Enterprise DLP
Prerequisite FQDNs for Exact Data Matching (EDM)
Table of Contents
Expand All
|
Collapse All
Enterprise DLP Docs
Prerequisite FQDNs for Exact Data Matching (EDM)
Fully Qualified Domain Names (FQDN) required to upload data sets for Exact Data
Matching (EDM).
To ensure General Data Protection Regulation (GDPR) compliance, the EDM CLI app hashes
and encrypts EDM data sets before upload to the Enterprise DLP EDM data set storage
bucket. The EDM CLI app first hashes the data set using the SHA256 hash function when
you initiate an EDM data set upload. The EDM CLI app then encrypts the EDM data set
using AES Symmetric encryption before beginning the EDM data set upload to the Enterprise DLP EDM data set storage bucket. The raw data in your EDM data sets
never leave your organization's network, and Enterprise DLP does not store or have
access to the raw EDM data set data. Enterprise DLP stores only hashed and
encrypted EDM data set data in the EDM data set storage bucket. Review the Enterprise DLP
Privacy Datasheet for more information about
how Enterprise DLP captures, processes, and stores personal information.
You need to allow the following FQDNs on your network to use EDM:
- API Egressβhttps://api.dlp.paloaltonetworks.comRequired for commercial and FedRAMP users to allow egress access to Enterprise DLP EDM API and allow EDM functionality on your network.
- EDM Client Authorizationβhttps://auth.apps.paloaltonetworks.comRequired for Enterprise DLP to authorize EDM client tokens for commercial and FedRAMP users.
- (FedRAMP High only) FedRAMP High Authorizationβhttps://auth.fed.apps.paloaltonetworks.usRequired by FedRAMP High users to authorize Enterprise DLP EDM functionality on your network.
- EDM Data Set UploadsβThe country-specific Public API URL and Storage Bucket FQDNs where you want EDM data sets stored.You must allow both FQDNs to successfully upload hashed and encrypted EDM data sets or a data dictionary to an Enterprise DLP storage bucket.
- Country Storage BucketsFor EDM CLI app 3.5 or earlier, allow the region-specific Public API URL and the Default FQDN.For EDM CLI app 4.0 or later, allow the region-specific Public API URL and FQDN.CountryPublic API URLFQDN for EDM CLI App 3.5 or EarlierFQDN for EDM CLI App 4.0 or Later
United States https://nam-west-oauth.dss.paloaltonetworks.com(Default) https://prod-edm-dataset-bucket.s3.us-west-2.amazonaws.comhttps://prod-edm-dataset-bucket-us-west-2.s3.us-west-2.amazonaws.comAustraliahttps://au-oauth.dss.paloaltonetworks.comNot Supportedhttps://prod-edm-dataset-bucket-ap-southeast-2.s3.ap-southeast-2.amazonaws.comCanadahttps://ca-oauth.dss.paloaltonetworks.comNot Supportedhttps://prod-edm-dataset-bucket-ca-central-1.s3.ca-central-1.amazonaws.comFrancehttps://fr-oauth.dss.paloaltonetworks.comNot Supportedhttps://prod-edm-dataset-bucket-eu-west-3.s3.eu-west-3.amazonaws.comGermanyhttps://emea-oauth.dss.paloaltonetworks.comNot Supportedhttps://prod-edm-dataset-bucket-eu-central-1.s3.eu-central-1.amazonaws.com India https://in-oauth.dss.paloaltonetworks.comNot Supportedhttps://prod-edm-dataset-bucket-ap-south-1.s3.ap-south-1.amazonaws.comJapanhttps://jp-saas-oauth.dss.paloaltonetworks.comNot Supportedhttps://prod-edm-dataset-bucket-ap-northeast-1.s3.ap-northeast-1.amazonaws.comSingaporehttps://apac-oauth.dss.paloaltonetworks.comNot Supportedhttps://prod-edm-dataset-bucket-.ap-southeast-1.s3.ap-southeast-1.amazonaws.comSwitzerlandhttps://sui-oauth.dss.paloaltonetworks.comNot Supportedhttps://prod-edm-dataset-bucket-eu-central-2.s3.eu-central-2.amazonaws.comUnited Kingdomhttps://uk-oauth.dss.paloaltonetworks.comNot Supportedhttps://prod-edm-dataset-bucket-eu-west-2.s3.eu-west-2.amazonaws.com - FedRAMP Storage BucketsCountryPublic API URLFQDN for EDM CLI App 3.5 or Earlier
FQDN for EDM CLI App 4.0 or Later FedRAMP Impact LevelUnited States https://apigov.dlp.pubsec-cloud.paloaltonetworks.comhttps://fm-prod-edm-dataset-bucket.s3.us-gov-west-1.amazonaws.comhttps://fm-prod-edm-dataset-bucket-us-gov-west-1.s3.us-gov-west-1.amazonaws.comModerateUnited States https://api-gov.dlp.paloaltonetworks.comhttps://prod-edm-dataset-bucket.s3.us-gov-west-1.amazonaws.comhttps://prod-edm-dataset-bucket-us-gov-west-1.s3.us-gov-west-1.amazonaws.comHigh