05-24-2023 07:30 AM
First, I do not claim to be a virtual environment expert, but our organization has been running into a problem with VDI and Cortex XDR.
We have had problems with v7.9.1 (or whichever version was released mid-December of last year) to communicate with the management console once all of the steps are completed per Palo's documentation.
After almost 6 months of troubleshooting, we were finally told that, when upgrading, each layer of the environment needs to be cleaned and rid of any Cortex file fragments that are left there. If each layer is not cleaned, this will present fragments of current and previous versions causing performance and communication issues (as put by PA Support). For an organization that has a predominant virtual environment with a lot of additional applications, this is a rather extensive task to perform given the timeframes that new versions are released and held until they go EOL. We've also been told this has to be installed on the OS layer.
My question is what does everyone else do? Do other organizations run into this issue where the agent won't communicate with the management console after a period of time? We've had this running for 4 years and it is now presenting this issue where XDR has injected itself into the other layers and now must be cleaned EACH TIME an upgrade is to be performed.
I appreciate any feedback on this. After 6 months of troubleshooting, this was not really news we wanted to hear. Thank you in advance.
05-24-2023 07:42 AM
I understand you're having issue with VDI and Cortex XDR agent connecting to the management console. It appears that you've been in touch with support, which is great. If you've worked with them for 6 months I'm not sure there's going to be much anyone else can do. I do have a question though. Are you using persistent or non persistent VDI?
05-24-2023 07:44 AM
05-24-2023 07:48 AM
So when you're talking about wiping away all parts of Cortex XDR you're only talking about cleaning the golden image. If that's the case I would just recommend using the cleaner on the golden image when you want to upgrade. You can get the cleaner by talking with support. You may need to open a new case.
I would also recommend trying to stay on the latest version of the Cortex XDR agent as this may alleviate some problems that you're having.
05-24-2023 07:53 AM
We were on the latest version until mid-December 🙂 But no, we've tried using the 8.0 version as well and ran into similar issues. According to support, they told us each layer would need to be cleared of anything Cortex including the golden image. OS layer, app layer, etc.
05-24-2023 08:04 AM
If that's the case I recommend getting the cleaner from support. This completely should remove any traces of the Cortex XDR Agent installation. From there you would create a new installation package and do a clean install.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!