Connecting Cortex XSOAR to Internal Cloud Hosted Panorama for Prisma Access Integration

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Connecting Cortex XSOAR to Internal Cloud Hosted Panorama for Prisma Access Integration

L1 Bithead

I'm seeking assistance on securely establishing an SSH connection from Cortex XSOAR to Panorama as part of the integration Prisma Access with XSOAR. This integration aims to execute CLI commands on Panorama, which is hosted within Azure (internally). To ensure security and avoid exposing Panorama to the internet, I'm looking for best practices or configurations involving intermediary services or agents within Azure or XSOAR. Any documentation or recommendations on how to securely facilitate this connection would be greatly appreciated.

Cortex XSOAR Prisma Access Azure Panorama 

1 REPLY 1

L1 Bithead

Hello,

It sounds like you will need to leverage an XSOAR engine to allow your XSOAR instance, assuming your instance is hosted, to talk to services within you network. 

In short, an XSOAR Engine is a reverse proxy that maintains an open connection between XSOAR and itself. The engine will initiate all network communication outward, so you will not need to expose any ports. Once the connection has been made, XSOAR is able to use that pipe to execute commands on the engine, and results will be returned back to XSOAR. You can read more about engines here: https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Administrator-Guide/Engines

  • 795 Views
  • 1 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!