<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyone else having XDR communication problems? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anyone-else-having-xdr-communication-problems/m-p/1264889#M9565</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/358259501"&gt;@C.Hamilton931476&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The distribution ID used must be from an Agent Installer of the same OS and whose version is less or equal to the installed Cortex XDR Agent version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To find the Distribution ID, do the following:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Navigate to Inventory-&amp;gt; Installations&lt;/LI&gt;
&lt;LI&gt;At your top right, you will have three dots symbol, then search and add the field ID&lt;/LI&gt;
&lt;LI&gt;Check the option and use the ID of the package that you have installed in the 'cytool reconnect force distribution_ID' command.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Or&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;You can enter the below command and see the Distribution ID in the Output -&amp;nbsp;&lt;CODE&gt;cytool connectivity_test&amp;nbsp;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;and on&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;"mark this as a Solution"&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;SPAN&gt;Thanks &amp;amp; Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;S. Subashkar Sekar&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Sep 2026 14:54:26 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-09-23T14:54:26Z</dc:date>
    <item>
      <title>Anyone else having XDR communication problems?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anyone-else-having-xdr-communication-problems/m-p/1257665#M9402</link>
      <description>&lt;P&gt;Starting later in the day on June 24, we started seeing endpoints show 'No connection to server' when opening the Cortex console on the endpoint. Endpoint tasks like collect firewall logs, pause protection and live terminal all fail.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some systems shows that they ARE connected to our tenant but trying to live terminal into them fails.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2026 14:18:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anyone-else-having-xdr-communication-problems/m-p/1257665#M9402</guid>
      <dc:creator>G.Stefanov</dc:creator>
      <dc:date>2026-06-29T14:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone else having XDR communication problems?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anyone-else-having-xdr-communication-problems/m-p/1257671#M9403</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170928011"&gt;@G.Stefanov&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The issue you are describing, where endpoints show as "Connected" in the management console but "No connection to server" on the local agent UI while interactive tasks (Live Terminal, log collection, pausing protection) fail, typically stems from a breakdown in the secure WebSocket (WSS) communication channel or an internal agent Inter-Process Communication (IPC) failure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="42" data-start="0" data-section-id="qtzlk3"&gt;Diagnostic Steps on Affected Endpoints:&lt;/H4&gt;
&lt;P data-end="132" data-start="44"&gt;Run the following commands from an elevated Command Prompt to isolate the failure point:&lt;/P&gt;
&lt;P data-end="132" data-start="44"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="163" data-start="134"&gt;1. Verify Service Status:&lt;CODE style="color: #3e3e3e; font-size: 13px; font-weight: normal;"&gt;cytool runtime query&lt;/CODE&gt;&lt;/H4&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="relative h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;Ensure that &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;" data-end="221" data-start="209"&gt;cyserver&lt;/STRONG&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;" data-end="237" data-start="226"&gt;cyverak&lt;/STRONG&gt;&lt;SPAN&gt; are in a &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;" data-end="258" data-start="247"&gt;Running&lt;/STRONG&gt;&lt;SPAN&gt; state.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="265" data-start="197"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="300" data-start="267"&gt;2. Test Network Connectivity:&amp;nbsp;&lt;CODE style="color: #3e3e3e; font-size: 13px; font-weight: normal;"&gt;cytool connectivity_test&lt;/CODE&gt;&lt;/H4&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="relative h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;Review the output for any &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;" data-end="378" data-start="364"&gt;DNS errors&lt;/STRONG&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;" data-end="403" data-start="380"&gt;connection timeouts&lt;/STRONG&gt;&lt;SPAN&gt;, or &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;" data-end="422" data-start="408"&gt;SSL errors&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;3. Verify WebSocket Status:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;cytool websocket query&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="relative h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;Confirm that the output shows:&amp;nbsp;&lt;/SPAN&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;Connected: &lt;SPAN class="ͼy"&gt;true&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;/CODE&gt;&lt;SPAN&gt;If it displays &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;" data-end="670" data-start="650"&gt;Connected: false&lt;/STRONG&gt;&lt;SPAN&gt; or &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;" data-end="711" data-start="674"&gt;No websocket connection available&lt;/STRONG&gt;&lt;SPAN&gt;, the agent is unable to receive real-time commands.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="relative h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;--------------------------&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H4 data-end="805" data-start="770" data-section-id="2rihqp"&gt;Recommended Remediation Actions&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="838" data-start="807"&gt;1. Whitelist Required URLs&lt;/H4&gt;
&lt;P data-end="1042" data-start="839"&gt;Ensure that all regional &lt;STRONG data-end="883" data-start="864"&gt;Cortex XDR URLs&lt;/STRONG&gt;, including &lt;STRONG data-end="917" data-start="895"&gt;wss:// (WebSocket)&lt;/STRONG&gt; connections, are excluded from &lt;STRONG data-end="971" data-start="949"&gt;SSL/TLS decryption&lt;/STRONG&gt; and &lt;STRONG data-end="1008" data-start="976"&gt;Deep Packet Inspection (DPI)&lt;/STRONG&gt; on your network security devices.&lt;/P&gt;
&lt;P data-end="1042" data-start="839"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="1076" data-start="1044"&gt;2. Force Agent Reconnection&lt;/H4&gt;
&lt;P data-end="1205" data-start="1077"&gt;If network connectivity is confirmed but the agent remains out of sync, force a reconnection using the tenant's Distribution ID:&amp;nbsp;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;cytool reconnect force [DISTRIBUTION_ID]&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-end="1205" data-start="1077"&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-end="1205" data-start="1077"&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;
&lt;P data-end="1205" data-start="1077"&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-end="1205" data-start="1077"&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-end="1205" data-start="1077"&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-end="1205" data-start="1077"&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2026 18:17:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anyone-else-having-xdr-communication-problems/m-p/1257671#M9403</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-06-29T18:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone else having XDR communication problems?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anyone-else-having-xdr-communication-problems/m-p/1264888#M9564</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;These instructions are exactly what I'm looking for.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the distribution ID, I have not been able to find a good guide on how to find this information. Can you please provide instructions on how to do so?&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 14:43:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anyone-else-having-xdr-communication-problems/m-p/1264888#M9564</guid>
      <dc:creator>C.Hamilton931476</dc:creator>
      <dc:date>2026-09-23T14:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone else having XDR communication problems?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anyone-else-having-xdr-communication-problems/m-p/1264889#M9565</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/358259501"&gt;@C.Hamilton931476&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The distribution ID used must be from an Agent Installer of the same OS and whose version is less or equal to the installed Cortex XDR Agent version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To find the Distribution ID, do the following:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Navigate to Inventory-&amp;gt; Installations&lt;/LI&gt;
&lt;LI&gt;At your top right, you will have three dots symbol, then search and add the field ID&lt;/LI&gt;
&lt;LI&gt;Check the option and use the ID of the package that you have installed in the 'cytool reconnect force distribution_ID' command.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Or&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;You can enter the below command and see the Distribution ID in the Output -&amp;nbsp;&lt;CODE&gt;cytool connectivity_test&amp;nbsp;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;and on&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;"mark this as a Solution"&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;SPAN&gt;Thanks &amp;amp; Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;S. Subashkar Sekar&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 14:54:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anyone-else-having-xdr-communication-problems/m-p/1264889#M9565</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-09-23T14:54:26Z</dc:date>
    </item>
  </channel>
</rss>

