If you already have a full-featured Cortex XSOAR server deployed on premises
or in the cloud, you can use that to integrate Device Security with
third-party systems. For the Cortex XSOAR server to support
Device Security third-party integrations, you must install a Device Security
content pack and configure an integration instance on the XSOAR server. The content
pack provides XSOAR with all the third-party integration instance settings,
playbooks, and jobs that Device Security requires, and the Palo Alto Networks IoT
3rd Party integration instance allows XSOAR to establish a permanent web socket
connection with the Device Security application.
The Cortex XSOAR server continues to provide the same functionality it did before it was
set up to work with Device Security. However, the Device Security integrations
the XSOAR server supports are limited to those in the content pack you install. The
content pack has the same set of integrations that a cohosted XSOAR instance has
with one exception: you can modify the playbooks for Device Security integrations
on an XSOAR server but not on a cohosted instance. To be precise, you can’t modify
the playbooks directly, but you can duplicate them, modify the duplicate playbooks,
and then use those on the server, which is something you can’t do in a cloud-hosted
instance.
When integrating
Device Security with third-party systems in a deployment
that must comply with FedRAMP Moderate, you must use a full on-premises
Cortex XSOAR server running a vendor-approved
FIPS version that complies with the
FIPS 140-2 standard. This option supports all the same
Device Security integrations as the cohosted version but is FIPS compliant.
The Device Security web interface (and the documentation) refer to this as
a full-featured Cortex XSOAR server,
which is a useful way to distinguish it from a cohosted Cortex XSOAR instance.
Nevertheless, the XSOAR server only needs to be deployed on premises to comply
with FedRAMP regulations. If your deployment doesn’t need to be FedRAMP
compliant, you can deploy the XSOAR server on premises or in the cloud. In
either case, the XSOAR server connects to Device Security in the same way.