Enable access to Palo Alto Networks resources
Enable network access to Cortex XSOAR 8 SaaS resources for your environment.
After you receive your account details, in your firewall configuration, enable and verify access to Cortex XSOAR communication servers, storage buckets, and various resources.
Note
Some of the IP addresses required for access are registered in the United States. As a result, some GeoIP databases do not correctly pinpoint the location in which IP addresses are used. All customer data is stored in your deployment region, regardless of the IP address registration, and restricts data transmission through any infrastructure to that region.
For IP address ranges in Google Cloud Platform (GCP), view the following tables for IP address coverage for your deployment:
https://www.gstatic.com/ipranges/goog.json: IP address subnet ranges
https://www.gstatic.com/ipranges/cloud.json: IP address ranges associated with your region
In your firewall configuration, enable the following resources:
<xsoar-tenant>.crtx.<region>.paloaltonetworks.com
Used to connect to Palo Alto Networks. For the relevant region and IP address, see the IP Address to connect to Cortex XSOAR column below. For example, if the region is US, use the 35.244.250.18 IP address.
api-<xsoar-tenant>.crtx.<region>.paloaltonetworks.com
Used for API requests and responses and to connect to an engine. For the relevant region and IP address, see the API/EDL IP Address column below. For example, if the region is US, use the 35.222.81.194 IP address.
ext-<xsoar-tenant>.crtx.<region>.paloaltonetworks.com
Used for EDL (long-running integrations). For the relevant region and IP address, see the API/EDL IP Address column below. For example, if the region is US, use the 35.222.81.194 IP address.
Note
<xsoar-tenant> refers to the chosen subdomain of your Cortex XSOAR tenant, and <region> is the region in which your tenant is deployed.
The port is 443.
Egress is used for communication between Cortex XSOAR and customer resources. For the relevant region and IP address, see the Egress IP Address column below. For example, if the region is US, use 34.132.108.184 and 34.69.63.16.
AU (Australia)
34.120.229.65
35.189.18.208
34.151.83.236
34.116.67.90
CA (Canada)
34.120.31.199
35.203.82.121
35.203.108.13
35.203.101.162
CH (Switzerland)
34.111.6.153
34.65.248.119
34.65.108.153
34.65.155.169
DE (Germany)
34.98.68.183
34.107.57.23
35.234.118.195
34.89.183.45
ES (Spain)
34.111.188.248
34.175.30.176
34.175.46.46
34.175.80.182
EU (Europe)
35.227.237.180
34.90.67.58
34.147.107.51
34.91.26.125
FA (France)
34.111.134.57
34.155.222.152
34.155.5.117
34.155.41.247
FI (Finland)
34.160.63.63
35.228.73.215
34.88.97.182
34.88.189.1
ID (Indonesia)
34.111.58.152
34.128.115.238
34.128.126.138
34.128.82.158
IL (Israel)
34.111.129.144
34.165.156.139
34.165.33.165
34.165.27.131
IN (India)
35.186.207.80
35.200.158.164
35.200.175.78
34.93.9.198
IT (Italy)
34.8.224.70
34.154.195.120
34.154.23.156
34.154.186.12
JP (Japan)
35.241.28.254
34.84.125.129
35.200.3.131
34.146.181.233
KR (South Korea)
34.54.5.247
34.64.54.175
34.64.93.168
34.64.237.45
PL (Poland)
34.117.240.208
34.116.216.55
34.118.48.171
34.116.202.235
QT (Qatar)
35.190.0.180
34.18.46.240
34.18.34.118
34.18.39.155
SA (Saudi Arabia)
35.244.157.127
34.166.58.79
34.166.61.81
34.166.58.213
SG (Singapore)
34.117.211.129
34.87.83.144
35.240.243.57
34.126.183.208
TW (Taiwan)
34.160.28.41
35.234.8.249
34.80.133.68
35.234.18.10
UK (United Kingdom)
34.120.87.77
34.89.56.78
35.242.180.163
34.105.173.229
US (United States)
35.244.250.18
35.222.81.194
34.132.108.184
34.69.63.16
ZA (South Africa)
34.149.165.12
34.35.64.191
34.35.42.196
34.35.79.219
Outbound IPs for engines
US (United States)
35.225.156.101
34.69.88.119
EU (Europe)
34.147.67.188
34.90.16.31
CA (Canada)
35.203.57.162
35.203.90.79
UK (United Kingdom)
34.142.3.42
34.142.44.136
JP (Japan)
34.146.60.215
34.84.93.160
SG (Singapore)
35.240.144.192
35.240.255.15
AU (Australia)
35.244.73.76
35.201.22.63
DE (Germany)
34.107.83.197
34.159.53.97
IN (India)
35.244.5.205
34.93.118.113
CH (Switzerland)
34.65.222.25
34.65.233.60
PL (Poland)
34.118.92.214
34.116.223.119
TW (Taiwan)
104.199.223.229
34.81.38.132
QT (Qatar)
34.18.39.0
34.18.32.96
FA (France)
34.155.197.131
34.155.5.100
IL (Israel)
34.165.46.47
34.165.17.246
SA (Saudi Arabia)
34.166.58.243
34.166.54.238
ID (Indonesia)
34.101.125.66
34.101.218.184
ES (Spain)
34.175.255.99
34.175.230.35
IT (Italy)
34.154.173.134
34.154.229.60
KR (South Korea)
34.64.189.205
34.64.45.118
ZA (South Africa)
34.35.70.193
34.35.80.189
In-app Help Center and notifications
data.pendo.io
Port: 443
pendo-static-5664029141630976.storage.googleapis.com
Port: 443
Email notifications
IP address for all regions: 159.183.150.248
App login and authentication
https://sso.paloaltonetworks.com
Port: 443
Required Resources for Federal (United States - Government)
app-proxy.federal.paloaltonetworks.com
IP address: 35.186.217.42
Port: 443
api-<xsoar-tenant>.crtx.federal.paloaltonetworks.com
Used for API requests and responses.
IP address: 130.211.195.231
Port: 443
Outbound IPs for XSOAR SaaS Engines
FedRAMP Moderate
34.123.127.174:443
34.71.135.18:443
FedRAMP High
34.123.153.175:443
35.223.253.2:443
App Login and Authentication
sso-fed.paloaltonetworks.com
Port: 443
Last updated
Was this helpful?
