Follow these high-level steps to configure the Sensor to detect domain name exceptions and C&C server domains in the DNS response packets.
- Import the Domain Name Exceptions into the Manager. See Manage domain name exceptions.
- Make sure that the latest callback detector file is deployed on the required Sensors. See Manage Botnet Detectors.
- Optionally, configure the TTL for the crafted DNS response packet as well as the sinkhole IPv4 address. See Configure TTL and IP address for DNS sinkholing.
- Enable Domain Name Exceptions detection, DNS Sinkholing, and other advanced callback detection options in the inspection option policies. See Define Advanced Botnet Detection in a Protection Option policy.
- Apply the inspection option policies to the Sensor resources. See Assign a protection option policy to Sensor resources.