Configure the Broker VM
To set up the broker virtual machine (VM), you need to deploy an image created by Palo Alto Networks on your network or AWS/Azure cloud environments and activate the available applications. You can set up several broker VMs for the same tenant to support larger environments. Ensure each environment matches the necessary requirements.
Before you set up the broker VM, verify you meet the following requirements:
- Hardware: For standard installation use 4-core processor, 8GB RAM, 512GB disk. For Agent Proxy only, you can use 2-core processor.The Broker VM comes with 512GB, you should deploythin provisioning, meaning that the hard disk can grow up to 512GB but will do so only if needed.
- Enable communication between the Broker Service, and other Palo Alto Networks services and apps. Confirm your Cortex XDR version to ensure you enable the appropriate connections.FQDN, Protocol, and PortDescriptionRequired for All Cortex XDR Versions(Default)
UDP port 123NTP server for clock synchronization between the syslog collector and other apps and services. The broker VM provides default servers you can use, or you can define an NTP server of your choice. If you remove the default servers, and do not specify a replacement, the broker VM uses the time of the host ESX.dl.magnifier.paloaltonetworks.comHTTPS over TCP port 443VM and analytics engine package upgrades.pathfinder-docker.magnifier.paloaltonetworks.comHTTPS over TCP port 443VM docker images required by package upgrades.bintray-cdn.paloaltonetworks.comHTTPS over TCP port 443Server used to distribute broker upgrade package.Required for Cortex XDR 2.0 and laterbr-<XDR tenant>.xdr.<region>.paloaltonetworks.comHTTPS over TCP port 443Broker Service server depending on the region of your deployment, eitherusoreu.distributions-prod-us.traps.paloaltonetworks.comHTTPS over TCP port 443Information needed to communicate with your Cortex XDR tenant. Used by tenants deployed in all regions.
Configure your broker VM as follows:
- In Cortex XDR, select.SettingsBrokerVMs
- Generate Tokenand copy to your clipboard.The token is valid only for 24 hours. A new token is generated each time you selectGenerate Token.
- Navigate tohttps://<broker_vm_ip_address>/.
- Log in with the password!nitialPassw0rdand then define your own unique password.The password must contain a minimum of eight characters, contain letters and numbers, and at least one capital letter and one special character.
- Configure your broker VM settings:
- In theNetwork Interfacesection, review the pre-configuredName,IPaddress, andMAC Address, select theAddress Allocation:DHCP(default) orStatic, and select to either toDisableor set asAdminthe network address as the broker VM web interface.
- If you chooseStatic, define the following andSaveyour configurations:
- Default Gateway
- DNS Server
- (Optional) Configure aProxy Server.
- Select the proxyType:HTTP,SOCKS4orSOCKS5
- Enter the proxyAddress,Portand an optionalUserandPassword. Select the pencil icon to enter the password.
- Saveyour configurations.
- (Requires Broker VM 8.0 and later) (Optional) In theNTPsection, configure your NTP servers.
- (Requires Broker VM 8.0 and later) (Optional) In theSSH Accesssection,EnableorDisableSSH connections to the broker VM. SSH access is authenticated using a public key, provided by the user. Using a public key grants remote access to colleagues and Cortex XDR support who the private key. You must haveApp Administratorrole permissions to configure SSH access.To enable connection, generate an RSA Key Pair, enter the public key in theSSH Public Keysection andSaveyour configuration.
- (Requires Broker VM 8.0 and later) (Optional) Collect andDownload Logs. Your XDR logs will download automatically after approximately 30 seconds.
- Registerand enter your uniqueToken, created in Cortex XDR console.Registration of the Broker VM can take up to 30 seconds.You are directed toAfter a successful registration, a registered notification will appear.. TheCortex XDRSettingsBrokerVMsBroker VMspage displays your broker VM details and allows you to edit the defined configurations.
Recommended For You
Recommended videos not found.