<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Agent not communicating in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/agent-not-communicating/m-p/577231#M6059</link>
    <description>&lt;P&gt;Hello, If I ask, can you please answer to this question?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The certificate used for decryption was installed as a trusted root CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console. What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?&lt;/P&gt;
&lt;P&gt;a. reinstall the root CA certificate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;b. enable SSL decryption&lt;/P&gt;
&lt;P&gt;c. disable SSL decryption&amp;nbsp;&lt;/P&gt;
&lt;P&gt;d. add paloaltonetworks.com to the SSL Decryption Exclusion list&lt;/P&gt;</description>
    <pubDate>Wed, 14 Feb 2024 07:58:21 GMT</pubDate>
    <dc:creator>JahidAliyev</dc:creator>
    <dc:date>2024-02-14T07:58:21Z</dc:date>
    <item>
      <title>Agent not communicating</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/agent-not-communicating/m-p/577231#M6059</link>
      <description>&lt;P&gt;Hello, If I ask, can you please answer to this question?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The certificate used for decryption was installed as a trusted root CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console. What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?&lt;/P&gt;
&lt;P&gt;a. reinstall the root CA certificate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;b. enable SSL decryption&lt;/P&gt;
&lt;P&gt;c. disable SSL decryption&amp;nbsp;&lt;/P&gt;
&lt;P&gt;d. add paloaltonetworks.com to the SSL Decryption Exclusion list&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 07:58:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/agent-not-communicating/m-p/577231#M6059</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-14T07:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Agent not communicating</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/agent-not-communicating/m-p/577338#M6072</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/274228"&gt;@JahidAliyev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;If you are using SSL decryption on your firewalls then please ensure to exclude below URLs from SSL decryption.&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;FQDN 1&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD rowspan="2"&gt;
&lt;P&gt;&lt;SPAN&gt;Cortex Services&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;*.traps.paloaltonetworks.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;FQDN 2&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;*.xdr.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;region&amp;gt;.&lt;/SPAN&gt;&lt;SPAN&gt;paloaltonetworks.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;FQDN 3&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Cloud Identity Engine Agent&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;agent-directory-sync.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;region&amp;gt;.&lt;/SPAN&gt;&lt;SPAN&gt;paloaltonetworks.com(&lt;/SPAN&gt;&lt;STRONG&gt;FOR US/UK/EU/SG&lt;/STRONG&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;agent-directory-sync.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;region&amp;gt;.apps.&lt;/SPAN&gt;&lt;SPAN&gt;paloaltonetworks.com(&lt;/SPAN&gt;&lt;STRONG&gt;FOR CA/JP/AU/DE/GOV/IN&lt;/STRONG&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please make sure to replace &amp;lt;region&amp;gt; with the actual region of your tenant.&lt;/P&gt;
&lt;P&gt;Also to establish communication between agent and XDR tenant please make sure the list of FQDNs, IPs, ports or App-ids that are mentioned in below document are whitelisted.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Resources-Required-to-Enable-Access" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Resources-Required-to-Enable-Access&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding updation of Trusted CA certificate for Broker VM please follow below link. You will find necessary details under "Configure the Broker VM" section.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Configure-the-Broker-VM" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Configure-the-Broker-VM&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you still face connectivity problem please open a TAC case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please c&lt;SPAN&gt;lick&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 14:00:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/agent-not-communicating/m-p/577338#M6072</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-02-15T14:00:26Z</dc:date>
    </item>
  </channel>
</rss>

