> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/plan-your-multi-tenant-deployment/communication-in-a-multi-tenant-deployment/configure-unidirectional-communication.md).

# Configure unidirectional communication

In a multi-tenant deployment, communication is predominantly from the main host server to any additional host servers, and then from the hosts to the tenants. Two-way communication should always be available between the main server and host servers. The main host server and additional host servers communicate using TLS 1.2 over port 443. Requests to the tenants are sent through the hosts (main or other) on port 443. The hosts forward the requests to the tenants, which listen on ports 18501 and higher.

Port 443 is used for communication between the main host server and additional host servers.

In a high availability environment, hosts in the same high availability group communicate with each other over port 443. There is no communication between hosts in different high availability groups.

|                             | Main hosts (incoming)                                                                                                                                                      | Additional hosts (incoming)               | Tenant on main host (incoming) | Tenant on additional host (incoming) |
| --------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------- | ------------------------------ | ------------------------------------ |
| Main hosts (outgoing)       | 443 (in high availability)                                                                                                                                                 | 443                                       | 1850x                          | 443                                  |
| Additional hosts (outgoing) | 443 ([configurable](/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/plan-your-multi-tenant-deployment/change-the-port-for-host-to-main-communication.md)) | 443 (in the same high availability group) | -                              | 1850x                                |

#### Configure unidirectional communication

Unidirectional communication or tunneling in multi-tenant deployments ensures secure, one-way communication from a host server to the main host server (master), preventing any data flow back to the host environment. This enhances security by isolating host networks while still enabling centralized management and monitoring.

For example, you can use unidirectional tunneling to send logs and alerts from a host to the main server without risking exposure of sensitive host networks. This setup ensures secure data transfer while maintaining strict network isolation for compliance and security purposes.

How to configure unidirectional tunneling in Cortex XSOAR

1. On the main (master) host, navigate to **Setting > ABOUT > Troubleshooting > Server Configuration**.
2. Click **Add Server Configuration**.
3. Add the **Server.UniDirectionalEnable** key and set it to **`true`**.
4. Click **Save**.
5. Add the **Server.UniDirectionalEnable** key on all hosts that want to communicate via the tunnel.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/plan-your-multi-tenant-deployment/communication-in-a-multi-tenant-deployment/configure-unidirectional-communication.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
