Infoblox announce NIOS v6.2
Infoblox has released a major update to its NIOSTM software. NIOS version 6.2 provides the following features and enhancements:
Sort List for DNS Views
A sort list prioritizes A and AAAA records on certain networks when those records are included in responses, sorting them to the beginning of the list in the response. Starting with this release, NIOS supports configuring sort lists for DNS views, as well as for Grids and members.
Multi-Grid Management
Infoblox now provides centralized management of multiple Grids. You can now configure a Master Grid from which you can manage and monitor up to 50 individual Grids. For example, you can create multiple Grids by region or functional group, and then control them from the Multi-Grid Manager. The Multi-Grid Manager also provides visibility into your entire IP address space, enabling you to assign IPv4 and IPv6 networks or blocks of networks. You can also monitor the member and service status of the managed Grids. The Grids regularly synchronize their data with the Multi-Grid Manager, ensuring updates in real time.
This feature requires a Multi-Grid Management license. For more information, refer to the Infoblox Multi-Grid Manager Administrator Guide.
IB-4010
The IB-4010 is a high performance network appliance that provides core network services, including DNS (Domain Name System) caching and authoritative services, and IPAM (IP Address Management). The integrated Infoblox approach combines the simplicity of appliances with the power of advanced distributed database technology to control and automate network services, while achieving availability, manageability, visibility, and control unmatched by conventional solutions based on legacy technologies. You configure and manage the IB-4010 through an easy-to-use Infoblox GUI that works seamlessly in Windows, Linux, and Mac environments using standard web browsers. For more information, refer to the Infoblox-4010 Installation Guide.
Advanced DHCP Option Logic
To further control how the NIOS appliance allocates IPv4 addresses, you can now configure Logic Filter and Class Filter lists so the appliance can determine the class statement it writes to the dhcpd configuration file, when to grant or deny a lease to the matching client, and which DHCP options to return to the matching client. You can also create complex match rules that use the AND and OR logic to further define filter criteria in option and NAC filters. The appliance provides an expression builder that automatically builds the rules after you define them.
IF-MAP Client Enhancements for DHCP Servers
When you configure an Infoblox DHCP server as an IF-MAP client, you can now configure the client to publish ip-mac and ipv6-duid metadata for specific leases. You can also define how the IF-MAP server handles the existing ip-mac and ipv6-duid information before the client sends the next update. For example, you can specify the IF-MAP server to always delete existing ip-mac and ipv6-duid information before the next update. With these enhancements, you can also view IF-MAP connection status of an IF-MAP client, create smart folders using the IF-MAP enabled client as a filter criterion, and validate the IF-MAP server certificate.
TACACS+ AAA
You can now configure NIOS to authenticate admins against TACACS+ (Terminal Access Controller Access-Control System Plus) servers, in addition to RADIUS servers and AD domain controllers. TACACS+ provides separate authentication, authorization, and accounting services.
Thales HSM Support
You can integrate a grid with third-party, network-attached Thales Hardware Security Modules (HSMs) for secure private key storage and generation, and zone-signing off-loading. When using a network-attached HSM, you can provide tight physical access control, allowing only selected security personnel to physically access the HSM that stores the DNSSEC keys. When you enable this feature, the HSM performs DNSSEC zone signing, key generation, and key safe keeping.
Forwarders for DNS Views
In addition to defining DNS forwarders for the entire grid and for each grid member, you can now define forwarders for each DNS view. So if you defined a DNS view for different user groups or regions, you can define a different set of forwarders for each DNS view.
Match Destination Views
You can now define a Match Destinations list that identifies destination addresses and TSIG keys that are allowed access to a DNS view. The NIOS appliance can determine which hosts can access a DNS view by matching the destination IP address or TSIG key with its Match Destinations list.
RFC 2317 Exclusion
The Add Delegation wizard now provides an option for performing “strict delegation” while delegating RFC 2317. This allows users to create labels corresponding to IP addresses in the delegated address space in the parent zone.

