<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XDR agent based firewall for locking down communication between DC's&amp;amp;SCCM in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-agent-based-firewall-for-locking-down-communication-between/m-p/343862#M241</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are looking to implement agent based firewall rules to lock down the communication between DC's and SCCM servers we have 20+ of each and I am wondering what is the most feasible way of doing that? User Guide has pretty much no guidance on anything FW related. Any suggestions would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Aug 2020 05:17:56 GMT</pubDate>
    <dc:creator>DmitriPoberejnii</dc:creator>
    <dc:date>2020-08-14T05:17:56Z</dc:date>
    <item>
      <title>XDR agent based firewall for locking down communication between DC's&amp;SCCM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-agent-based-firewall-for-locking-down-communication-between/m-p/343862#M241</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are looking to implement agent based firewall rules to lock down the communication between DC's and SCCM servers we have 20+ of each and I am wondering what is the most feasible way of doing that? User Guide has pretty much no guidance on anything FW related. Any suggestions would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 05:17:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-agent-based-firewall-for-locking-down-communication-between/m-p/343862#M241</guid>
      <dc:creator>DmitriPoberejnii</dc:creator>
      <dc:date>2020-08-14T05:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: XDR agent based firewall for locking down communication between DC's&amp;am</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-agent-based-firewall-for-locking-down-communication-between/m-p/344231#M255</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149850"&gt;@DmitriPoberejnii&lt;/a&gt;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Cortex XDR host-based firewall is IP/port/protocol based as you would find in Windows Firewall.&amp;nbsp; You would have to create entries for the IP's (IPv4 or IPv6) along with the port/protocol information to create the restrictions or allow lists.&amp;nbsp; You would do this under Endpoints &amp;gt; Policy Management &amp;gt; Extensions &amp;gt; Profiles &amp;gt; New Profile &amp;gt; Host Firewall.&amp;nbsp; Once created and saved, you would then apply the entries in your Host Firewall extension profile to an extension policy rule.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/hardened-endpoint-security/host-firewall.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/hardened-endpoint-security/host-firewall.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 19:08:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-agent-based-firewall-for-locking-down-communication-between/m-p/344231#M255</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-08-17T19:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: XDR agent based firewall for locking down communication between DC's&amp;am</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-agent-based-firewall-for-locking-down-communication-between/m-p/344241#M257</link>
      <description>&lt;P&gt;Thank you for trying to help here, unfortunately I cant call it a solution for a few reasons: 1) this document was reviewed prior to posting the question here and it is not complete for many reasons 2) It is not apples to apples comparison with Windows firewall. One example of that would be inability to list IP's in the rules using comma, only ranges or individual IP's. I hope Engineering would change that at some point soon.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 19:35:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-agent-based-firewall-for-locking-down-communication-between/m-p/344241#M257</guid>
      <dc:creator>DmitriPoberejnii</dc:creator>
      <dc:date>2020-08-17T19:35:54Z</dc:date>
    </item>
  </channel>
</rss>

