TCP Ports and FQDNs Required for Cortex Data Lake
List of FQDNs and ports that you must allow to ensure
connectivity to Cortex Data Lake.
Depending on the platform you are using, you must allow
traffic from different sources to connect to Cortex Data Lake successfully.
Palo
Alto Networks Firewalls
If you are using a Palo Alto Networks
firewall to secure traffic between Panorama, the firewalls, and
Cortex Data Lake, use the following table to identify the App-IDs
and ports to which you must allow traffic to ensure that Panorama
and the firewalls can successfully connect to Cortex Data Lake:
App-IDs | Ports |
---|---|
|
|
For OCSP, you must also allow the firewalls
to access ocsp.paloaltonetworks.com on port 80.
On firewalls
running PAN-OS 9.1.7 or earlier, you also need a Security policy rule
that allows SSL over port 444 to
lic.lc.prod.us.cs.paloaltonetworks.com
.(
PAN-OS
10.0 or later
) If you are sending telemetry data to Cortex
Data Lake, then, in addition to the above App-IDs and ports (except paloalto-logging-service
),
you must allow the following:App-IDs | Ports |
---|---|
|
|
Panorama
FQDNs and Ports used | Description |
---|---|
| Panorama needs to access these FQDNs for
the initial setup and one-time password, and for ongoing certificate
revocation checks. |
Vendor
Firewalls
If you are using another vendor’s firewall,
use the following table to identify the fully qualified domain names
(FQDNs) and ports to which you must allow traffic to ensure that
Panorama and the firewalls can successfully connect to Cortex Data Lake.
FQDNs and Ports used per Region | Description |
---|---|
United States - Americas: *.lc.prod.us.cs.paloaltonetworks.com and
*.cdl.paloaltonetworks.com
| Use the FQDNs that match
the Cortex Data Lake region to which your firewalls and Panorama
connect:
|
Netherlands - Europe: *.lc.prod.eu.cs.paloaltonetworks.com and
*.cdl.paloaltonetworks.com
| |
United Kingdom: *.lc.prod.us.cs.paloaltonetworks.com and
*.cdl.paloaltonetworks.com
| |
Singapore: *.lc.prod.us.cs.paloaltonetworks.com and
*.cdl.paloaltonetworks.com
| |
Canada: *.lc.prod.us.cs.paloaltonetworks.com and
*.cdl.paloaltonetworks.com
| |
Japan: *.lc.prod.us.cs.paloaltonetworks.com and
*.cdl.paloaltonetworks.com
| |
Australia: *.lc.prod.us.cs.paloaltonetworks.com and
*.cdl.paloaltonetworks.com
| |
Germany (DE): *.lc.prod.us.cs.paloaltonetworks.com and
*.cdl.paloaltonetworks.com
| |
India (IN): *.lc.prod.us.cs.paloaltonetworks.com and
*.cdl.paloaltonetworks.com
| |
United States - Government: *.lc.prod.us.cs.paloaltonetworks.com and
*.cdl.paloaltonetworks.com
|
Recommended For You
Recommended Videos
Recommended videos not found.