> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/enable-access-to-palo-alto-networks-resources.md).

# Enable access to Palo Alto Networks resources

After you receive your account details, in your firewall configuration, enable and verify access to Cortex XSOAR communication servers, storage buckets, and various resources.

{% hint style="info" %}

### Note

Some of the IP addresses required for access are registered in the United States. As a result, some GeoIP databases do not correctly pinpoint the location in which IP addresses are used. All customer data is stored in your deployment region, regardless of the IP address registration, and restricts data transmission through any infrastructure to that region.
{% endhint %}

For IP address ranges in Google Cloud Platform (GCP), view the following tables for IP address coverage for your deployment:

* <https://www.gstatic.com/ipranges/goog.json>: IP address subnet ranges
* <https://www.gstatic.com/ipranges/cloud.json>: IP address ranges associated with your region

In your firewall configuration, enable the following resources:

| FQDN                                                    | Description                                                                                                                                                                                                               |
| ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| \<xsoar-tenant>.crtx.\<region>.paloaltonetworks.com     | Used to connect to Palo Alto Networks. For the relevant region and IP address, see the **IP Address to connect to Cortex XSOAR** column below. For example, if the region is US, use the 35.244.250.18 IP address.        |
| api-\<xsoar-tenant>.crtx.\<region>.paloaltonetworks.com | Used for API requests and responses and to connect to an engine. For the relevant region and IP address, see the **API/EDL IP Address** column below. For example, if the region is US, use the 35.222.81.194 IP address. |
| ext-\<xsoar-tenant>.crtx.\<region>.paloaltonetworks.com | Used for EDL (long-running integrations). For the relevant region and IP address, see the **API/EDL IP Address** column below. For example, if the region is US, use the 35.222.81.194 IP address.                        |

{% hint style="info" %}

### Note

\<xsoar-tenant> refers to the chosen subdomain of your Cortex XSOAR tenant, and \<region> is the region in which your tenant is deployed.

The port is 443.
{% endhint %}

Egress is used for communication between Cortex XSOAR and customer resources. For the relevant region and IP address, see the **Egress IP Address** column below. For example, if the region is US, use 34.132.108.184 and 34.69.63.16.

| Region              | IP Address to connect to Cortex XSOAR | API/EDL IP Address | Egress IP Address                                       |
| ------------------- | ------------------------------------- | ------------------ | ------------------------------------------------------- |
| AU (Australia)      | 34.120.229.65                         | 35.189.18.208      | <ul><li>34.151.83.236</li><li>34.116.67.90</li></ul>    |
| CA (Canada)         | 34.120.31.199                         | 35.203.82.121      | <ul><li>35.203.108.13</li><li>35.203.101.162</li></ul>  |
| CH (Switzerland)    | 34.111.6.153                          | 34.65.248.119      | <ul><li>34.65.108.153</li><li>34.65.155.169</li></ul>   |
| DE (Germany)        | 34.98.68.183                          | 34.107.57.23       | <ul><li>35.234.118.195</li><li>34.89.183.45</li></ul>   |
| ES (Spain)          | 34.111.188.248                        | 34.175.30.176      | <ul><li>34.175.46.46</li><li>34.175.80.182</li></ul>    |
| EU (Europe)         | 35.227.237.180                        | 34.90.67.58        | <ul><li>34.147.107.51</li><li>34.91.26.125</li></ul>    |
| FA (France)         | 34.111.134.57                         | 34.155.222.152     | <ul><li>34.155.5.117</li><li>34.155.41.247</li></ul>    |
| FI (Finland)        | 34.160.63.63                          | 35.228.73.215      | <ul><li>34.88.97.182</li><li>34.88.189.1</li></ul>      |
| ID (Indonesia)      | 34.111.58.152                         | 34.128.115.238     | <ul><li>34.128.126.138</li><li>34.128.82.158</li></ul>  |
| IL (Israel)         | 34.111.129.144                        | 34.165.156.139     | <ul><li>34.165.33.165</li><li>34.165.27.131</li></ul>   |
| IN (India)          | 35.186.207.80                         | 35.200.158.164     | <ul><li>35.200.175.78</li><li>34.93.9.198</li></ul>     |
| IT (Italy)          | 34.8.224.70                           | 34.154.195.120     | <ul><li>34.154.23.156</li><li>34.154.186.12</li></ul>   |
| JP (Japan)          | 35.241.28.254                         | 34.84.125.129      | <ul><li>35.200.3.131</li><li>34.146.181.233</li></ul>   |
| KR (South Korea)    | 34.54.5.247                           | 34.64.54.175       | <ul><li>34.64.93.168</li><li>34.64.237.45</li></ul>     |
| PL (Poland)         | 34.117.240.208                        | 34.116.216.55      | <ul><li>34.118.48.171</li><li>34.116.202.235</li></ul>  |
| QT (Qatar)          | 35.190.0.180                          | 34.18.46.240       | <ul><li>34.18.34.118</li><li>34.18.39.155</li></ul>     |
| SA (Saudi Arabia)   | 35.244.157.127                        | 34.166.58.79       | <ul><li>34.166.61.81</li><li>34.166.58.213</li></ul>    |
| SG (Singapore)      | 34.117.211.129                        | 34.87.83.144       | <ul><li>35.240.243.57</li><li>34.126.183.208</li></ul>  |
| TW (Taiwan)         | 34.160.28.41                          | 35.234.8.249       | <ul><li>34.80.133.68</li><li>35.234.18.10</li></ul>     |
| UK (United Kingdom) | 34.120.87.77                          | 34.89.56.78        | <ul><li>35.242.180.163</li><li>34.105.173.229</li></ul> |
| US (United States)  | 35.244.250.18                         | 35.222.81.194      | <ul><li>34.132.108.184</li><li>34.69.63.16</li></ul>    |
| ZA (South Africa)   | 34.149.165.12                         | 34.35.64.191       | <ul><li>34.35.42.196</li><li>34.35.79.219</li></ul>     |

