> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources/fedramp-and-the-us-federal-government-required-resources.md).

# FedRAMP and the US Federal Government required resources

The following table lists the required resources for the federal government of the United States, including FQDNs, IP addresses, ports, and App-ID coverage for your deployment:

#### Egress and engine resources

All ports are 443 unless otherwise specified.

| Source                   | Compliance level                     | IP Addresses                         |
| ------------------------ | ------------------------------------ | ------------------------------------ |
| Egress                   | FedRAMP Moderate                     | 34.122.220.113, 35.223.83.172        |
| FedRAMP High             | 34.136.155.252, 34.133.46.50         |                                      |
| Outbound IPs for Engines | FedRAMP Moderate                     | 34.123.127.174:443, 34.71.135.18:443 |
| FedRAMP High             | 34.123.153.175:443, 35.223.253.2:443 |                                      |

#### Core Cortex Cloud communication

These resources handle agent registration, heartbeats, data uploads, and API connections. All ports are 443 unless specified otherwise.

| Resource/Function                                                                                                                                                                                                                                                                                          | FQDN                                                 | IP Address & Port | App-ID                     |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------- | ----------------- | -------------------------- |
| <p>Initial registration</p><p>Used for the first request in registration flow where the agent passes the distribution ID and obtains the <strong><code>ch-</code></strong><em><strong><code>\<tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong> of its tenant</p> | `distributions-prod-fed.traps.paloaltonetworks.com`  | 104.198.132.24    | `traps-management-service` |
| <p>Agent heartbeat and data upload</p><p>Used for all other requests between the agent and its tenant server, including heartbeat, uploads, action results, and scan reports.</p>                                                                                                                          | `ch-<tenant-name>.traps.paloaltonetworks.com`        | 130.211.195.231   | `traps-management-service` |
| <p>EDR data upload</p><p>Used for EDR data upload.</p>                                                                                                                                                                                                                                                     | `dc-<tenant-name>.traps.paloaltonetworks.com`        | 130.211.195.231   | `traps-management-service` |
| <p>API gateway</p><p>Used for API requests and responses.</p>                                                                                                                                                                                                                                              | `api-<tenant-name>.xdr.federal.paloaltonetworks.com` | 130.211.195.231   | N/a                        |
| <p>Verdict requests</p><p>Used for get-verdict requests.</p>                                                                                                                                                                                                                                               | `cc-<tenant-name>.traps.paloaltonetworks.com`        | 35.222.50.74      | `traps-management-service` |
| <p>Live terminal</p><p>Used in live terminal flow.</p>                                                                                                                                                                                                                                                     | `wss://lrc-fed.paloaltonetworks.com`                 | 35.188.188.91     | `cortex-xdr`               |
| App proxy                                                                                                                                                                                                                                                                                                  | `app-proxy.federal.paloaltonetworks.com`             | 35.186.217.42     | N/a                        |

#### Content updates and storage (GCP)

These resources are hosted on Google Cloud Platform. All ports are 443 unless otherwise specified.

| Resource/function                                                                                                                    | FQDN                                                            | IP Addresses     | App-ID       |
| ------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------- | ---------------- | ------------ |
| <p>Installers</p><p>Used to download installers for upgrade actions from the server.</p>                                             | `panw-xdr-installers-prod-fr.storage.googleapis.com`            | IP ranges in GCP | `cortex-xdr` |
| <p>Legacy payloads</p><p>Used to download the executable for the live terminal for Cortex XDR agents earlier than version 7.1.0.</p> | `panw-xdr-payloads-prod-fr.storage.googleapis.com`              | IP ranges in GCP | `cortex-xdr` |
| <p>Content updates</p><p>Used to download content updates.</p>                                                                       | `global-content-profiles-policy-prod-fr.storage.googleapis.com` | IP ranges in GCP | `cortex-xdr` |
| <p>Scanning verdicts</p><p>Used to download extended verdict request results in scanning.</p>                                        | `panw-xdr-evr-prod-fr.storage.googleapis.com`                   | IP ranges in GCP | `cortex-xdr` |

#### Broker VM resources

Required only for deployments utilizing Broker VM features. All ports are 443, unless otherwise stated.

| Resource/Function                                                                                                                       | FQDN                                                | IP Addresses   |           App-ID           |
| --------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------- | -------------- | :------------------------: |
| Broker connection                                                                                                                       | `br-<tenant-name>.xdr.federal.paloaltonetworks.com` | 34.71.185.11   |             N/a            |
| <p>Registration</p><p>Used for the first request in the registration flow, for Broker VMs to obtain their specific connection URLs.</p> | `distributions-prod-fed.traps.paloaltonetworks.com` | 104.198.132.24 | `traps-management-service` |
| <p>XSIAM gateway</p><p>Broker VM 3.0 and above</p>                                                                                      |                                                     | N/a            |             N/a            |
| <p>Time sync (NTP)</p><p>Used by the Broker VM to ensure accurate timestamping for forwarded logs.</p>                                  | N/a                                                 | UDP port 123   |             N/a            |

#### Authentication (SSO)

Required for administrator login and Single Sign-On. All ports are 443 unless specified

| Resource         | FQDN                            | IP Addresses and Port | App-ID |
| ---------------- | ------------------------------- | --------------------- | :----: |
| Identity service | `identity.paloaltonetworks.com` | 34.107.215.35         |   N/a  |
| Login service    | `login.paloaltonetworks.com`    | 34.107.190.184        |   N/a  |

#### Ingress: Third-party data collection

Allow traffic from these IPs to your network when collecting data from SaaS and Cloud resources.

| IP Addresses                                         | App-ID       |
| ---------------------------------------------------- | ------------ |
| <ul><li>34.68.217.16</li><li>34.69.175.202</li></ul> | `cortex-xdr` |

#### Log forwarding to a syslog receiver

If you want to send logs to a syslog receiver, you need to enable access to Cortex Cloud IP addresses for your region in your firewall. For more information, see [Integrate a syslog receiver](/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/integrate-a-syslog-receiver.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources/fedramp-and-the-us-federal-government-required-resources.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
