Setup Prerequisites for Enterprise DLP
Focus
Focus
Enterprise DLP

Setup Prerequisites for Enterprise DLP

Table of Contents

Setup Prerequisites for Enterprise DLP

Ports, Fully Qualified Domain Names, and IP addressed required to enable Enterprise Data Loss Prevention (E-DLP).
On May 7, 2025, Palo Alto Networks is introducing new Evidence Storage and Syslog Forwarding service IP addresses to improve performance and expand availability for these services globally.
You must allow these new service IP addresses on your network to avoid disruptions for these services. Review the Enterprise DLP Release Notes for more information.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • Enterprise Data Loss Prevention (E-DLP) license
    Review the Supported Platforms for details on the required license for each enforcement point.
Or any of the following licenses that include the Enterprise DLP license
  • Prisma Access CASB license
  • Next-Generation CASB for Prisma Access and NGFW (CASB-X) license
  • Data Security license
Allow specific secure and functional connections to Enterprise Data Loss Prevention (E-DLP) and supported services. This is required to successfully send traffic for inspection and verdict rendering and to utilize the various services for supported platforms.
  • Enterprise DLP Inline Inspection—Allow the required ports and FQDNs on your network for supported platforms to successfully forward traffic to Enterprise DLP for inspection and verdict rendering.
  • Evidence Storage—Allow access to the region-specific IP addresses to automatically store copies of traffic scanned by Enterprise DLP that match your data profile match criteria. The region-specific IP address you allow on your corporate network depends on the region where you deployed your storage bucket.
    Evidence Storage and Syslog Forwarding services share the same IP addresses.
  • Syslog Forwarding—Allow access to the region-specific IP addresses to enable Enterprise DLP to forward DLP incidents and audit syslogs to your third-party security information and event management (SIEM), Security Orchestration, and Response (SOAR), or other automated ticketing systems.
    Evidence Storage and Syslog Forwarding services share the same IP addresses.
  • FQDNs for EDM—Allow access to all required FQDNs, and region-specific FQDNs, to create and upload Exact Data Matching (EDM) data sets to region-specific or FedRAMP Enterprise DLP storage buckets.
  • End User Coaching—Minimum prerequisite agent, software, and plugin versions to display notifications to your end users in the Access Experience User Interface (UI) when they generate an Enterprise DLP incident.
  • End User Alerting—Required integrations for Enterprise DLP and Cortex XSOAR to use End User Alerting and grant your team members the ability to self-service temporary exemptions for file uploads that match your Enterprise DLP data profile match criteria.

Prerequisite Ports and FQDNs for Enterprise DLP

Allow access to the following IP addresses and open ports required to successfully forward traffic to Enterprise Data Loss Prevention (E-DLP).
FQDNsPorts
  • http://ocsp.paloaltonetworks.com
  • http://crl.paloaltonetworks.com
  • http://ocsp.godaddy.com
  • http://crl.godaddy.com
TCP 80
  • https://api.paloaltonetworks.com
  • https://apitrusted.paloaltonetworks.com
  • certificatetrusted.paloaltonetworks.com
  • certificate.paloaltonetworks.com
  • hawkeye.services-edge.paloaltonetworks.com
  • dlp.hawkeye.services-edge.paloaltonetworks.com
  • ace.hawkeye.services-edge.paloaltonetworks.com
  • urlcat.hawkeye.services-edge.paloaltonetworks.com
  • enforcer-hawkeye.services-edge.paloaltonetworks.com
TCP 443

