Set Up Device Security and Cortex XSOAR for Infoblox Outbound API Integration
Focus
Focus
Device Security

Set Up Device Security and Cortex XSOAR for Infoblox Outbound API Integration

Table of Contents

Set Up Device Security and Cortex XSOAR for Infoblox Outbound API Integration

Configure Cortex XSOAR with an integration instance to set up Device Security to receive real-time Network Change IPv4 events from Infoblox using the Outbound API.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
  • (Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
  • Device Security subscription
  • Precision AI bundle subscription
  • Device Security X subscription
One of the following Cortex XSOAR setups:
  • A free, cohosted, limited-featured Cortex XSOAR instance
    AND
    A free Cortex XSOAR Engine (on-premises integration)
  • A full-featured Cortex XSOAR server
The Infoblox Outbound API integration uses a long-running webhook listener built into the Palo Alto Networks IoT 3rd Party integration instance in Cortex XSOAR. No Cortex XSOAR engine, job, or playbook is required for this integration.
Before configuring the integration instance in Cortex XSOAR, Set Up Infoblox for Outbound API Integration to configure the REST Event Template, Outbound Endpoint, and Notification Rule in Infoblox Grid Manager.
You also need the following information:

Configure Device Security and Cortex XSOAR

  1. Log in to Device Security and then access the Palo Alto Networks IoT 3rd Party instance settings in Cortex XSOAR.
    1. Log in to Device Security and select IntegrationsIntegration ManagementManage Integrations.
      Device Security uses Cortex XSOAR to integrate with the Infoblox Outbound API, and the settings you must configure are in the Cortex XSOAR interface.
    2. Click Launch Cortex XSOAR.
      The Cortex XSOAR interface opens in a new browser tab or window.
    3. Click Settings in the left navigation menu to go to IntegrationsInstances, and search for Palo Alto Networks IoT 3rd Party to locate the integration.
  2. Configure the Palo Alto Networks IoT 3rd Party integration instance.
    The Palo Alto Networks IoT 3rd Party integration instance acts as a shared webhook listener that Device Security uses to receive events from third-party systems. Enabling Long Running Instance starts the webhook server on the configured port so that Infoblox can send Network Change IPv4 events to it.
    1. Click the active integration instance settings icon, or click Add instance, to open the settings panel.
    2. Enter the following settings and leave the others at their default values:
      If you already have an existing integration instance for Palo Alto Networks IoT 3rd Party, you can skip steps 1-5.
      1. Name: Enter a name to help you identify the integration instance for the Infoblox Outbound API.
      2. Server URL: Enter the URL of your Cortex XSOAR server.
      3. Customer ID: Enter the Customer ID.
      4. Access Key: Enter your Device Security API Access Key.
      5. Key ID: Enter your Device Security API Key ID.
      6. Long Running Instance: Enable this setting to start the webhook server.
      7. Long Running Port: Specify the port that you want the webhook listener to use. The default port is 6778.
    3. When finished, click Test or Test resultsRun test to test the integration instance.
      If the test is successful, a Success message appears. If not, check that the settings were entered correctly, and then test the configuration again.
    4. After the test succeeds, click Save & exit to save your changes and close the settings panel.
  3. Enable the Palo Alto Networks IoT 3rd Party integration instance.
    The webhook server starts on the configured port. Infoblox can now send Network Change IPv4 events to Device Security through this endpoint.
    If your Cortex XSOAR deployment requires external systems to reach this endpoint from outside the network, set instance.execute.external = true in your Cortex XSOAR server configuration. Contact your Cortex XSOAR administrator if you are unsure whether this setting is needed.
  4. Return to Device Security and check the status of the Infoblox integration.
    An integration instance can be in one of the following four states, which Device Security displays in the Status column on the Integrations page:
    • Active — the integration was configured and enabled and is functioning properly.
    • Disabled — either the integration was configured but intentionally disabled or it was never configured and a job that references it is enabled and running.
    • Error — the integration was configured and enabled but is not functioning properly, possibly due to a configuration error or network condition.
    • Inactive — the integration was configured and enabled but no job has run for at least the past 60 minutes.
    When you see that the status of an integration instance is Active, its setup is complete.