Make sure that you have write access to the root admin domain.
You might want to exclude certain domains from DNS-based analysis for callback detection. Include all such domains in the domain name exceptions list in the Manager. You can also use the domain name exceptions list to exclude C&C server domains by the callback detectors.
Create a .csv file, which contains all domains to be included in the domain name exception list.
Sample .csv file.png)
The domain names, which you include in the domain name exceptions can contain any number of levels. However, for levels above the second level, the domain name in the DNS response must exactly match to be exempted.
For example, if the domain name exceptions contain .org, all domain names for which the top-level domain is .org are exempted.
If the domain name exceptions contain ntp.org, all domain names ending with ntp.org are exempted. For example, 1.pool.ntp.org is exempted.
If the domain name exceptions contain pool.ntp.org, the domain name in the DNS response must exactly be pool.ntp.org to be exempted. That is, 1.pol.ntp.org is not exempted.
If the domain name exceptions contain ntp.org and 1.pool.ntp.org, 2.pool.ntp.org is also exempted. If you have ntp.org in the domain name exceptions, you need not include 1.pool.ntp.org in the domain name exceptions.
As a best practice, make sure that you add all your organization's public and internal domain names to the exceptions list. If Trellix is an example, you add
trellix.comto the exception list. Add the last two domain levels for such exceptions. That is, instead ofwww.trellix.com, addtrellix.com. This ensures that Sensor resources are not spent on analyzing DNS traffic of known domains.
In the Manager, select Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → Domain Names.
To manage Callback Detection Exclusions:
To import the domain names from the .csv file, click Other Actions → Import on the Callback Detection Exclusions tab.
Import from CSV window appears. Browse the .csv file. Use the Append option to add a new list of domains or to append a list of domains to an existing list. Use the Replace option to remove the existing list of domains and add a new list from the file being imported. Click Import in the Import from CSV window.
Import Domain Names from a CSV file.png)
The domain names are displayed under the Callback Detection Exclusions tab.
Domain Name — Name of the domain imported
Last updated — Automatically populates the Date and Time when a domain name was imported and the user who imported it
Comment — Enter a comment for the required record names. Double-click the Comment column for a record and type in the comment.
You cannot include the comments in the .csv file when the domain names are imported. You can manually enter them in the Domain Names page.
Imported domain names.png)
To add a single domain to the exclusion list, click
.To locate records in the Domain Names page, enter a string in the Search box.
All records containing the entered string in any of the columns are listed.
Search records.png)
To edit any record, double-click the domain.
You can edit the domain in the Domain Details pane. Click Save.
Edit record.png)
To delete records, select the domain name(s) and click
.To delete all the records, click Other Actions → Delete All.
Delete records.png)
To export the current list of domain name exceptions to a .csv file, click Other Actions → Export All and save the file.
You can also save all the existing domains. Click Save as CSV to save the existing list.
To manage IPS Inspection Exclusions:
To import the domain names from the .csv file, click Other Actions → Import Custom on the IPS Inspection Exclusions tab.
Import from CSV window appears. Browse the .csv file. Use the Append option to add a new list of custom domains or to append a list of custom domains to an existing list. Use the Replace option to remove the existing list of custom domains and add a new list from the file being imported. Click Import in the Import from CSV window.
Import Domain Names from a CSV file.png)
The domain names are displayed under the IPS Inspection Exclusions tab.
State — Current state of the domain - Enabled/Disabled
Domain Name — Name of the domain imported
Domain Type — The type of domain - Default/Custom
Last updated — Automatically populates the Date and Time when a domain name was imported and the user who imported it
Comment — Enter a comment for the required record names. Double-click the Comment column for a record and type in the comment. The comment is automatically saved when you click outside the column.
You cannot include the comments in the .csv file to be included when the domain names are imported. You can only manually enter them in the Domain Names page.
Imported domain names.png)
To add a single domain to the exclusion list, click
.png)
To locate records in the Domain Names page, enter a string in the Search box.
All records containing the entered string in any of the columns are listed.
Search records.png)
To edit any record, double click the domain.
You can edit the domain in the Domain Details pane.
Note
You cannot edit the
Domain Namefor a default domain. You can either enable or disable a default domain name by selecting the domain and selecting the Enabled or Disabled option in the State drop-down list in Domain Details pane.To delete records, select the domain name and click
.To delete all custom records, click Other Actions → Delete All Custom.
Delete records.png)
To export the current list of custom domain name exceptions to a .csv file, click Other Actions → Export All Custom and save the file.
You can also save all the existing domains. Click Save as CSV to save the existing list.
Note
When the datapath processors on the Sensor are experiencing a high number of queued packets to be processed, the traffic from domains in the whitelist is skipped for inspection.