<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR - Operations for an offline agent (isolated from internet access) - Concerns regarding installation and updates. in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-operations-for-an-offline-agent-isolated-from/m-p/413210#M799</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello Orkan,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your input, but since the goal is offline operation, a proxy solution does not meet the customer requirements for this scenario.&lt;BR /&gt;I assume I will need to ask Palo Alto Support to advise on that matter further.&lt;BR /&gt;&lt;BR /&gt;I wish you a great day!&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jun 2021 12:33:05 GMT</pubDate>
    <dc:creator>A_Adamski</dc:creator>
    <dc:date>2021-06-15T12:33:05Z</dc:date>
    <item>
      <title>Cortex XDR - Operations for an offline agent (isolated from internet access) - Concerns regarding installation and updates.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-operations-for-an-offline-agent-isolated-from/m-p/412403#M790</link>
      <description>&lt;P&gt;Dear Palo Alto Community Members,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope you will be able to help me out or point me in the correct direction.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm struggling to find appropriate information about the operations for a cortex agent which will not be connected to the internet and will never be able to communicate with the cloud (Cortex XDR).&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my customer scenario, the machine is not and will never be connected to the internet. Therefore the agent will never be able to connect to Cortex XDR, not even during/right after installation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While we could find a way to use the Content.zip which is available for download from the PA support portal alongside the installer itself, we are not sure about a way to export policies from Cortex XDR to feed them manually into the “offline” agent.&lt;/P&gt;&lt;P&gt;We are also not sure about the license considerations, and the only piece of information I have found was informed that after 30 days when&amp;nbsp;the endpoint has not communicated with Cortex Console we should see 'Connection Lost' notification.&lt;BR /&gt;But I doubt it could actually be even something we will see in our scenario, as the agent will never communicate with the console.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;After some digging through the documentation we've come across&amp;nbsp;information about the Cytool which might help to import/export the policies (for Windows and Linux machines).&lt;BR /&gt;As I understand, in theory, I could import the policies from one agent and then export them to another one, is that correct?&lt;/P&gt;&lt;P&gt;Unfortunately, I do not have any options to test it and I'm wondering if anyone had a chance to do it already, or maybe had some experience with a similar scenario and could share some thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will really appreciate some help on this one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 17:18:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-operations-for-an-offline-agent-isolated-from/m-p/412403#M790</guid>
      <dc:creator>A_Adamski</dc:creator>
      <dc:date>2021-06-10T17:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - Operations for an offline agent (isolated from internet access) - Concerns regarding installation and updates.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-operations-for-an-offline-agent-isolated-from/m-p/412732#M794</link>
      <description>&lt;P&gt;Hello Adamski.&lt;/P&gt;&lt;P&gt;You can use proxy communication for Cortex XDR agents to connecting Cortex XDR app. For that you must install Cortex Broker VM (&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/broker-vm/set-up-broker-vm.html#:~:text=The%20Palo%20Alto%20Networks%20Broker,logs%20and%20files%20for%20analysis." target="_self"&gt;about Broker VM&lt;/A&gt;). After installation enable &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/broker-vm/set-up-broker-vm/activate-the-agent-proxy-for-closed-networks.html#id4daac0ca-f041-4ff3-a0d4-ee4c3220cf65" target="_self"&gt;Agent proxy settings.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jun 2021 18:04:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-operations-for-an-offline-agent-isolated-from/m-p/412732#M794</guid>
      <dc:creator>OrkanAlibayli</dc:creator>
      <dc:date>2021-06-12T18:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - Operations for an offline agent (isolated from internet access) - Concerns regarding installation and updates.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-operations-for-an-offline-agent-isolated-from/m-p/413210#M799</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello Orkan,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your input, but since the goal is offline operation, a proxy solution does not meet the customer requirements for this scenario.&lt;BR /&gt;I assume I will need to ask Palo Alto Support to advise on that matter further.&lt;BR /&gt;&lt;BR /&gt;I wish you a great day!&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 12:33:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-operations-for-an-offline-agent-isolated-from/m-p/413210#M799</guid>
      <dc:creator>A_Adamski</dc:creator>
      <dc:date>2021-06-15T12:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - Operations for an offline agent (isolated from internet access) - Concerns regarding installation and updates.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-operations-for-an-offline-agent-isolated-from/m-p/413523#M801</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case if anyone will need this info in the future:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've checked this with the Palo Alto Support and it turned out that, &lt;STRONG&gt;The XDR does not support the fully offline environment.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The XDR requires network communication for the agent management purpose:&amp;nbsp;&lt;A title="Cortex XDR for windows requirements" href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-4/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/cortex-xdr-for-windows-requirements.html" target="_self"&gt;Cortex XDR for windows - requirements&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Agent installation option for the Content Update package is to reduce the network bandwidth for the initial Agent installation. But the agent must be able to connect to the XDR Cloud for the registration, license allocation, Policy Rule's acquirement and etc. Therefore, the XDR does not support the fully closed network environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;But we still have some options, and might try reaching out to our SE and ask for deployment options&amp;nbsp;or Palo Alto's account team to submit a New Feature Request (NFR).&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;Hope this info helps those who seek an answer to the same question &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Have a great one!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 10:03:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-operations-for-an-offline-agent-isolated-from/m-p/413523#M801</guid>
      <dc:creator>A_Adamski</dc:creator>
      <dc:date>2021-06-16T10:03:50Z</dc:date>
    </item>
  </channel>
</rss>