Prerequisite IP Addresses for Enterprise DLP Evidence Storage

Allow access to the IP addresses required to save evidence for investigative analysis with Enterprise Data Loss Prevention (E-DLP).
  • You must allow the Default IP addresses to successfully connect your evidence storage bucket to Enterprise DLP.
  • To automatically store inspected files of your inspected traffic, the IP addresses you need to allow access for are dependent on the region or zone where Enterprise DLP scans traffic.
  • To download stored files from your evidence storage bucket, you may also need to allow the specific user IP addresses as well. If your organization uses a virtual private network (VPN), you must allow the subnets allowed to download files from your evidence storage bucket.
Enterprise DLP requires that you allow the same IP addresses for Evidence Storage and Syslog Forwarding on your network. You don't need to allow any region-specific IP addresses for Evidence Storage if you have already allowed them for Syslog Forwarding.
RegionIP Address
Date Introduced
Australia
13.54.198.248
April 30, 2022
52.63.9.154
34.87.236.168
May 7, 2025
Canada
15.222.125.234
April 30, 2022
99.79.19.33
34.118.182.133
May 7, 2025
France
15.237.145.165
April 30, 2022
13.36.207.215
34.155.50.15
May 7, 2025
Germany
3.123.172.116
April 30, 2022
52.59.186.42
35.198.73.41
May 7, 2025
India
15.207.246.3
April 30, 2022
3.108.103.214
34.47.134.16
May 7, 2025
Japan
3.115.43.201
April 30, 2022
35.72.148.77
35.74.96.38
52.68.52.77
34.84.142.203
May 7, 2025
Singapore
13.228.151.58
April 30, 2022
52.74.82.77
34.142.217.106
May 7, 2025
Switzerland
34.65.89.231
June 13, 2025
United Kingdom
13.43.141.10
April 30, 2022
18.169.44.228
35.177.5.4
52.56.54.90
(London, England) 35.197.230.50
May 7, 2025
(Default) United States of America
3.230.176.219
April 30, 2022
3.226.106.173
18.190.146.204
3.16.224.253
34.223.123.78
52.27.148.95
34.135.174.89
May 7, 2025
34.173.206.52
34.172.74.250
34.48.104.244
35.197.73.227
34.94.161.165
34.66.246.164
35.225.238.124
35.223.231.169
34.58.60.130
35.238.28.62
34.67.76.48
104.154.217.19
35.202.179.253
34.123.101.142

IP Addresses for Syslog Forwarding

Allow the IP addresses required to forward DLP incident syslogs from Enterprise Data Loss Prevention (E-DLP) to manage and create workflows.
Allow the following IP addresses on your network to successfully forward Enterprise Data Loss Prevention (E-DLP) incidents syslogs to your third-party security information and event management (SIEM), Security Orchestration, and Response (SOAR), or other automated ticketing systems. This enables your SOC Analysts and Incident admins to effectively triage, review, and resolve data security risks that occur in your organization. To forward DLP incident syslogs, the IP addresses you need to allow access for are dependent on region or zone where the file will be scanned by Enterprise DLP.
Evidence Storage and Syslog Forwarding require you allow the same IP addresses on your network. You don't need to allow any region-specific IP addresses for Syslog Forwarding if already allowed for Evidence Storage.
RegionIP Address
Date Introduced
Australia
13.54.198.248
April 30, 2022
52.63.9.154
34.87.236.168
May 7, 2025
Canada
15.222.125.234
April 30, 2022
99.79.19.33
34.118.182.133
May 7, 2025
France
15.237.145.165
April 30, 2022
13.36.207.215
34.155.50.15
May 7, 2025
Germany
3.123.172.116
April 30, 2022
52.59.186.42
35.198.73.41
May 7, 2025
India
15.207.246.3
April 30, 2022
3.108.103.214
34.47.134.16
May 7, 2025
Japan
3.115.43.201
April 30, 2022
35.72.148.77
35.74.96.38
52.68.52.77
34.84.142.203
May 7, 2025
Singapore
13.228.151.58
April 30, 2022
52.74.82.77
34.142.217.106
May 7, 2025
Switzerland
34.65.89.231
June 13, 2025
United Kingdom
13.43.141.10
April 30, 2022
18.169.44.228
35.177.5.4
52.56.54.90
(London, England) 35.197.230.50
May 7, 2025
(Default) United States of America
3.230.176.219
April 30, 2022
3.226.106.173
18.190.146.204
3.16.224.253
34.223.123.78
52.27.148.95
34.135.174.89
May 7, 2025
34.173.206.52
34.172.74.250
34.48.104.244
35.197.73.227
34.94.161.165
34.66.246.164
35.225.238.124
35.223.231.169
34.58.60.130
35.238.28.62
34.67.76.48
104.154.217.19
35.202.179.253
34.123.101.142

