Cortex XDR Certificate enforcement for Windows and macOS endpoints

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR Certificate enforcement for Windows and macOS endpoints

L3 Networker

Hi Team,

I have a query regarding the Cortex XDR Agent (8.3) Certificate Enforcement settings.

1. Enable the Certificate Enforcement option.
2. Decrypt either only Cortex XDR Agent traffic in the firewall or decrypt all traffic related to application servers in the firewall.

Please confirm if these steps are correct, as I have not found comprehensive documentation on this configuration.

1 accepted solution

Accepted Solutions

Hi, I linked this document that shows all the required URLs: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Resourc...

 

Not only the tenant URL, there are a few more that the agent needs to communicate. If you have PANW NGFW you can see the App-ID Coverage in that doc.

JM

View solution in original post

3 REPLIES 3

L5 Sessionator

Hi @Vinothkumar_SBA, thanks for reaching us using the Live Community.

 

The Agent Certificate Enforcement is a feature introduced in 8.3 to improve the agent security, by enforcing the use of root CA that is provided by Palo Alto Networks rather than on the local machine. You have more information in the Agents Settings Profile document.

 

If you have SSL Decryption in your firewall, the FQDNS are still needed to be added as an exception for the XDR Agents. Here you can find the resources to except.

jmazzeo_0-1726061265467.png

 

If this post answers your question, please mark it as the solution.

JM

Hi Jmazzeo,

Thank you for your response. You mentioned that only the Cortex XDR agent URLs should be added to the FQDN exception list, and not all URLs or other application server URLs. Is my understanding correct or incorrect?

Hi, I linked this document that shows all the required URLs: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Resourc...

 

Not only the tenant URL, there are a few more that the agent needs to communicate. If you have PANW NGFW you can see the App-ID Coverage in that doc.

JM
  • 1 accepted solution
  • 776 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!