- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-22-2024 03:25 AM
I'm seeking assistance on securely establishing an SSH connection from Cortex XSOAR to Panorama as part of the integration Prisma Access with XSOAR. This integration aims to execute CLI commands on Panorama, which is hosted within Azure (internally). To ensure security and avoid exposing Panorama to the internet, I'm looking for best practices or configurations involving intermediary services or agents within Azure or XSOAR. Any documentation or recommendations on how to securely facilitate this connection would be greatly appreciated.
02-22-2024 06:57 AM
Hello,
It sounds like you will need to leverage an XSOAR engine to allow your XSOAR instance, assuming your instance is hosted, to talk to services within you network.
In short, an XSOAR Engine is a reverse proxy that maintains an open connection between XSOAR and itself. The engine will initiate all network communication outward, so you will not need to expose any ports. Once the connection has been made, XSOAR is able to use that pipe to execute commands on the engine, and results will be returned back to XSOAR. You can read more about engines here: https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Administrator-Guide/Engines
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!