Prerequisite FQDNs for Exact Data Matching (EDM)

Fully Qualified Domain Names (FQDN) required to upload data sets for Exact Data Matching (EDM).
To ensure General Data Protection Regulation (GDPR) compliance, the EDM CLI app hashes and encrypts EDM data sets before upload to the Enterprise DLP EDM data set storage bucket. The EDM CLI app first hashes the data set using the SHA256 hash function when you initiate an EDM data set upload. The EDM CLI app then encrypts the EDM data set using AES Symmetric encryption before beginning the EDM data set upload to the Enterprise DLP EDM data set storage bucket. The raw data in your EDM data sets never leave your organization's network, and Enterprise DLP does not store or have access to the raw EDM data set data. Enterprise DLP stores only hashed and encrypted EDM data set data in the EDM data set storage bucket. Review the Enterprise DLP Privacy Datasheet for more information about how Enterprise DLP captures, processes, and stores personal information.
You need to allow the following FQDNs on your network to use EDM:
  • API Egresshttps://api.dlp.paloaltonetworks.com
    Required for commercial and FedRAMP users to allow egress access to Enterprise DLP EDM API and allow EDM functionality on your network.
  • EDM Client Authorizationhttps://auth.apps.paloaltonetworks.com
    Required for Enterprise DLP to authorize EDM client tokens for commercial and FedRAMP users.
  • (FedRAMP High only) FedRAMP High Authorizationhttps://auth.fed.apps.paloaltonetworks.us
    Required by FedRAMP High users to authorize Enterprise DLP EDM functionality on your network.
  • EDM Data Set Uploads—The country-specific Public API URL and Storage Bucket FQDNs where you want EDM data sets stored.
    You must allow both FQDNs to successfully upload hashed and encrypted EDM data sets to an Enterprise DLP storage bucket.
  • Country Storage Buckets
    Country
    Public API URL
    Storage Bucket
    Australia
    https://au-oauth.dss.paloaltonetworks.com
    https://prod-edm-dataset-bucket.s3.ap-southeast-2.amazonaws.com
    Canada
    https://ca-oauth.dss.paloaltonetworks.com
    https://prod-edm-dataset-bucket.s3.ca-central-1.amazonaws.com
    France
    https://fr-oauth.dss.paloaltonetworks.com
    https://prod-edm-dataset-bucket.s3.eu-west-3.amazonaws.com
    Germany
    https://emea-oauth.dss.paloaltonetworks.com
    https://prod-edm-dataset-bucket.s3.eu-central-1.amazonaws.com
    India
    https://in-oauth.dss.paloaltonetworks.com
    https://prod-edm-dataset-bucket.s3.ap-south-1.amazonaws.com
    Japan
    https://jp-saas-oauth.dss.paloaltonetworks.com
    https://prod-edm-dataset-bucket.s3.ap-northeast-1.amazonaws.com
    Singapore
    https://apac-oauth.dss.paloaltonetworks.com
    https://prod-edm-dataset-bucket.s3.ap-southeast-1.amazonaws.com
    Switzerland
    https://sui-oauth.dss.paloaltonetworks.com
    https://prod-edm-dataset-bucket.s3.eu-central-2.amazonaws.com
    United Kingdom
    https://uk-oauth.dss.paloaltonetworks.com
    https://prod-edm-dataset-bucket.s3.eu-west-2.amazonaws.com
    United States
    https://nam-west-oauth.dss.paloaltonetworks.com
    https://prod-edm-dataset-bucket.s3.us-west-2.amazonaws.com
  • FedRAMP Storage Buckets
    Country
    Public API URL
    Storage Bucket
    FedRAMP Impact Level
    United States
    https://apigov.dlp.pubsec-cloud.paloaltonetworks.com
    https://prod-edm-dataset-bucket.us-gov-west-1.amazonaws.com
    Moderate
    United States
    https://api-gov.dlp.paloaltonetworks.com
    https://prod-edm-dataset-bucket.us-gov-west-1.amazonaws.com
    High

