Enable access to required PANW resources
Learn more about enabling network access to the Cortex XDR resources.
After you receive your account details, enable and verify access to Cortex XDR communication servers, storage buckets, and various resources in your firewall configuration.
Some of the IP addresses required for access are registered in the United States. As a result, some GeoIP databases do not correctly pinpoint the location in which IP addresses are used. All customer data is stored in your deployment region, regardless of the IP address registration, and restricts data transmission through any infrastructure to that region.
Keep in mind the following guidelines:
If you use the specific Palo Alto Networks App-IDs indicated in the tables, you do not need to allow access to the resource.
A dash (—) indicates there is no App-ID coverage for a resource. Enable access from the agent to the console; this does not need to be bidirectional.
For IP address ranges in Google Cloud Platform (GCP), refer to these lists for IP address coverage for your deployment:
https://www.gstatic.com/ipranges/goog.json: IP address subnet ranges
https://www.gstatic.com/ipranges/cloud.json: IP address ranges associated with your region
If you use SSL decryption and experience difficulty in connecting the Cortex XDR agent to the server, we recommend that you add the FQDNs required for access to your SSL Decryption Exclusion list.
In PAN-OS 8.0 and later releases, you can configure the list in Device → Certificate Management → SSL Decryption Exclusion.
Note
<xdr-tenant> refers to the selected subdomain of your Cortex XDR tenant, and <region> is the region in which your tenant is deployed. For more information, see Cortex XDR supported regions.
The following table lists the required resources by region, including FQDNs, IP addresses, ports, and App-ID coverage for your deployment:
<xdr-tenant>.xdr.<region>.paloaltonetworks.com
Used to connect to the Cortex XDR tenant.
IP address by region:
US (United States): 35.244.250.18
EU (Europe): 35.227.237.180
CA (Canada): 34.120.31.199
UK (United Kingdom): 34.120.87.77
JP (Japan): 35.241.28.254
SG (Singapore): 34.117.211.129
AU (Australia): 34.120.229.65
DE (Germany): 34.98.68.183
IN (India): 35.186.207.80
CH (Switzerland): 34.111.6.153
PL (Poland): 34.117.240.208
TW (Taiwan): 34.160.28.41
QT (Qatar): 35.190.0.180
FA (France): 34.111.134.57
FI (Finland): 34.160.63.63
IL (Israel): 34.111.129.144
SA (Saudi Arabia): 35.244.157.127
ID (Indonesia): 34.111.58.152
ES (Spain): 34.111.188.248
IT (Italy): 34.8.224.70
KR (South Korea): 34.54.5.247
ZA (South Africa): 34.149.165.12
Port: 443
cortex-xdr
distributions.traps.paloaltonetworks.com
Used for the first request in registration flow where the agent passes the distribution id and obtains the ch-<xdr-tenant> .traps.paloaltonetworks.com of its tenant.
IP address: 35.223.6.69
Port: 443
traps-management-service
https://lrc-<region>.paloaltonetworks.com
wss://lrc-<region>.paloaltonetworks.com
Used in live terminal flow.
IP address by region:
US (United States): 35.190.88.43
EU (Europe): 35.244.251.25
CA (Canada): 35.203.99.74
UK (United Kingdom): 35.242.159.176
JP (Japan): 34.84.201.32
SG (Singapore): 34.87.61.186
AU (Australia): 35.244.66.177
DE (Germany): 34.107.61.141
IN (India): 35.200.146.253
CH (Switzerland): 34.65.213.226
PL (Poland): 34.118.62.80
TW (Taiwan): 34.80.34.30
QT (Qatar): 34.18.34.73
FA (France): 34.163.57.57
FI (Finland): 34.88.31.230
IL (Israel): 34.165.43.106
SA (Saudi Arabia): 34.166.54.6
ID (Indonesia): 34.101.214.157
ES (Spain): 34.175.18.78
IT (Italy): 34.154.154.5
KR (South Korea): 34.22.66.91
ZA (South Africa): 34.35.56.170
Port: 443
cortex-xdr
panw-xdr-installers-prod-us.storage.googleapis.com
Used to download installers for upgrade actions from the server.
This storage bucket is used for all regions.
