For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XSOAR 8 (SaaS)

Enable access to Palo Alto Networks resources

Enable network access to Cortex XSOAR 8 SaaS resources for your environment.

After you receive your account details, in your firewall configuration, enable and verify access to Cortex XSOAR communication servers, storage buckets, and various resources.

Note

Some of the IP addresses required for access are registered in the United States. As a result, some GeoIP databases do not correctly pinpoint the location in which IP addresses are used. All customer data is stored in your deployment region, regardless of the IP address registration, and restricts data transmission through any infrastructure to that region.

For IP address ranges in Google Cloud Platform (GCP), view the following tables for IP address coverage for your deployment:

In your firewall configuration, enable the following resources:

FQDN
Description

<xsoar-tenant>.crtx.<region>.paloaltonetworks.com

Used to connect to Palo Alto Networks. For the relevant region and IP address, see the IP Address to connect to Cortex XSOAR column below. For example, if the region is US, use the 35.244.250.18 IP address.

api-<xsoar-tenant>.crtx.<region>.paloaltonetworks.com

Used for API requests and responses and to connect to an engine. For the relevant region and IP address, see the API/EDL IP Address column below. For example, if the region is US, use the 35.222.81.194 IP address.

ext-<xsoar-tenant>.crtx.<region>.paloaltonetworks.com

Used for EDL (long-running integrations). For the relevant region and IP address, see the API/EDL IP Address column below. For example, if the region is US, use the 35.222.81.194 IP address.

Note

<xsoar-tenant> refers to the chosen subdomain of your Cortex XSOAR tenant, and <region> is the region in which your tenant is deployed.

The port is 443.

Egress is used for communication between Cortex XSOAR and customer resources. For the relevant region and IP address, see the Egress IP Address column below. For example, if the region is US, use 34.132.108.184 and 34.69.63.16.

Region
IP Address to connect to Cortex XSOAR
API/EDL IP Address
Egress IP Address

AU (Australia)

34.120.229.65

35.189.18.208

  • 34.151.83.236

  • 34.116.67.90

CA (Canada)

34.120.31.199

35.203.82.121

  • 35.203.108.13

  • 35.203.101.162

CH (Switzerland)

34.111.6.153

34.65.248.119

  • 34.65.108.153

  • 34.65.155.169

DE (Germany)

34.98.68.183

34.107.57.23

  • 35.234.118.195

  • 34.89.183.45

ES (Spain)

34.111.188.248

34.175.30.176

  • 34.175.46.46

  • 34.175.80.182

EU (Europe)

35.227.237.180

34.90.67.58

  • 34.147.107.51

  • 34.91.26.125

FA (France)

34.111.134.57

34.155.222.152

  • 34.155.5.117

  • 34.155.41.247

FI (Finland)

34.160.63.63

35.228.73.215

  • 34.88.97.182

  • 34.88.189.1

ID (Indonesia)

34.111.58.152

34.128.115.238

  • 34.128.126.138

  • 34.128.82.158

IL (Israel)

34.111.129.144

34.165.156.139

  • 34.165.33.165

  • 34.165.27.131

IN (India)

35.186.207.80

35.200.158.164

  • 35.200.175.78

  • 34.93.9.198

IT (Italy)

34.8.224.70

34.154.195.120

  • 34.154.23.156

  • 34.154.186.12

JP (Japan)

35.241.28.254

34.84.125.129

  • 35.200.3.131

  • 34.146.181.233

KR (South Korea)

34.54.5.247

34.64.54.175

  • 34.64.93.168

  • 34.64.237.45

PL (Poland)

34.117.240.208

34.116.216.55

  • 34.118.48.171

  • 34.116.202.235

QT (Qatar)

35.190.0.180

34.18.46.240

  • 34.18.34.118

  • 34.18.39.155

SA (Saudi Arabia)

35.244.157.127

34.166.58.79

  • 34.166.61.81

  • 34.166.58.213

SG (Singapore)

34.117.211.129

34.87.83.144

  • 35.240.243.57

  • 34.126.183.208

TW (Taiwan)

34.160.28.41

35.234.8.249

  • 34.80.133.68

  • 35.234.18.10

UK (United Kingdom)

34.120.87.77

34.89.56.78

  • 35.242.180.163

  • 34.105.173.229

US (United States)

35.244.250.18

35.222.81.194

  • 34.132.108.184

  • 34.69.63.16

ZA (South Africa)

34.149.165.12

34.35.64.191

  • 34.35.42.196

  • 34.35.79.219

Outbound IPs for engines

Region
IP addresses

US (United States)

  • 35.225.156.101

  • 34.69.88.119

EU (Europe)

  • 34.147.67.188

  • 34.90.16.31

CA (Canada)

  • 35.203.57.162

  • 35.203.90.79

UK (United Kingdom)

  • 34.142.3.42

  • 34.142.44.136

JP (Japan)

  • 34.146.60.215

  • 34.84.93.160

SG (Singapore)

  • 35.240.144.192

  • 35.240.255.15

AU (Australia)

  • 35.244.73.76

  • 35.201.22.63

DE (Germany)

  • 34.107.83.197

  • 34.159.53.97

IN (India)

  • 35.244.5.205

  • 34.93.118.113

CH (Switzerland)

  • 34.65.222.25

  • 34.65.233.60

PL (Poland)

  • 34.118.92.214

  • 34.116.223.119

TW (Taiwan)

  • 104.199.223.229

  • 34.81.38.132

QT (Qatar)

  • 34.18.39.0

  • 34.18.32.96

FA (France)

  • 34.155.197.131

  • 34.155.5.100

IL (Israel)

  • 34.165.46.47

  • 34.165.17.246

SA (Saudi Arabia)

  • 34.166.58.243

  • 34.166.54.238

ID (Indonesia)

  • 34.101.125.66

  • 34.101.218.184

ES (Spain)

  • 34.175.255.99

  • 34.175.230.35

IT (Italy)

  • 34.154.173.134

  • 34.154.229.60

KR (South Korea)

  • 34.64.189.205

  • 34.64.45.118

ZA (South Africa)

  • 34.35.70.193

  • 34.35.80.189

In-app Help Center and notifications

FQDN
Port

data.pendo.io

Port: 443

pendo-static-5664029141630976.storage.googleapis.com

Port: 443

Email notifications

IP address for all regions: 159.183.150.248

App login and authentication

FQDN
IP address and port

https://sso.paloaltonetworks.com

Port: 443

Required Resources for Federal (United States - Government)

FQDN
IP Addresses and Port

app-proxy.federal.paloaltonetworks.com

  • IP address: 35.186.217.42

  • Port: 443

api-<xsoar-tenant>.crtx.federal.paloaltonetworks.com

Used for API requests and responses.

  • IP address: 130.211.195.231

  • Port: 443

Outbound IPs for XSOAR SaaS Engines

FedRAMP Moderate

  • 34.123.127.174:443

  • 34.71.135.18:443

FedRAMP High

  • 34.123.153.175:443

  • 35.223.253.2:443

App Login and Authentication

sso-fed.paloaltonetworks.com

Port: 443

Last updated

Was this helpful?