<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Broker VM questions in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-questions/m-p/452306#M1346</link>
    <description>&lt;P&gt;Dear Ben-Price,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the role of brokerVM is working like HTTP proxy. not necessary to be in same vlan with you XDR agents unless xdr agent located in private vlan.&amp;nbsp; if a vlan does not have a gateway for routing, yes one of the interface of brokerVM should be in this vlan.&amp;nbsp;&lt;/P&gt;&lt;P&gt;BrokerVM is not router. its not routing TCP packages of agents. its proxying of HTTP requests.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Proxy server on BrokerVM is for parent proxy. if brokerVM cannot able access internet (due to your infrastructure), you can define parent proxy. in that case, agent will connect BrokerVM and BrokerVM will connect parent proxy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internal network configuration is a configuration for avoiding potential conflict with docker network which is located on BrokerVM. By default&amp;nbsp;172.17.0.1/16 subnet is configured for docker containers. If this network conflicting with your internal network, you can set new docker network with this configuration.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Dec 2021 08:26:29 GMT</pubDate>
    <dc:creator>etugriceri</dc:creator>
    <dc:date>2021-12-09T08:26:29Z</dc:date>
    <item>
      <title>Cortex XDR Broker VM questions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-questions/m-p/452206#M1344</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone answer a few questions about Cortex XDR Broker VM?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the Broker VM is being used as a proxy, do the hosts connecting to the Broker VM need to be on the same subnet as the Broker VM or can they communicate with the Broker VM via the default gateway of their VLAN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When defining the proxy server on Broker VM, is the address you assign here the IP address of the Broker VM itself?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone explain the Internal network of the broker VM? Is this the subnet that the container applets use internally on the VM itself or is this something else?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 22:37:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-questions/m-p/452206#M1344</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-12-08T22:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Broker VM questions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-questions/m-p/452306#M1346</link>
      <description>&lt;P&gt;Dear Ben-Price,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the role of brokerVM is working like HTTP proxy. not necessary to be in same vlan with you XDR agents unless xdr agent located in private vlan.&amp;nbsp; if a vlan does not have a gateway for routing, yes one of the interface of brokerVM should be in this vlan.&amp;nbsp;&lt;/P&gt;&lt;P&gt;BrokerVM is not router. its not routing TCP packages of agents. its proxying of HTTP requests.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Proxy server on BrokerVM is for parent proxy. if brokerVM cannot able access internet (due to your infrastructure), you can define parent proxy. in that case, agent will connect BrokerVM and BrokerVM will connect parent proxy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internal network configuration is a configuration for avoiding potential conflict with docker network which is located on BrokerVM. By default&amp;nbsp;172.17.0.1/16 subnet is configured for docker containers. If this network conflicting with your internal network, you can set new docker network with this configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Dec 2021 08:26:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-questions/m-p/452306#M1346</guid>
      <dc:creator>etugriceri</dc:creator>
      <dc:date>2021-12-09T08:26:29Z</dc:date>
    </item>
  </channel>
</rss>

