Cortex XDR Delayed Global Protect Connection Timing.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR Delayed Global Protect Connection Timing.

L0 Member

We are transitioning from MDE to Cortex XDR and a number of users have stated that connection time takes from 2-10mins to take place after a full reboot / cold start.

This is inconsistent.

MDE is currently in EDR in BlockMode - which was the advice given to be the correct status during transition in that it is in Passive mode on those specific endpoints.

The user logs into their device, attempts to connect to GP, the connection either takes substantially longer than non XDR endpoints, or fails to connect then establishes on the second try.

We have some operational exclusions in, as well as some SUex provided by TAC, but so far no consistent improvement has been made.

1 REPLY 1

L6 Presenter

Hello @RobKen ,

 

Greetings for the day.

 

The reported 2–10 minute connection delay and inconsistent GlobalProtect (GP) connectivity after a cold start are commonly associated with resource contention during the Windows boot sequence, especially when Cortex XDR coexists with other security products such as Microsoft Defender for Endpoint (MDE).

 

Potential Root Causes:

  • Heartbeat Interval: The Cortex XDR agent checks in every 5 minutes. If network services (DNS, Proxy, or Wi-Fi) are not ready during startup, the next connection attempt may be delayed until the next heartbeat.
  • Resource Contention with MDE: Running Cortex XDR alongside Microsoft Defender for Endpoint (Passive or EDR Block Mode) can increase CPU usage (cyserver.exe) during boot, delaying services like GlobalProtect and MFA.
  • Network Initialization: If the agent checks the network location before the network stack is fully initialized, it may temporarily apply an External firewall policy, affecting GlobalProtect connectivity until the next successful check.
  • CRL/WildFire Checks: Certificate validation (CRL) and WildFire verdict requests during startup can introduce additional delays if network responses are slow.

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".

 

Thanks & Regards,
S. Subashkar Sekar

  • 38 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!