restart after modify the address. Default account and password : admin / infoblox Default management interface is shutdown. Default Lan1 address is 192.168.1.2/24 Use command “show network” to show the network setting. Use command “set network” to modify the Lan1 address. The system would restart after modify the address.
11
© 2013 Unicomp Inc. All Rights Reserved. System Setting 11 Address setting
12
© 2013 Unicomp Inc. All Rights Reserved. System Setting 12 License Use command “show license” to check the license status.
13
© 2013 Unicomp Inc. All Rights Reserved. System Setting 13 License Use command “set license” to add the license. Use command “set temp_license” to add the 60 days demo license.
14
© 2013 Unicomp Inc. All Rights Reserved. System Setting 14 Reset system “reset all” : To reset the configuration but keep the licenses. “reset all license” : To reset the configuration and remove the licenses. “reset all” : To reset the configuration but keep the licenses. “reset all license” : To reset the configuration and remove the licenses.
15
© 2013 Unicomp Inc. All Rights Reserved. System Setting 15 Show system information Also show grid status (Master or member) Also show HA status Show current version and serial number Show current version and serial number
16
© 2013 Unicomp Inc. All Rights Reserved. System Setting 16 Enable SSH management Use command “set remote_console” to enable ssh.
17
© 2013 Unicomp Inc. All Rights Reserved. System Setting 17 Enable SSH management
18
© 2013 Unicomp Inc. All Rights Reserved. System Setting 18 Initial Setup After login to web, appliance startup wizard opens.
19
© 2013 Unicomp Inc. All Rights Reserved. System Setting 19 Initial Setup
20
© 2013 Unicomp Inc. All Rights Reserved. System Setting 20 Change user’s password Password must contain at least 4 characters.
21
© 2013 Unicomp Inc. All Rights Reserved. System Setting 21 Create New Account Administration > Administrators > Groups Add new Group. Don’t select any roles. Select default Dashboard template.
22
© 2013 Unicomp Inc. All Rights Reserved. System Setting 22 Create New Account Administration > Administrators > Permissions Add the Global Permission to the group.
23
© 2013 Unicomp Inc. All Rights Reserved. System Setting 23 Create New Account Administration > Administrators > Permissions Select the permission type Check the permission of functions.
24
© 2013 Unicomp Inc. All Rights Reserved. System Setting 24 Create New Account Administration > Administrators > Admins Add an account and select the admin group Test permission
25
© 2013 Unicomp Inc. All Rights Reserved. System Setting 25 Interface Configuration Grid > Grid Manager > Members Edit the Grid member.
26
© 2013 Unicomp Inc. All Rights Reserved. System Setting 26 Interface Configuration *After enable interface “MGMT”, you could not manage device with LAN.
27
© 2013 Unicomp Inc. All Rights Reserved. System Setting 27 Interface Configuration Data Management > DNS > Members Edit DNS Member. Check the interface to enable DNS service.
28
© 2013 Unicomp Inc. All Rights Reserved. System Setting 28 Firmware Upgrade Upload firmware and distribute to members.
29
© 2013 Unicomp Inc. All Rights Reserved. System Setting 29 Firmware Downgrade
30
© 2013 Unicomp Inc. All Rights Reserved. Agenda 30 Overviews System Setting HA & Grid Setting DNS Overview DNS configuration Others Overviews System Setting HA & Grid Setting DNS Overview DNS configuration Others
31
© 2013 Unicomp Inc. All Rights Reserved. HA Configuration 31 HA Overviews HA pair consists of two nodes: Active and Passive. Active send VRRP advertisements every second to Passive to indicate that it is alive. Passive listens for advertisements and remains in passive state. If Passive doesn’t receive an advertisement in three seconds, it takes over as new Active. HA pair consists of two nodes: Active and Passive. Active send VRRP advertisements every second to Passive to indicate that it is alive. Passive listens for advertisements and remains in passive state. If Passive doesn’t receive an advertisement in three seconds, it takes over as new Active. L2 Switch Lan HA Lan HA HA node1 HA node2 HA VIP
32
© 2013 Unicomp Inc. All Rights Reserved. HA Configuration 32 bloxSYNC Database synchronization process is called bloxSYNC. Active sends updates to the Passive. -Host names, IP addresses, zones, leases, configuration, etc. If Passive has to assume operation, there is little or no loss of data. Database synchronization process is called bloxSYNC. Active sends updates to the Passive. -Host names, IP addresses, zones, leases, configuration, etc. If Passive has to assume operation, there is little or no loss of data.
