How to Deliver Upgrades to Endpoints with a Connection Lost Status

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to Deliver Upgrades to Endpoints with a Connection Lost Status

L0 Member

Dear Community,

I am encountering a challenge with the XDR agent upgrades. Although we distribute updates through the Action Center, agents in a "Connection Lost" state are not included as upgrade targets.

In our environment, some devices remain offline for more than 30 days, resulting in them transitioning to a "Connection Lost" state. This is due to our current settings, which mark devices as "Connection Lost" if they haven't connected for 30 days or more.

Is there a method to include agents in the "Connection Lost" state as upgrade targets, aside from automating the agent upgrades? Your insights or suggestions would be greatly appreciated.

Thank you in advance.

2 REPLIES 2

L5 Sessionator

Hi k.imai349842, 

It is normal that if a connection is lost from more than 30 days since for the tenant, those endpoints are not reachable. 
It might be even that some endpoints are switched off or there is no network path to reach them. 

It is a best practice recommended that agents/endpoints are maintained on a regular basis to avoid connection issues in the future from agents that lost connection and were unmanaged long long time ago

 

You can force the reconnection of those endpoints:

C:\Program Files\Palo Alto Networks\Traps\cytool reconnect force
Please check the documentation on cytool 
 

 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.

 

KR, 

Luis

 
 

Hi Luis,

 

Thank you for your response.

I completely agree that regularly maintaining agents and endpoints is crucial. However, in our environment, we have endpoints that repeatedly switch between "Connection Lost" and "Connected" states at 40-day intervals. This presents a challenge when delivering upgrades to those endpoints.

Currently, we are unable to deliver upgrades to endpoints in the "Connection Lost" state via the Cortex web portal.

 

KR,

imai

  • 515 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!