Setup Prerequisites for Enterprise DLP End User Coaching

Agent and version minimum prerequisites for Enterprise Data Loss Prevention (E-DLP) End User Coaching to display notifications to your users when they generate DLP incident.
Review GlobalProtect app, Prisma Access Agent, Prisma Access, and Enterprise DLP plugin documentation for detailed information about minimum and recommended versions.
  • Enterprise DLP (Inline)
    Requirement
    GlobalProtect app
    Prisma Access Agent
    Agent Version
    6.2.7 or later
    Palo Alto Networks recommends always installing the latest Prisma Access Agent version.
    Incident Notification
    Autonomous DEM version 5.0.0 or later
    Configuration Management
    Strata Cloud Manager
    Endpoint Operating System for Agent Notification
    • Windows 10 or later
    • macOS 13 or later
    • Ubuntu 20.04, 22.04, or 24.04
    • Red Hat Enterprise Linux (RHEL) 8.9, 9.1, 9.3 or later
    • Windows 10 version 2004 or later
    • macOS 14 (Sonoma) or later
    Prisma Access Version
    5.1 (Preferred or Innovation) or later
    PAN-OS or Prisma Access Dataplane Version
    • PAN-OS 10.2.10-h19
    • PAN-OS 10.2.17 or later
    • PAN-OS 11.1.0 or later release
    • PAN-OS 11.2.6 or later
    • PAN-OS 10.2.10-h19
    • PAN-OS 10.2.17 or later 10.2 release
    • PAN-OS 11.2.6 or later
    Enterprise DLP Plugin Version
    Enterprise DLP plugin 3.0.10 or later
  • Endpoint DLP
    Requirement
    Prisma Access Agent
    Agent Version
    Palo Alto Networks recommends always installing the latest Prisma Access Agent version.
    Incident Notification
    Autonomous DEM version 5.3.4 or later
    Configuration Management
    Strata Cloud Manager
    Endpoint Operating System for Agent Notification
    • Windows 10 version 2004 or later
    • macOS 14 (Sonoma) or later
    Prisma Access Version
    5.1 (Preferred or Innovation) or later
    PAN-OS or Prisma Access Dataplane Version
    • PAN-OS 10.2.10-h19
    • PAN-OS 10.2.17 or later 10.2 version
    • PAN-OS 11.2.6 or later

Prerequisites for Enterprise DLP End User Alerting with Cortex XSOAR

The integrated platforms, supported applications, and configuration prerequisites required to use the Enterprise Data Loss Prevention (E-DLP) End User Alerting with Cortex XSOAR.
Review the Palo Alto Networks product portfolio integration, supported application, and configuration prerequisites required to use Enterprise Data Loss Prevention (E-DLP) End User Alerting with Cortex XSOAR.
Requirements
Panorama (Palo Alto Networks Next-Generation Firewalls)
Prisma Access (Managed by Panorama)
Strata Cloud Manager
PAN-OS Release
  • All PAN-OS versions that support Enterprise DLP
  • All Enterprise DLP plugin versions
N/A
Palo Alto Networks Product Portfolio Integration
Cortex XSOAR
Supported Applications
Slack, Microsoft Teams, Email
IP Mapping to Email Addresses