33
© 2013 Unicomp Inc. All Rights Reserved. HA Configuration 33 bloxHA Communication Active and Passive use SSLVPN tunnel for data transfer. - Active node HA interface Passive node Lan interface. - Data is synchronized through this connection. VRRP Advertisements are sent outside the tunnel. - Active node HA interface Passive node HA & Lan interfaces. Lan Port on Active plays minor role. -Used for SSH access, SNMP, syslog, … DNS and DHCP service work on HA port. Active and Passive use SSLVPN tunnel for data transfer. - Active node HA interface Passive node Lan interface. - Data is synchronized through this connection. VRRP Advertisements are sent outside the tunnel. - Active node HA interface Passive node HA & Lan interfaces. Lan Port on Active plays minor role. -Used for SSH access, SNMP, syslog, … DNS and DHCP service work on HA port.
34
© 2013 Unicomp Inc. All Rights Reserved. HA Configuration 34 HA Pair Configuration Edit the Active Device.
35
© 2013 Unicomp Inc. All Rights Reserved. HA Configuration 35 HA Pair Configuration Configure the Vrouter ID, VIP, HA, LAN IP address in Active Device. Configure the Vrouter ID, VIP, HA, LAN IP address in Active Device.
36
© 2013 Unicomp Inc. All Rights Reserved. HA Configuration 36 HA Pair Configuration Edit the Passive Device.
37
© 2013 Unicomp Inc. All Rights Reserved. HA Configuration 37 HA Pair Configuration Default Grid name is “Infoblox”, Default Secret is “test”
38
© 2013 Unicomp Inc. All Rights Reserved. HA Configuration 38 HA Pair Configuration After HA created, login using the VIP
39
© 2013 Unicomp Inc. All Rights Reserved. HA Configuration 39 HA Pair Configuration Check the HA status.
40
© 2013 Unicomp Inc. All Rights Reserved. HA Configuration 40 HA Pair Configuration Check the HA status.
41
© 2013 Unicomp Inc. All Rights Reserved. HA Configuration 41 HA Pair Configuration Check the detailed HA status.
42
© 2013 Unicomp Inc. All Rights Reserved. HA Configuration 42 Breaking the HA Pair After Breaking the HA Pair, the Active will retain the VIP address.
43
© 2013 Unicomp Inc. All Rights Reserved. Grid Configuration 43 Grid is Managed by Grid Master A Grid is a network of Infoblox appliances. Grid Master is administrative center of grid. - Is the only member that you can log into via the GUI. - Functions as library for the grid – backs up all data in grid. - Displays health and services of grid members. - May be a single box or HA pair. A Grid is a network of Infoblox appliances. Grid Master is administrative center of grid. - Is the only member that you can log into via the GUI. - Functions as library for the grid – backs up all data in grid. - Displays health and services of grid members. - May be a single box or HA pair. Master Candidate Only Master Candidates receive a full database.
44
© 2013 Unicomp Inc. All Rights Reserved. Grid Configuration 44 Data Replication Master Candidate Data move from GM only to active Active node Passive node Active updates passive Grid uses two UDP ports for grid communication over VPN. UDP 2114 – Builds the VPN tunnel. UDP 1194 – VPN communication.
45
© 2013 Unicomp Inc. All Rights Reserved. Grid Configuration 45 Grid Failover Master Candidate Member Catastrophic failure of Master : Admin may promote any GMC to Master. You Must manually run CLI command: #set promote_master
46
© 2013 Unicomp Inc. All Rights Reserved. Grid Configuration Building a Grid Buillding the Grid is a two-step process: 1. On the GM, identify the member who are going to join the grid. - In the Grid Management, add members. - Migrate data to members (include zones, networks etc.) 2. Login members via the GUI and “Grid Management > Members” and select “Join Grid” from the Toolbar or SSH to the appliance and run “set membership” CLI command. Alternatively, you can add data to members after they join the grid. Buillding the Grid is a two-step process: 1. On the GM, identify the member who are going to join the grid. - In the Grid Management, add members. - Migrate data to members (include zones, networks etc.) 2. Login members via the GUI and “Grid Management > Members” and select “Join Grid” from the Toolbar or SSH to the appliance and run “set membership” CLI command. Alternatively, you can add data to members after they join the grid.
47
© 2013 Unicomp Inc. All Rights Reserved. Grid Configuration Building a Grid Add members in Master. Add this member to Master Candidate.
48
© 2013 Unicomp Inc. All Rights Reserved. Grid Configuration Building a Grid Add members in Master. Modify the member address.