**Outbound IPs for engines**

| Region              | IP addresses                                           |
| ------------------- | ------------------------------------------------------ |
| US (United States)  | <ul><li>35.225.156.101</li><li>34.69.88.119</li></ul>  |
| EU (Europe)         | <ul><li>34.147.67.188</li><li>34.90.16.31</li></ul>    |
| CA (Canada)         | <ul><li>35.203.57.162</li><li>35.203.90.79</li></ul>   |
| UK (United Kingdom) | <ul><li>34.142.3.42</li><li>34.142.44.136</li></ul>    |
| JP (Japan)          | <ul><li>34.146.60.215</li><li>34.84.93.160</li></ul>   |
| SG (Singapore)      | <ul><li>35.240.144.192</li><li>35.240.255.15</li></ul> |
| AU (Australia)      | <ul><li>35.244.73.76</li><li>35.201.22.63</li></ul>    |
| DE (Germany)        | <ul><li>34.107.83.197</li><li>34.159.53.97</li></ul>   |
| IN (India)          | <ul><li>35.244.5.205</li><li>34.93.118.113</li></ul>   |
| CH (Switzerland)    | <ul><li>34.65.222.25</li><li>34.65.233.60</li></ul>    |
| PL (Poland)         | <ul><li>34.118.92.214</li><li>34.116.223.119</li></ul> |
| TW (Taiwan)         | <ul><li>104.199.223.229</li><li>34.81.38.132</li></ul> |
| QT (Qatar)          | <ul><li>34.18.39.0</li><li>34.18.32.96</li></ul>       |
| FA (France)         | <ul><li>34.155.197.131</li><li>34.155.5.100</li></ul>  |
| IL (Israel)         | <ul><li>34.165.46.47</li><li>34.165.17.246</li></ul>   |
| SA (Saudi Arabia)   | <ul><li>34.166.58.243</li><li>34.166.54.238</li></ul>  |
| ID (Indonesia)      | <ul><li>34.101.125.66</li><li>34.101.218.184</li></ul> |
| ES (Spain)          | <ul><li>34.175.255.99</li><li>34.175.230.35</li></ul>  |
| IT (Italy)          | <ul><li>34.154.173.134</li><li>34.154.229.60</li></ul> |
| KR (South Korea)    | <ul><li>34.64.189.205</li><li>34.64.45.118</li></ul>   |
| ZA (South Africa)   | <ul><li>34.35.70.193</li><li>34.35.80.189</li></ul>    |

**In-app Help Center and notifications**

| FQDN                                                 | Port      |
| ---------------------------------------------------- | --------- |
| data.pendo.io                                        | Port: 443 |
| pendo-static-5664029141630976.storage.googleapis.com | Port: 443 |

**Email notifications**

IP address for all regions: 159.183.150.248

**App login and authentication**

| FQDN                               | IP address and port |
| ---------------------------------- | ------------------- |
| <https://sso.paloaltonetworks.com> | Port: 443           |

**Required Resources for Federal (United States - Government)**

| FQDN                                                                                                                                                                                                       | IP Addresses and Port                                                                                                                                                |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **`app-proxy.federal.paloaltonetworks.com`**                                                                                                                                                               | <ul><li>IP address: 35.186.217.42</li><li>Port: 443</li></ul>                                                                                                        |
| <p><strong><code>api-</code></strong><em><strong><code>\<xsoar-tenant></code></strong></em><strong><code>.crtx.federal.paloaltonetworks.com</code></strong></p><p>Used for API requests and responses.</p> | <ul><li>IP address: 130.211.195.231</li><li>Port: 443</li></ul>                                                                                                      |
| **Outbound IPs for XSOAR SaaS Engines**                                                                                                                                                                    |                                                                                                                                                                      |
|                                                                                                                                                                                                            | <p>FedRAMP Moderate</p><ul><li>34.123.127.174:443</li><li>34.71.135.18:443</li></ul><p>FedRAMP High</p><ul><li>34.123.153.175:443</li><li>35.223.253.2:443</li></ul> |
| **App Login and Authentication**                                                                                                                                                                           |                                                                                                                                                                      |
| **`sso-fed.paloaltonetworks.com`**                                                                                                                                                                         | Port: 443                                                                                                                                                            |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/enable-access-to-palo-alto-networks-resources.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