IP ranges in GCP
Port: 443
cortex-xdr
panw-xdr-payloads-prod-us.storage.googleapis.com
Used to download the executable for live terminal for XDR agents earlier than version 7.1.0.
This storage bucket is used for all regions.
IP ranges in GCP
Port: 443
cortex-xdr
global-content-profiles-policy.storage.googleapis.com
Used to download content updates.
IP ranges in GCP
Port: 443
cortex-xdr
panw-xdr-evr-prod-<region>.storage.googleapis.com
Used to download extended verdict request results in scanning.
IP ranges in GCP
Port: 443
cortex-xdr
https://<region>-docker.pkg.dev
Used to download the Kubernetes image from the registry for Kubernetes agents installation.
IP ranges in GCP
Port: 443
dc-<xdr-tenant>.traps.paloaltonetworks.com
Used for EDR data upload.
IP address by region:
US (United States): 34.98.77.231
EU (Europe): 34.102.140.103
CA (Canada): 34.96.120.25
UK (United Kingdom): 35.244.133.254
JP (Japan): 34.95.66.187
SG (Singapore): 34.120.142.18
AU (Australia): 34.102.237.151
DE (Germany): 34.107.161.143
IN (India): 34.120.213.187
CH (Switzerland): 34.149.180.250
PL (Poland): 35.190.13.237
TW (Taiwan): 34.149.248.76
QT (Qatar): 34.107.129.254
FA (France): 34.36.155.211
FI (Finland): 136.110.165.34
IL (Israel): 34.128.157.130
SA (Saudi Arabia): 34.107.213.85
ID (Indonesia): 34.128.156.84
ES (Spain): 34.120.102.147
IT (Italy): 34.8.234.58
KR (South Korea): 34.54.155.245
ZA (South Africa): 35.190.79.68
Port: 443
traps-management-service
ch-<xdr-tenant>.traps.paloaltonetworks.com
Used for all other requests between the agent and its tenant server including heartbeat, uploads, action results, and scan reports.
IP address by region:
US (United States): 34.98.77.231
EU (Europe): 34.102.140.103
CA (Canada): 34.96.120.25
UK (United Kingdom): 35.244.133.254
JP (Japan): 34.95.66.187
SG (Singapore): 34.120.142.18
AU (Australia): 34.102.237.151
DE (Germany): 34.107.161.143
IN (India): 34.120.213.188
CH (Switzerland): 34.149.180.250
PL (Poland): 35.190.13.237
TW (Taiwan): 34.149.248.76
QT (Qatar): 34.107.129.254
FA (France): 34.36.155.211
FI (Finland): 136.110.165.34
IL (Israel): 34.128.157.130
SA (Saudi Arabia): 34.107.213.85
ID (Indonesia): 34.128.156.84
ES (Spain): 34.120.102.147
IT (Italy): 34.8.234.58
KR (South Korea): 34.54.155.245
ZA (South Africa): 35.190.79.68
Port: 443
traps-management-service
api-<xdr-tenant>``.xdr. <region>.paloaltonetworks.com
Used for API requests and responses and to connect to an engine.
IP address by region:
US (United States): 35.222.81.194
EU (Europe): 34.90.67.58
CA (Canada): 35.203.82.121
UK (United Kingdom): 34.89.56.78
JP (Japan): 34.84.125.129
SG (Singapore): 34.87.83.144
AU (Australia): 35.189.18.208
DE (Germany): 34.107.57.23
IN (India): 35.200.158.164
CH (Switzerland): 34.65.248.119
PL (Poland): 34.116.216.55
TW (Taiwan): 35.234.8.249
QT (Qatar): 34.18.46.240
FA (France): 34.155.222.152
FI (Finland): 35.228.73.215
IL (Israel): 34.165.156.139
SA (Saudi Arabia): 34.166.58.79
ID (Indonesia): 34.128.115.238
ES (Spain): 34.175.30.176
IT (Italy): 34.154.195.120
KR (South Korea): 34.64.54.175
ZA (South Africa): 34.35.64.191
Port: 443
—
cc-<xdr-tenant>.traps.paloaltonetworks.com
Used for get-verdict requests.