49
© 2013 Unicomp Inc. All Rights Reserved. Grid Configuration Building a Grid Join Grid via GUI in Members.
50
© 2013 Unicomp Inc. All Rights Reserved. Grid Configuration Building a Grid Check the status of Grid Member. Master Candidate Member
51
© 2013 Unicomp Inc. All Rights Reserved. Agenda 51 Overviews System Setting HA & Grid Setting DNS Overview DNS configuration Others Overviews System Setting HA & Grid Setting DNS Overview DNS configuration Others
52
© 2013 Unicomp Inc. All Rights Reserved. DNS Overview Panel - Zones All zones, sub-zones, forward and reverse-lookup zones and all records are created, viewed, edited and deleted from this tab. This is also the place where DNS views are created and viewed. DNS Views are an advanced topic and covered in the Advanced Administration Course.
53
© 2013 Unicomp Inc. All Rights Reserved. DNS Overview Panel – Members The Members tab is where Member level DNS settings are set, as well as starting/ stopping the DNS services can done. In a grid, all members doing DNS services will be shown here.
54
© 2013 Unicomp Inc. All Rights Reserved. DNS Overview Panel – Name Server Groups - DNS servers can be organized in functional groups. - One server would be designated primary with multiple secondary servers. - Zones/records can be associated with the Name Server Group, and any changes made to those zones/records would be immediately shared with all the servers in the group. - This will save time and effort and reduce the possibility of errors or typos.
55
© 2013 Unicomp Inc. All Rights Reserved. DNS Overview Panel – Shared Record Groups - A group of records can be defined and clustered together in one group. - This group can be “shared” with many zones. - This reduces the number of records that need to be created/edited/deleted. - Saves on the total number of database writes required if each zone had a separate record created and written to the database.
56
© 2013 Unicomp Inc. All Rights Reserved. DNS Overview Panel – Blacklist Rulesets - A set of rules can be defined, based on a blacklist of domains. - Blacklist usually consists of domains that are considered to be not acceptable to be accessed. - The rulesets define actions to be taken should a query for any domain on the blacklist be received.
57
© 2013 Unicomp Inc. All Rights Reserved. DNS Overview Panel – DNS64 Groups - Define a synthesis group, using an IPv6 prefix. - This group is used on an Infoblox appliance to “synthesize” a AAAA record, where none exists, from an IPv4 A record. - This synthesized AAAA record can be used by an IPv6 host to reach an non-IPv6 device. - This mechanism must be used with a NAT64 device.
58
© 2013 Unicomp Inc. All Rights Reserved. Agenda 58 Overviews System Setting HA & Grid Setting DNS Overview DNS configuration Others Overviews System Setting HA & Grid Setting DNS Overview DNS configuration Others
59
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Start the DNS service Select the member and then start the service.
60
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Configure a Forwarder Enterprise Internet Forwarder Forwarding Server - Does internet-bound lookups for other servers - Builds up large cache - Only server to have internet access - Also called caching server
61
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Configure a Forwarder Edit the member to configure the forwarder.
62
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Configure a Forwarder If these DNS servers have no reply, this forwarder would forward query to the root DNS server. Unless check the box labeled “Use Forwarders Only”.
63
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Configure a Zone Transfer Transfer the Zone data from Master to Slave.
64
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Allow Query Access Black/white list.
65
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Allow Recursion Check the box “Allow recursion”.
66
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Viewing Member Statistics
67
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Clearing Member Statistics
68
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Zone Configuration Zone panel is used to create : - Forward mapping zones - Reverse zones - Records - Views Zone panel is used to create : - Forward mapping zones - Reverse zones - Records - Views
69
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Add Authoritative Zone
70
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Add Authoritative Zone
71
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Add Authoritative Zone
72
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Add Authoritative Zone
73
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Add Authoritative Zone Select the member, if there was only one member, it will automatically be listed, then click Add. The stealth option will hide the NS record for the primary name server from DNS queries.
74
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Add Authoritative Zone The new authoritative zone was created. Remember to restart the service.
75
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Add Delegated Zone Create a delegated or sub-zone to an authoritative zone.
76
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Add Delegated Zone
77
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Add Delegated Zone Enter the hostname and IP address of the name server.
78
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Add Delegated Zone The new sub-zone was created.
79
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Record Configuration Click a zone to open it. And add records in the zone. Click a zone to open it. And add records in the zone.
80
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration A Record Configuration Add the hostname and IP address
81
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration A Record Configuration
82
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration MX Record Configuration Mail Exchanger: Enter the fully qualified domain name of the mail exchanger.
