<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Broker VM connection issue in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-connection-issue/m-p/555307#M5037</link>
    <description>&lt;P&gt;Hi Community&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Finally we figured out what caused this issue!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The brokers transmits all HTTP packets to the webproxy with the endpoints IP addresses as source.&lt;BR /&gt;So the webproxy blocked the connections as we only add the brokers IP addresses on the URL whitelist.&lt;/P&gt;
&lt;P&gt;We mainly focused on connections between the brokers and webproxy/internet. However, because webproxy rules apply on application layer, we overlooked this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After activating content caching on the brokers (and tcp443 connections) everything works fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
    <pubDate>Fri, 25 Aug 2023 14:42:59 GMT</pubDate>
    <dc:creator>Rocky-25</dc:creator>
    <dc:date>2023-08-25T14:42:59Z</dc:date>
    <item>
      <title>Broker VM connection issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-connection-issue/m-p/555072#M5031</link>
      <description>&lt;P&gt;Hi Community&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're facing an connection issue with Endpoints using Broker VMs (agent proxy). We opened a TAC case, but it's stuck. There is no useful help yet.&lt;/P&gt;
&lt;P&gt;- Endpoints are isolated from the internet (no direct or webproxy access)&lt;BR /&gt;- Endpoints are registered in Cortex, but doesn't get content updates&lt;BR /&gt;- Live terminal to endpoints is not possible&lt;BR /&gt;- Brokers connect to the internet through a webproxy&lt;BR /&gt;- Webproxy has whitelisted the URLs* (no Authentication, no TLS Interception)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've checked the following:&lt;BR /&gt;- Re-installed agents&lt;BR /&gt;- Re-deployed brokers&lt;BR /&gt;- Connection from endpoints to brokers is successful (tcp8888)&lt;BR /&gt;- Connection from brokers to URLs* is successful (https)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone some useful information or connectivity tests we can run?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*) &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Resources-Required-to-Enable-Access" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Resources-Required-to-Enable-Access&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Best regards&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 14:25:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-connection-issue/m-p/555072#M5031</guid>
      <dc:creator>Rocky-25</dc:creator>
      <dc:date>2023-08-24T14:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM connection issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-connection-issue/m-p/555274#M5036</link>
      <description>&lt;P&gt;Hello Roman,&lt;/P&gt;
&lt;P&gt;We have not came across such scenarios. This case requires TAC intervention.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it is stuck, I would suggest reaching out to Accounts Team to accelerate the progress.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 11:44:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-connection-issue/m-p/555274#M5036</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2023-08-25T11:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM connection issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-connection-issue/m-p/555307#M5037</link>
      <description>&lt;P&gt;Hi Community&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Finally we figured out what caused this issue!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The brokers transmits all HTTP packets to the webproxy with the endpoints IP addresses as source.&lt;BR /&gt;So the webproxy blocked the connections as we only add the brokers IP addresses on the URL whitelist.&lt;/P&gt;
&lt;P&gt;We mainly focused on connections between the brokers and webproxy/internet. However, because webproxy rules apply on application layer, we overlooked this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After activating content caching on the brokers (and tcp443 connections) everything works fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 14:42:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-connection-issue/m-p/555307#M5037</guid>
      <dc:creator>Rocky-25</dc:creator>
      <dc:date>2023-08-25T14:42:59Z</dc:date>
    </item>
  </channel>
</rss>

