<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Defender Firewall blocking applications in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-defender-firewall-blocking-applications/m-p/381729#M507</link>
    <description>&lt;P&gt;thats interesting. I wish i could see it but we havent engaged it yet unfortunately so i will learn from you. I think SEP like many other vendors actually completely disables the windows firewall? You may have in fact been vulnerable. I think the cortex only engages the rules you choose. Can you put some context on things it might block? This one would seem to explain a little possibly?&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;By default, host firewall profile rules are based on the current location of your device. Configure two sets of rules: a set of&amp;nbsp;&lt;BR /&gt;External Rules&amp;nbsp;that apply when the device is located outside the internal organization network, and a set of&amp;nbsp;&lt;BR /&gt;Internal Rules&amp;nbsp;that apply when the device is located within the internal organization network. If you disable the&amp;nbsp;&lt;BR /&gt;Location Based&amp;nbsp;option, your policy will apply the internal set of rules only, and that will be applied to the device regardless of its location&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jan 2021 21:51:55 GMT</pubDate>
    <dc:creator>JohnSmith7732</dc:creator>
    <dc:date>2021-01-22T21:51:55Z</dc:date>
    <item>
      <title>Windows Defender Firewall blocking applications</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-defender-firewall-blocking-applications/m-p/381690#M506</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;We are moving from Symantec Endpoint Protection (SEP) to Cortex XDR. If you are not familiar with SEP, it has its own firewall built in. When active, Windows Defender only manages a few aspects of the firewall. Since moving to having Cortex manage the firewall, we keep getting pop ups that Windows Defender is blocking some applications. After some discussion with Tech Support, we find out that Cortex XDR uses and API to manage the Windows Firewall.&lt;/P&gt;&lt;P&gt;I have been looking for some documentation on either what I might be missing or some sort of best practice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any insight to what I may be missing or misunderstanding?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 19:32:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-defender-firewall-blocking-applications/m-p/381690#M506</guid>
      <dc:creator>AndrewBowden04</dc:creator>
      <dc:date>2021-01-22T19:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Defender Firewall blocking applications</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-defender-firewall-blocking-applications/m-p/381729#M507</link>
      <description>&lt;P&gt;thats interesting. I wish i could see it but we havent engaged it yet unfortunately so i will learn from you. I think SEP like many other vendors actually completely disables the windows firewall? You may have in fact been vulnerable. I think the cortex only engages the rules you choose. Can you put some context on things it might block? This one would seem to explain a little possibly?&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;By default, host firewall profile rules are based on the current location of your device. Configure two sets of rules: a set of&amp;nbsp;&lt;BR /&gt;External Rules&amp;nbsp;that apply when the device is located outside the internal organization network, and a set of&amp;nbsp;&lt;BR /&gt;Internal Rules&amp;nbsp;that apply when the device is located within the internal organization network. If you disable the&amp;nbsp;&lt;BR /&gt;Location Based&amp;nbsp;option, your policy will apply the internal set of rules only, and that will be applied to the device regardless of its location&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 21:51:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-defender-firewall-blocking-applications/m-p/381729#M507</guid>
      <dc:creator>JohnSmith7732</dc:creator>
      <dc:date>2021-01-22T21:51:55Z</dc:date>
    </item>
  </channel>
</rss>

