Regional Service Domains
Allow access to the Advanced IP Defense regional service domains to enable real-time IP attribute lookups and direct-to-IP detection from your enforcement points.
Advanced IP Defense uses a globally distributed cloud infrastructure to deliver real-time IP attribute lookups and direct-to-IP detection verdicts. When a firewall encounters a connection that requires a cloud lookup, it communicates with the nearest regional service domain over TCP 443 (HTTPS) to retrieve IP attributes and cache them locally. The firewall automatically connects to the closest regional endpoint to minimize lookup latency.
To ensure uninterrupted Advanced IP Defense protection, you must allow outbound HTTPS access from your enforcement points to the Advanced IP Defense service domains listed below. If your environment uses a firewall, proxy, or other network security device that restricts outbound traffic, add these domains to your allow list.
Global Service Domain
The global service domain uses anycast routing to direct traffic to the nearest
available regional endpoint. This is the default endpoint used by all enforcement
points. If your network restricts outbound traffic through a firewall, proxy, or
other security device, add these domains to your network allow list to ensure
enforcement points can reach the Advanced IP Defense cloud service. You cannot
change or modify the cloud server endpoint on the enforcement point.
| Type | Domain |
| Inspection (Global) | api.prod.aipd.service.paloaltonetworks.com (TCP 443) |
| Content Delivery (CDN) | static.prod.aipd.service.paloaltonetworks.com (TCP 443) |
Regional Service Domains
Regional service domains provide localized inspection endpoints. The firewall selects the appropriate regional endpoint based on its configured region or geographic proximity. All regional domains use TCP 443 (HTTPS).
| Location | Domain |
| Johannesburg, South Africa | api-za.prod.aipd.service.paloaltonetworks.com |
| Paris, France | api-fr.prod.aipd.service.paloaltonetworks.com |
| Ashburn, Northern Virginia, USA | api-us-va.prod.aipd.service.paloaltonetworks.com |
| Los Angeles, California, USA | api-us-ca.prod.aipd.service.paloaltonetworks.com |
| Frankfurt, Germany | api-de.prod.aipd.service.paloaltonetworks.com |
| Singapore | api-sg.prod.aipd.service.paloaltonetworks.com |
| Tokyo, Japan | api-jp.prod.aipd.service.paloaltonetworks.com |
| Sydney, Australia | api-au.prod.aipd.service.paloaltonetworks.com |
| London, England | api-uk.prod.aipd.service.paloaltonetworks.com |
| Eemshaven, Netherlands | api-nl.prod.aipd.service.paloaltonetworks.com |
| Council Bluffs, Iowa, USA | api-us-ia.prod.aipd.service.paloaltonetworks.com |
| The Dalles, Oregon, USA | api-us-or.prod.aipd.service.paloaltonetworks.com |
| Montreal, Canada | api-ca.prod.aipd.service.paloaltonetworks.com |
| Osasco, São Paulo, Brazil | api-br.prod.aipd.service.paloaltonetworks.com |
| Mumbai, India | api-in.prod.aipd.service.paloaltonetworks.com |
| Tel Aviv, Israel | api-il.prod.aipd.service.paloaltonetworks.com |
| Seoul, South Korea | api-kr.prod.aipd.service.paloaltonetworks.com |
| Qatar | api-qa.prod.aipd.service.paloaltonetworks.com |
| Hong Kong | api-hk.prod.aipd.service.paloaltonetworks.com |
| China |
The Advanced IP Defense regional service domain in China has two FQDN options:
- api-cn.prod.aipd.service.paloaltonetworks.com
- api-hk.prod.aipd.service.paloaltonetworks.com
Palo Alto Networks recommends using the api-cn.prod.aipd.service.paloaltonetworks.com FQDN. If you experience connectivity or access issues, use the Hong Kong endpoint as a fallback.
|