<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Auto-Upgrade Best Practices in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/auto-upgrade-best-practices/m-p/538838#M4138</link>
    <description>&lt;P&gt;Hi, I recently created an Agent Settings auto-upgrade profile to test with in Cortex XDR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After creating the profile I created a new policy and then applied it to a small group of endpoints to start with. This worked as expected so I then ramped up to 50, 250 and finally 500 computers. Our environment has almost 16000 endpoints total.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd like to know what Palo thinks is the best practice to now apply that policy to the entire environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it best to replace our default policy with the one I created and then just delete/disable my "test" policy? I will also need to get creative with rolling out to our retail environment since that is the company's bread &amp;amp; butter. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I appreciate your help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Joe&lt;/P&gt;</description>
    <pubDate>Fri, 14 Apr 2023 22:15:29 GMT</pubDate>
    <dc:creator>Joe_Carissimo</dc:creator>
    <dc:date>2023-04-14T22:15:29Z</dc:date>
    <item>
      <title>Auto-Upgrade Best Practices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/auto-upgrade-best-practices/m-p/538838#M4138</link>
      <description>&lt;P&gt;Hi, I recently created an Agent Settings auto-upgrade profile to test with in Cortex XDR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After creating the profile I created a new policy and then applied it to a small group of endpoints to start with. This worked as expected so I then ramped up to 50, 250 and finally 500 computers. Our environment has almost 16000 endpoints total.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd like to know what Palo thinks is the best practice to now apply that policy to the entire environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it best to replace our default policy with the one I created and then just delete/disable my "test" policy? I will also need to get creative with rolling out to our retail environment since that is the company's bread &amp;amp; butter. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I appreciate your help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 22:15:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/auto-upgrade-best-practices/m-p/538838#M4138</guid>
      <dc:creator>Joe_Carissimo</dc:creator>
      <dc:date>2023-04-14T22:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Auto-Upgrade Best Practices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/auto-upgrade-best-practices/m-p/538840#M4139</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/217597"&gt;@Joe_Carissimo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out through LIVEcommunity!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In reference to best practices for agent auto upgrade I think you're on the right track.&amp;nbsp; We'd like all of our customers to be on the lastest available agent versions to ensure they're getting the most out of the agent and it's features.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as best practices for your roll out that's entirely up to you and your organization.&amp;nbsp; The most common issue i'm aware of is some customers reporting bandwidth issues when enabling agent auto upgrade.&amp;nbsp; This is why there's a P2P feature that can be enabled.&amp;nbsp; In this scenario overall bandwidth is decreased because the agents will begin reach out to other agents on the internal network before attempting to reach outside of the network for the new agent download package.&amp;nbsp; If you haven't been having any of these issues I'd say continue to roll this out to the rest of your environment.&amp;nbsp; To ensure you have the proper configuration for Download Source take a look at the image below.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2023-04-14 at 5.25.02 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49496iE6F866A0546EDC56/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2023-04-14 at 5.25.02 PM.png" alt="Screen Shot 2023-04-14 at 5.25.02 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as creating a new policy or using the existing policy I think that's just personal preference.&amp;nbsp; I'd think it would be faster to edit the existing policy as it's already applied to the endpoints you want affected. Once that's done you could just delete the 'test policy'.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope you find this information helpful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 22:28:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/auto-upgrade-best-practices/m-p/538840#M4139</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-04-14T22:28:07Z</dc:date>
    </item>
  </channel>
</rss>

