<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR Connection method in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-connection-method/m-p/1222532#M7999</link>
    <description>&lt;P data-start="76" data-end="287"&gt;Hi, While monitoring network traffic during our deployment, we noticed that all traffic between the endpoint and the &lt;STRONG data-start="185" data-end="199"&gt;XDR portal&lt;/STRONG&gt; (&lt;CODE data-start="201" data-end="249"&gt;&amp;lt;xdr-tenant&amp;gt;.xdr.&amp;lt;region&amp;gt;.paloaltonetworks.com&lt;/CODE&gt;) is &lt;STRONG data-start="254" data-end="284"&gt;one-directional (outbound)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-start="76" data-end="287"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="289" data-end="515"&gt;We have &lt;STRONG data-start="297" data-end="322"&gt;private Linux servers&lt;/STRONG&gt; in a &lt;STRONG data-start="328" data-end="376"&gt;separate environment with no internet access&lt;/STRONG&gt;. However, after deploying the agent and reviewing firewall logs, we did not observe any traffic from the &lt;STRONG data-start="482" data-end="512"&gt;endpoint to the XDR portal&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-start="289" data-end="515"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="517" data-end="678"&gt;Could someone provide more details on how the &lt;STRONG data-start="563" data-end="598"&gt;connection works on the backend?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-start="517" data-end="678"&gt;&lt;STRONG data-start="563" data-end="598"&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Mar 2025 12:33:53 GMT</pubDate>
    <dc:creator>A.Alharbi095930</dc:creator>
    <dc:date>2025-03-04T12:33:53Z</dc:date>
    <item>
      <title>Cortex XDR Connection method</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-connection-method/m-p/1222532#M7999</link>
      <description>&lt;P data-start="76" data-end="287"&gt;Hi, While monitoring network traffic during our deployment, we noticed that all traffic between the endpoint and the &lt;STRONG data-start="185" data-end="199"&gt;XDR portal&lt;/STRONG&gt; (&lt;CODE data-start="201" data-end="249"&gt;&amp;lt;xdr-tenant&amp;gt;.xdr.&amp;lt;region&amp;gt;.paloaltonetworks.com&lt;/CODE&gt;) is &lt;STRONG data-start="254" data-end="284"&gt;one-directional (outbound)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-start="76" data-end="287"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="289" data-end="515"&gt;We have &lt;STRONG data-start="297" data-end="322"&gt;private Linux servers&lt;/STRONG&gt; in a &lt;STRONG data-start="328" data-end="376"&gt;separate environment with no internet access&lt;/STRONG&gt;. However, after deploying the agent and reviewing firewall logs, we did not observe any traffic from the &lt;STRONG data-start="482" data-end="512"&gt;endpoint to the XDR portal&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-start="289" data-end="515"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="517" data-end="678"&gt;Could someone provide more details on how the &lt;STRONG data-start="563" data-end="598"&gt;connection works on the backend?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-start="517" data-end="678"&gt;&lt;STRONG data-start="563" data-end="598"&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 12:33:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-connection-method/m-p/1222532#M7999</guid>
      <dc:creator>A.Alharbi095930</dc:creator>
      <dc:date>2025-03-04T12:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Connection method</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-connection-method/m-p/1222795#M8007</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/848744293"&gt;@A.Alharbi095930&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By default in the Agent Settings profile, the agents will try to get the Content Updates from other agents using P2P, then Broker VM if there is any, and then goes to the tenant over internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1741189135856.png" style="width: 596px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66387iA81FBFACBE76F9BC/image-dimensions/596x155?v=v2" width="596" height="155" role="button" title="jmazzeo_0-1741189135856.png" alt="jmazzeo_0-1741189135856.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If there is another agent in the same network with the CU downloaded, it will be shared.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have more information in &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Set-up-agent-settings-profiles" target="_self"&gt;this document&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 15:42:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-connection-method/m-p/1222795#M8007</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2025-03-05T15:42:03Z</dc:date>
    </item>
  </channel>
</rss>

