Resources Required to Enable Access to Cortex XDR
Cortex
XDR
Depending on your network environment settings, you should
enable network access to the Cortex XDR resources.
To Enable
Access to Cortex XDR components, you must allow access to
various Palo Alto Networks resources. If you use the specific Palo
Alto Networks App-IDs indicated in the table, you do not need to
explicitly allow access to the resource. A dash (—) indicates there
is no App-ID coverage for a resource.
Some of the IP addresses required for access are registered
in the United States. As a result, some GeoIP databases do not correctly
pinpoint the location in which IP addresses are used. All customer
data is stored in your deployment region, regardless of the IP address
registration and restricts data transmission through any infrastructure
to that region. For considerations, see Plan
Your Cortex Deployment.
Throughout this topic, refers
to the chosen subdomain of your is
the region in which your
<xdr-tenant>
Cortex
XDR
tenant and <region>
Cortex
Data Lake
is deployed (see Plan
Your Cortex Deployment for supported regions).Refer to the following tables for the FQDNs, IP addresses, ports,
and App-ID coverage for your deployment.
For IP address ranges in GCP, refer to the following
tables for IP address coverage for your deployment:
- https://www.gstatic.com/ipranges/goog.json—Refer to this list to look up and allow access to the IP address ranges subnets.
- https://www.gstatic.com/ipranges/cloud.json—Refer to this list to look up and allow access to the IP address ranges associated with your region.
FQDN | IP Addresses and Port | App-ID Coverage |
---|---|---|
<xdr-tenant> .xdr.<region> .paloaltonetworks.comUsed
to connect to the Cortex XDR management console. | IP address by region.
Port—443 | cortex-xdr |
distributions.traps.paloaltonetworks.com Used
for the first request in registration flow where the agent passes
the distribution id and obtains the ch- of
its tenant<xdr-tenant> .traps.paloaltonetworks.com |
| traps-management-service |
wss://lrc- <region> .paloaltonetworks.comUsed
in live terminal flow. | IP address by region.
Port—443 | cortex-xdr |
panw-xdr-installers-prod-us.storage.googleapis.com Used
to download installers for upgrade actions from the server. This
storage bucket is used for all regions. |
| cortex-xdr |
panw-xdr-payloads-prod-us.storage.googleapis.com Used
to download the executable for live terminal for Cortex XDR agents earlier than version 7.1.0.This
storage bucket is used for all regions. |
| cortex-xdr |
global-content-profiles-policy.storage.googleapis.com Used
to download content updates. |
| cortex-xdr |
panw-xdr-evr-prod- <region> .storage.googleapis.comUsed
to download extended verdict request results in scanning. |
| cortex-xdr |
dc- <xdr-tenant> .traps.paloaltonetworks.comUsed
for EDR data upload. | IP address by region.
Port—443 | traps-management-service |
ch- <xdr-tenant> .traps.paloaltonetworks.comUsed
for all other requests between the agent and its tenant server including
heartbeat, uploads, action results, and scan reports. | IP address by region.
Port—443 | traps-management-service |
api- <xdr-tenant> .xdr. <region> .paloaltonetworks.comUsed
for API requests and responses. | IP address by region.
| — |
cc- <xdr-tenant> .traps.paloaltonetworks.comUsed
for get-verdict requests. | IP address by region.
| traps-management-service |
Broker VM Resources Required
for deployments that use Broker VM features | ||
br- <xdr-tenant> .xdr. <region> .paloaltonetworks.com | IP address by region.
| — |
distributions.traps.paloaltonetworks.com |
| traps-management-service |
| UDP port—123 | — |
App Login and Authentication | ||
identity.paloaltonetworks.com (SSO) |
| — |
login.paloaltonetworks.com (SSO) |
| — |
In-App Help Center and Notifications | ||
data.pendo.io | Port—443 | — |
pendo-static-5664029141630976.storage.googleapis.com | Port—443 | — |
Email Notifications | ||
— | IP address for all regions starting 7th
August 2022—159.183.150.248 IP address by region.
| — |
To Collect 3rd Party Data from
Customer's SaaS and Cloud resources | ||
— | IP address by region.
| cortex-xdr |
Log Forwarding to a Syslog
Receiver | ||
FQDN | IP Addresses and Port | App-ID Coverage |
---|---|---|
distributions-prod-fed.traps.paloaltonetworks.com Used
for the first request in registration flow where the agent passes
the distribution ID and obtains the ch- of
its tenant<xdr-tenant> .traps.paloaltonetworks.com |
| traps-management-service |
wss://lrc-fed.paloaltonetworks.com Used
in live terminal flow. |
| cortex-xdr |
panw-xdr-installers-prod-fr.storage.googleapis.com Used
to download installers for upgrade actions from the server. |
| cortex-xdr |
panw-xdr-payloads-prod-fr.storage.googleapis.com Used
to download the executable for live terminal for Cortex XDR agents
earlier than version 7.1.0. |
| cortex-xdr |
global-content-profiles-policy-prod-fr.storage.googleapis.com Used
to download content updates. |
| cortex-xdr |
panw-xdr-evr-prod-fr.storage.googleapis.com Used
to download extended verdict request results in scanning. |
| cortex-xdr |
app-proxy.federal.paloaltonetworks.com |
| — |
dc- <xdr-tenant> .traps.paloaltonetworks.comUsed
for EDR data upload. |
| traps-management-service |
ch- <xdr-tenant> .traps.paloaltonetworks.comUsed
for all other requests between the agent and its tenant server including
heartbeat, uploads, action results, and scan reports. |
| traps-management-service |
api- <xdr-tenant> .xdr. federal.paloaltonetworks.comUsed
for API requests and responses. |
| — |
cc- <xdr-tenant> .traps.paloaltonetworks.comUsed
for get-verdict requests. |
| traps-management-service |
Broker VM Resources Required
for deployments that use Broker VM features | ||
br- <xdr-tenant> .xdr. federal.paloaltonetworks.com:443 |
| — |
distributions-prod-fed.traps.paloaltonetworks.com |
| traps-management-service |
| UDP port—123 | — |
App Login and Authentication | ||
identity.paloaltonetworks.com (SSO) |
| — |
login.paloaltonetworks.com (SSO) |
| — |
In-App Help Center and Notifications | ||
data.pendo.io | Port—443 | — |
pendo-static-5664029141630976.storage.googleapis.com | Port—443 | — |
To Collect 3rd Party Data from
Customer's SaaS and Cloud resources | ||
— | IP addresses
| cortex-xdr |
Log Forwarding to a Syslog
Receiver | ||
Most Popular
Recommended For You
Recommended Videos
Recommended videos not found.