<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex Broker Mapper scans in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-broker-mapper-scans/m-p/1229519#M8322</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;the error is :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tlmarques_0-1747764885543.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67689iE2DD133779296EA0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tlmarques_0-1747764885543.png" alt="tlmarques_0-1747764885543.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;in this case is only a test network...&lt;BR /&gt;but normaly we&amp;nbsp;&lt;SPAN&gt;using a /16 range&amp;nbsp;.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 20 May 2025 18:17:25 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2025-05-20T18:17:25Z</dc:date>
    <item>
      <title>Cortex Broker Mapper scans</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-broker-mapper-scans/m-p/1229258#M8314</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We’re experiencing an issue with Cortex brokers related to the network mapper.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;When we run network scans using the "ICMP Echo" flag, the scan completes successfully and everything works as expected.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;However, when performing a "TCP SYN" scan on the following ports:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;80, 443, 22, 21, 25, 53, 23, 110, 123, 135, 137, 139, 143, 3389, 3306, 445, 1433, 161, 5900, 993, 587, 8080, 6660-6669, 5432, 5985, 5986, 636, 9100,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;the result is always a failure.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;On our firewalls and core switches, we’ve already created ACLs allowing any service, but the behavior remains the same.&lt;BR /&gt;&lt;BR /&gt;We have not observed any signs of network congestion. We use multiple monitoring platforms and none have reported any issues.&lt;BR /&gt;&lt;BR /&gt;As for the scanning configuration, we’re currently using a /16 range instead of /24. This is because we manage multiple sites, and each sites contains 50-100 of /24 subnets.&lt;BR /&gt;&lt;BR /&gt;What is the recommended approach for conducting large-scale scans? &lt;BR /&gt;Would it be more efficient or accurate to specify each /24 subnet individually rather than scanning an entire /16?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2025 09:42:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-broker-mapper-scans/m-p/1229258#M8314</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2025-05-16T09:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex Broker Mapper scans</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-broker-mapper-scans/m-p/1229515#M8321</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;Can you please share what kind of error messages you are seeing? Please share the screenshot (hiding any confidential information).&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 17:10:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-broker-mapper-scans/m-p/1229515#M8321</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2025-05-20T17:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex Broker Mapper scans</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-broker-mapper-scans/m-p/1229519#M8322</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;the error is :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tlmarques_0-1747764885543.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67689iE2DD133779296EA0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tlmarques_0-1747764885543.png" alt="tlmarques_0-1747764885543.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;in this case is only a test network...&lt;BR /&gt;but normaly we&amp;nbsp;&lt;SPAN&gt;using a /16 range&amp;nbsp;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 18:17:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-broker-mapper-scans/m-p/1229519#M8322</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2025-05-20T18:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex Broker Mapper scans</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-broker-mapper-scans/m-p/1229628#M8326</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your response. There is a possibility of firewalls blocking broker vm traffic. Please make sure to allow broker vm network resources on your firewalls. Below is the link for all the network FQDNs and IPs required by XDR. You will find resources specific to broker vm under heading "Required for deployments that use Broker VM features".&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Enable-access-to-required-PANW-resources" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Enable-access-to-required-PANW-resources&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If above resources are allowed and still seeing error then open a TAC case to investigate logs for troubleshooting.&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 15:26:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-broker-mapper-scans/m-p/1229628#M8326</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2025-05-21T15:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex Broker Mapper scans</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-broker-mapper-scans/m-p/1230356#M8357</link>
      <description>&lt;P data-start="81" data-end="278"&gt;I have full communication open to and from the broker VM. I spoke with support, and they mentioned that the issue is related to the number of open ports. They recommend a maximum of 20 ports.&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 12:44:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-broker-mapper-scans/m-p/1230356#M8357</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2025-05-29T12:44:14Z</dc:date>
    </item>
  </channel>
</rss>