83
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration MX Record Configuration
84
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration NS Record Configuration
85
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration NS Record Configuration Must add the DNS server IP address.
86
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration NS Record Configuration The system would be created the A record automatically.
87
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Host Record Configuration - A Host Record is an Infoblox record type. - Provides a convenient method of entering DNS and DHCP information as one entity and not as separate records. - Allow you to enter up four type of data as a single Infoblox object : - A record - PTR record - CNAME record (optional) - MAC address (optional) - Maintains consistency because you are entering/deleting one record.
88
© 2013 Unicomp Inc. All Rights Reserved. DNS Configuration Host Record Configuration DHCP: Select this to enable the DHCP services to manage the host IP address. If you do not select this option, the host IP address is not managed by the DHCP server.
89
© 2013 Unicomp Inc. All Rights Reserved. Agenda 89 Overviews System Setting HA & Grid Setting DNS Overview DNS configuration DNS Others Overviews System Setting HA & Grid Setting DNS Overview DNS configuration DNS Others
90
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Name Server Groups An easier way to assign members to zones is to use Name Server Groups. A Name Server Groups is an alias for a primary server and optionally one or more secondary servers. Makes zone configuration easy – define once and use it over and over. Reduces configuration errors since the definition is performed once. An easier way to assign members to zones is to use Name Server Groups. A Name Server Groups is an alias for a primary server and optionally one or more secondary servers. Makes zone configuration easy – define once and use it over and over. Reduces configuration errors since the definition is performed once. Name Server Group DNS Primary Secondary Servers
91
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Configure Name Server Groups Click Add to create a new group and add members to it.
92
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Configure Name Server Groups Click the “+” button and add a Grid Primary or Secondary. If there are multiple name servers, you will be shown a window with the name servers to choose from. Continue these steps until all name servers that are to be part of the Name Server Group are added.
93
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Configure Name Server Groups When configuring a zone, assign your name server group.
94
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Shared Record Groups Shared Record Groups are groups of DNS records that can be shared by multiple zones and views. - For example, you can create a shared record group called test, add 10 records to it and then import this group into multiple zones. The main advantage : - Reduces effort needed to maintain records across multiple zones. - When updated, Shared Records dynamically update in all associated views and zones. The “Gotcha” : - When using a Shared Record Group, the IP address of each record must be the same in each zone the Shared Record Group in used in. - If you need to change the IP address of a shared record in a zone, you will not be able to use the Shared Record Group in that zone as changing the IP address of a shared record for one zone is not possible!
95
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Shared Record Groups
96
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Shared Record Groups Add a zone by clicking on the zone name. Repeat to add additional zones.
97
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Shared Record Groups Shared Record Groups behave like zones. Records will be shared amongst the group’s zones. Shared Record Groups behave like zones. Records will be shared amongst the group’s zones.
98
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Shared Record Groups Add a shared A record.
99
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Shared Record Groups The A record will be shared amongst the group’s zones
100
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Blacklist Rulesets Blacklisting is usually used to redirects users attempts to get to certain domains which a company may want to deny access to. - For example a user may type: www.badsite.com - And get redirected to: hrpolicy.widget.com This is similar to a NODATA response or a NXDOMAIN Redirection, except that the site for which the data was requested actually exists. Specifically if a Name Server receives a query for an A record that matches a Blacklisted domain name two options exist for response : - Return one or more A records. - Return a Refused response code. If the ruleset contains duplicate domain names, the first rule is loaded and subsequent rules are discarded. Blacklist rules can only be imported through the CSV import feature. Blacklisting is usually used to redirects users attempts to get to certain domains which a company may want to deny access to. - For example a user may type: www.badsite.com - And get redirected to: hrpolicy.widget.com This is similar to a NODATA response or a NXDOMAIN Redirection, except that the site for which the data was requested actually exists. Specifically if a Name Server receives a query for an A record that matches a Blacklisted domain name two options exist for response : - Return one or more A records. - Return a Refused response code. If the ruleset contains duplicate domain names, the first rule is loaded and subsequent rules are discarded. Blacklist rules can only be imported through the CSV import feature.
101
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Configure Blacklist Rulesets
102
© 2013 Unicomp Inc. All Rights Reserved. DNS Others Configure Blacklist Rulesets
103
© 2013 Unicomp Inc. All Rights Reserved.
104
Thank You 104
Similar presentations
© 2025 SlidePlayer.com Inc.
All rights reserved.