The network
cannot run on
a spreadsheet.
DNS, DHCP and IP address management are the three services everything else assumes are working. Kubernesis DDI puts them under one control plane, discovers what is actually out there, and blocks the DNS traffic attackers depend on.
— The situation
Every enterprise has an IPAM.
Most of them are a spreadsheet.
It was accurate the day it was made. Then a project team stood up a subnet, a contractor plugged into a port, a cloud account created a zone, and somebody left. Now the address space has holes nobody can account for, DHCP scopes overlap in two branches, and the only person who understands the DNS estate is on notice.
DDI replaces that with a system of record that updates itself, because it is the thing actually handing out the addresses.
— Capabilities
What you get.
Unified DNS
Authoritative and recursive DNS for internal and external zones, on-prem and cloud, managed from one place.
DHCP with real scopes
Lease management, failover pairs and scope utilisation you can see before you run out of addresses, not after.
IPAM that stays true
Network discovery
Scheduled and event-driven discovery across subnets, switches and cloud accounts, so the inventory finds what nobody declared.
Protective DNS
Queries to known command-and-control, phishing and newly registered domains are blocked at resolution, before a session is ever established.
Cloud zone sync
Route 53, Azure DNS and Cloud DNS zones discovered and reconciled against the internal estate.
Automation and API
Provisioning hooks so a new VM gets its record without a ticket, and a REST API for everything the console does.
High availability
HA pairs per site with automatic failover, because DNS going down is an outage of everything at once.
— Protective DNS
The cheapest control you
are not using.
Malware has to resolve a name before it can call home. Blocking at the resolver stops the session earlier and cheaper than any inline appliance, and it covers devices no agent is installed on — IoT, OT, printers, the vendor’s laptop.
- Command-and-control domains blocked before the connection opens
- Newly registered and lookalike domains held by policy
- DNS tunnelling and exfiltration detected on query pattern
- Blocks attributed to a device and an owner, not just an IP
- Works for unmanaged and agentless devices on the same network
- Query logs forwarded to your SIEM in the format it expects
— Deployment
How it lands.
| SITE TYPE | RECOMMENDED | NOTES |
|---|---|---|
| Data centre / HQ | HA appliance pair | Authoritative zones, primary DHCP, grid master |
| Large branch | Virtual pair | Local DHCP survivability if the WAN drops |
| Small branch | Single virtual node | Caching and forwarding, leases from the core |
| Cloud VPC | Cloud instance | Zone sync and discovery per account |