<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Host Firewall behavior Question in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-firewall-behavior-question/m-p/542404#M4366</link>
    <description>&lt;P&gt;Hi Neelrohit,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So in case we have rules applied on the Native Windows Firewall, we will need to migrate and apply the same rules on Cortex XDR to achieve the same configuration?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ammar,&lt;/P&gt;</description>
    <pubDate>Wed, 17 May 2023 05:59:25 GMT</pubDate>
    <dc:creator>AmmarJi</dc:creator>
    <dc:date>2023-05-17T05:59:25Z</dc:date>
    <item>
      <title>Cortex XDR Host Firewall behavior Question</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-firewall-behavior-question/m-p/542376#M4364</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to configure host firewall using Cortex XDR, in the documentation, it mentions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;EM&gt;The&amp;nbsp;&lt;SPAN class="phrase"&gt;Cortex XDR&lt;/SPAN&gt;&amp;nbsp;host firewall rules leverage the operating system firewall APIs and enforce these rules on your endpoints, but not your Windows or Mac firewall settings.&lt;/EM&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;EM&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Device-Control" target="_blank"&gt;Device Control • Cortex XDR Prevent Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;Which I understood that it will not affect the Local Windows Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I proceeded with configuring following the steps, and once I created a profile rule, I got the below message:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;U&gt;&lt;STRONG&gt;You have assigned a non-default HFW profile. This will move control from Windows FW to Cortex HFW and Windows firewall rules will no longer apply (agent version 7.5 and above).&lt;/STRONG&gt;&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this mean that it will disable Windows built-in firewall? Since I willing to run Cortex Firewall to be applied only on external network for certain IPs. Will this disable all the rules applied by Windows Local Firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Ammar&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2023 22:04:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-firewall-behavior-question/m-p/542376#M4364</guid>
      <dc:creator>AmmarJi</dc:creator>
      <dc:date>2023-05-16T22:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Host Firewall behavior Question</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-firewall-behavior-question/m-p/542398#M4365</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/257307"&gt;@AmmarJi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we talk about using the host firewall using Cortex XDR, the agent uses the same APIs used by Windows Native host firewall ie. the Windows filtering platform. Because we blend well with native environment on the Windows side, we use the same APIs and as a result, we disable the Windows firewall as a feature. This means that the rules on the Windows native firewall will be disabled once the rules on Cortex XDR host firewall is activated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this answers your query.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 04:36:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-firewall-behavior-question/m-p/542398#M4365</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-05-17T04:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Host Firewall behavior Question</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-firewall-behavior-question/m-p/542404#M4366</link>
      <description>&lt;P&gt;Hi Neelrohit,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So in case we have rules applied on the Native Windows Firewall, we will need to migrate and apply the same rules on Cortex XDR to achieve the same configuration?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ammar,&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 05:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-firewall-behavior-question/m-p/542404#M4366</guid>
      <dc:creator>AmmarJi</dc:creator>
      <dc:date>2023-05-17T05:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Host Firewall behavior Question</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-firewall-behavior-question/m-p/542405#M4367</link>
      <description>&lt;P&gt;That is correct. If you have windows native firewall rules enabled, you might want to import those and add it to Cortex XDR host firewall rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 06:05:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-firewall-behavior-question/m-p/542405#M4367</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-05-17T06:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Host Firewall behavior Question</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-firewall-behavior-question/m-p/542410#M4368</link>
      <description>&lt;P&gt;Thank you for the answer.&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 06:22:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-firewall-behavior-question/m-p/542410#M4368</guid>
      <dc:creator>AmmarJi</dc:creator>
      <dc:date>2023-05-17T06:22:19Z</dc:date>
    </item>
  </channel>
</rss>