IP address by region:
US (United States): 35.224.140.142
EU (Europe): 34.90.71.103
CA (Canada): 35.203.35.23
UK (United Kingdom): 34.89.42.214
JP (Japan): 34.84.225.105
SG (Singapore): 35.247.161.94
AU (Australia): 35.201.23.188
DE (Germany): 35.242.201.199
IN (India): 35.244.57.196
CH (Switzerland): 34.65.137.215
PL (Poland): 34.116.213.71
TW (Taiwan): 35.229.186.216
QT (Qatar): 34.18.53.229
FA (France): 34.155.110.169
FI (Finland): 35.228.118.177
IL (Israel): 34.165.2.110
SA (Saudi Arabia): 34.166.53.160
ID (Indonesia): 34.101.155.198
ES (Spain): 34.175.205.166
IT (Italy): 34.154.230.76
KR (South Korea): 34.64.228.117
ZA (South Africa): 34.35.13.198
Port: 443
traps-management-service
Broker VM Resources
Required for deployments that use Broker VM features
Used to download Broker VM images from the server.
This storage bucket is used for all regions.
IP ranges in GCP
Port: 443
cortex-xdr
br-<xdr-tenant>``.xdr.``<region>.paloaltonetworks.com
IP address by region:
US (United States): 104.155.131.72
EU (Europe): 34.91.128.226
CA (Canada): 34.95.8.232
UK (United Kingdom): 35.197.219.110
JP (Japan):34.85.74.43
SG (Singapore): 34.87.167.125
AU (Australia): 35.244.93.0
DE (Germany): 35.198.112.13
IN (India): 35.200.234.99
CH (Switzerland): 34.65.51.103
PL (Poland): 34.116.176.97
TW (Taiwan): 34.80.230.166
QT (Qatar): 34.18.37.73
FA (France): 34.155.90.61
FI (Finland): 34.88.26.246
IL (Israel): 34.165.24.222
SA (Saudi Arabia): 34.166.55.153
ID (Indonesia): 34.101.101.170
ES (Spain): 34.175.182.55
IT (Italy): 34.154.168.139
KR (South Korea): 34.64.46.249
ZA (South Africa): 34.35.45.251
Port: 443
—
distributions.traps.paloaltonetworks.com
IP address: 35.223.6.69
Port: 443
traps-management-service
time.google.compool.ntp.org
UDP port: 123
—
App Login and Authentication
identity.paloaltonetworks.com
(SSO)
IP address: 34.120.119.85
Port: 443
—
login.paloaltonetworks.com
(SSO)
IP address: 34.102.139.110
Port: 443
—
In-App Help Center and Notifications
data.pendo.io
Port: 443
—
pendo-static-5664029141630976.storage.googleapis.com
Port: 443
—
Email Notifications
—
IP address for all regions: 159.183.150.248
—
Egress
These IPs are used for communication between Cortex XDR and your resources. Use them when sending data out from your tenant.
US (United States)
34.132.108.184
34.69.63.16
EU (Europe)
34.147.107.51
34.91.26.125
CA (Canada)
35.203.108.13
35.203.101.162
UK (United Kingdom)
35.242.180.163
34.105.173.229
JP (Japan)
35.200.3.131
34.146.181.233
SG (Singapore)
35.240.243.57
34.126.183.208
AU (Australia)
34.151.83.236
34.116.67.90
DE (Germany)
35.234.118.195
34.89.183.45
IN (India)
35.200.175.78
34.93.9.198
CH (Switzerland)
34.65.108.153
34.65.155.169
PL (Poland)
34.118.48.171
34.116.202.235
TW (Taiwan)
34.80.133.68
35.234.18.10
QT (Qatar)
34.18.34.118
34.18.39.155
FA (France)
34.155.5.117
34.155.41.247
(FI) Finland
34.88.97.182
34.88.189.1
IL (Israel)
34.165.33.165
34.165.27.131
SA (Saudi Arabia)
34.166.61.81
34.166.58.213
ID (Indonesia)
34.128.126.138
34.128.82.158
ES (Spain)
34.175.46.46
34.175.80.182
IT (Italy)
34.154.23.156
34.154.186.12
KR (South Korea)
34.64.93.168
34.64.237.45
ZA (South Africa):
34.35.42.196
34.35.79.219
cortex-xdr
To Collect 3rd Party Data from Customer's SaaS and Cloud resources
—
IP address by region.
