Response Action

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Response Action

L3 Networker

There is an option Response Action under agent configuration, which means we can allow access to a certain application in case the endpoint is isolated.

 

Which application access should ideally be provided in it.

 

Thanks

1 accepted solution

Accepted Solutions

L4 Transporter

Hello @Shahwaz_Md 

 

Thanks for reaching out to Live Community.

 

When you isolate an endpoint, it will halt all network traffic except for cortex XDR traffic. "Response Actions" feature under Agent settings profile allow you to add specific applications to be allowed in case of Network Isolation.

Allowing a specific application depends on the customer environment and use cases. There is no recommendation from our side. 

For example, 

  • (Windows) For VDI sessions, using the network isolation response action can disrupt communication with the VDI host management system thereby halting access to the VDI session. As a result, before using the response action you must add the VDI processes and corresponding IP addresses to your allow list.

  • Some customer may want Windows Update service to continue to work even in isolation.
  • Some may want to allow access to some other security tool e.g. DLP.

Please keep network access to bare minimum in case of Isolation to restrict attacker’s mobility on your network. Below is the link for your reference.

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Respons...

 

View solution in original post

1 REPLY 1

L4 Transporter

Hello @Shahwaz_Md 

 

Thanks for reaching out to Live Community.

 

When you isolate an endpoint, it will halt all network traffic except for cortex XDR traffic. "Response Actions" feature under Agent settings profile allow you to add specific applications to be allowed in case of Network Isolation.

Allowing a specific application depends on the customer environment and use cases. There is no recommendation from our side. 

For example, 

  • (Windows) For VDI sessions, using the network isolation response action can disrupt communication with the VDI host management system thereby halting access to the VDI session. As a result, before using the response action you must add the VDI processes and corresponding IP addresses to your allow list.

  • Some customer may want Windows Update service to continue to work even in isolation.
  • Some may want to allow access to some other security tool e.g. DLP.

Please keep network access to bare minimum in case of Isolation to restrict attacker’s mobility on your network. Below is the link for your reference.

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Respons...

 

  • 1 accepted solution
  • 900 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!