Denied URL - Broker VM

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Denied URL - Broker VM

L1 Bithead

Hi team!

 

Does anyone have or have had a situation where the applet local agent settings show "Denied url: URL_HERE"? 

 

 Sometimes for short periods of time (around 5 -30 seconds) our broker VMs turn on in red the applet and we can see the message "Denied urls: ch-<xdr-tenant> .traps.paloaltonetworks.com "

The URLs denied are different, sometimes is ch-<xdr-tenant> .traps.paloaltonetworks.com other times is dc-<xdr-tenant>.traps.paloaltonetworks.com or cc-<xdr-tenant>.traps.paloaltonetworks.com

 

As we can see, they are URLs from this documentation: 

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Resources-R...

 

We have allowed all the resources, so, we don't understand why the URLs could be denied. 

 

All comments are very welcome. Thank you!

MarcoA
2 REPLIES 2

L3 Networker

Dear @MarcoMJ , 

 

Thank you for reaching out to Live community. From the description I see that you are seeing access denied for the broker VM for a very short amount of time (5 to 30 seconds), in such situations I would suggest you to please check on the firewall rules if any of these URLs are missing on the whitelist . Also, please check if DNS is working properly and there is no SSL Decryption getting in the way. Thank you. 

 

Also, if you can please confirm if this issue is persistent or does it happen only some times? Thank you.  

 

If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.

Hi Abdrahman, 

I requested to the team verify the firewall rules and they said that everything is fine, all the resources are on the whithelist, also, they verify DNS and is the same situation, is fine. 

MarcoA
  • 464 Views
  • 2 replies
  • 0 Likes
  • 78 Subscriptions
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!