- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-10-2024 09:54 PM
Hi Team,
I have a query regarding the Cortex XDR Agent (8.3) Certificate Enforcement settings.
1. Enable the Certificate Enforcement option.
2. Decrypt either only Cortex XDR Agent traffic in the firewall or decrypt all traffic related to application servers in the firewall.
Please confirm if these steps are correct, as I have not found comprehensive documentation on this configuration.
09-12-2024 06:13 AM
Hi, I linked this document that shows all the required URLs: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Resourc...
Not only the tenant URL, there are a few more that the agent needs to communicate. If you have PANW NGFW you can see the App-ID Coverage in that doc.
09-11-2024 06:31 AM
Hi @Vinothkumar_SBA, thanks for reaching us using the Live Community.
The Agent Certificate Enforcement is a feature introduced in 8.3 to improve the agent security, by enforcing the use of root CA that is provided by Palo Alto Networks rather than on the local machine. You have more information in the Agents Settings Profile document.
If you have SSL Decryption in your firewall, the FQDNS are still needed to be added as an exception for the XDR Agents. Here you can find the resources to except.
If this post answers your question, please mark it as the solution.
09-11-2024 11:10 PM
Hi Jmazzeo,
Thank you for your response. You mentioned that only the Cortex XDR agent URLs should be added to the FQDN exception list, and not all URLs or other application server URLs. Is my understanding correct or incorrect?
09-12-2024 06:13 AM
Hi, I linked this document that shows all the required URLs: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Resourc...
Not only the tenant URL, there are a few more that the agent needs to communicate. If you have PANW NGFW you can see the App-ID Coverage in that doc.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!