US (United States)
34.66.69.154
35.202.21.123
AU (Australia)
35.197.181.108
35.197.175.44
CA (Canada)
34.95.33.72
34.95.62.136
SG (Singapore)
35.247.148.38
35.247.173.40
JP (Japan)
34.85.68.167
34.84.99.239
IN (India)
34.93.3.196
34.93.175.218
DE (Germany)
34.89.197.46
34.107.3.224
UK (United Kingdom)
34.105.227.146
34.105.137.22
EU (Europe)
34.90.70.107
35.204.129.196
CH (Switzerland)
34.65.225.124
34.65.89.6
PL (Poland)
34.118.71.237
34.118.124.130
TW (Taiwan)
35.201.142.86
35.189.176.163
QT (Qatar)
34.18.44.71
34.18.30.132
FA (France)
34.163.125.167
34.163.155.105
FI (Finland)
35.228.192.167
34.88.193.126
IL (Israel)
34.165.131.171
34.165.120.206
SA (Saudi Arabia)
34.166.59.20
34.166.53.242
ID (Indonesia)
34.101.158.32
34.101.79.159
ES (Spain)
34.175.27.251
34.175.198.50
IT (Italy)
34.154.208.247
34.154.243.11
KR (South Korea)
34.64.107.163
34.64.84.25
ZA (South Africa):
34.35.69.156
34.35.60.86
cortex-xdr
Log Forwarding to a Syslog Receiver
The following table lists the required resources for the federal government of the United States, including FQDNs, IP addresses, ports, and App-ID coverage for your deployment:
distributions-prod-fed.traps.paloaltonetworks.com
Used for the first request in registration flow where the agent passes the distribution ID and obtains the ch-<xdr-tenant> .traps.paloaltonetworks.com of its tenant
IP address: 104.198.132.24
Port: 443
traps-management-service
wss://lrc-fed.paloaltonetworks.com
Used in live terminal flow.
IP address: 35.188.188.91
Port: 443
cortex-xdr
panw-xdr-installers-prod-fr.storage.googleapis.com
Used to download installers for upgrade actions from the server.
IP ranges in GCP
Port: 443
cortex-xdr
panw-xdr-payloads-prod-fr.storage.googleapis.com
Used to download the executable for live terminal for Cortex XDR agents earlier than version 7.1.0.
IP ranges in GCP
Port: 443
cortex-xdr
global-content-profiles-policy-prod-fr.storage.googleapis.com
Used to download content updates.
IP ranges in GCP
Port: 443
cortex-xdr
panw-xdr-evr-prod-fr.storage.googleapis.com
Used to download extended verdict request results in scanning.
IP ranges in GCP
Port: 443
cortex-xdr
app-proxy.federal.paloaltonetworks.com
IP address: 35.186.217.42
Port: 443
—
dc-<xdr-tenant> .traps.paloaltonetworks.com
Used for EDR data upload.
IP address: 130.211.195.231
Port: 443
traps-management-service
ch-<xdr-tenant> .traps.paloaltonetworks.com
Used for all other requests between the agent and its tenant server including heartbeat, uploads, action results, and scan reports.
IP address: 130.211.195.231
Port: 443
traps-management-service
api-<xdr-tenant> .xdr.federal.paloaltonetworks.com
Used for API requests and responses.
IP address: 130.211.195.231
Port: 443
—
cc-<xdr-tenant>.traps.paloaltonetworks.com
Used for get-verdict requests.
IP address: 35.222.50.74
Port: 443
traps-management-service
Broker VM Resources
Required for deployments that use Broker VM features
br-<xdr-tenant>``.xdr.federal.paloaltonetworks.com:443
IP address: 34.71.185.11
Port: 443
—
xdr-gateway (Broker VM 3.0 only)
Port: 443
—
distributions-prod-fed.traps.paloaltonetworks.com
IP address: 104.198.132.24
Port: 443
traps-management-service
UDP port: 123
—
App Login and Authentication
identity.paloaltonetworks.com
(SSO)
IP address: 34.107.215.35
Port: 443
—
login.paloaltonetworks.com
(SSO)
IP address: 34.107.190.184
Port: 443
—
To Collect 3rd Party Data from Customer's SaaS and Cloud resources
—
IP addresses
34.68.217.16
34.69.175.202
cortex-xdr
Log Forwarding to a Syslog Receiver
Last updated
Was this helpful?
