Resources required to enable access to XDR collectors

To enable access to XDR Collectors components, you must allow access to various Palo Alto Networks resources. If you use the specific Palo Alto Networks App-IDs indicated in the table, you do not need to explicitly allow access to the resource. A dash (-) indicates there is no App-ID coverage for a resource.

Some of the IP addresses required for access are registered in the United States. As a result, some GeoIP databases do not correctly pinpoint the location in which IP addresses are used. All customer data is stored in your deployment region, regardless of the IP address registration and restricts data transmission through any infrastructure to that region. For considerations, see Plan and preparePlan and prepare.

Throughout this topic, <xsiam-tenant> refers to the chosen subdomain of your Cortex XSIAM tenant and <region> is the region in which your Strata Logging Service is deployed.

Refer to the following tables for the FQDNs, IP addresses, ports, and App-ID coverage for your deployment.

For IP address ranges in GCP, refer to the following tables for IP address coverage for your deployment.

The following table shows the required resources by region.

FQDN IP addresses and port App-ID coverage
<xsiam-tenant>.xdr.<region>.paloaltonetworks.com Used to connect to the Cortex XSIAM management console. <p>IP address by region:</p><ul><li>US (United States): 35.244.250.18</li><li>EU (Europe): 35.227.237.180</li><li>CA (Canada): 34.120.31.199</li><li>UK (United Kingdom): 34.120.87.77</li><li>JP (Japan): 35.241.28.254</li><li>SG (Singapore): 34.117.211.129</li><li>AU (Australia): 34.120.229.65</li><li>DE (Germany): 34.98.68.183</li><li>IN (India): 35.186.207.80</li><li>CH (Switzerland): 34.111.6.153</li><li>PL (Poland): 34.117.240.208</li><li>TW (Taiwan): 34.160.28.41</li><li>QT (Qatar): 35.190.0.180</li><li>FA (France): 34.111.134.57</li><li>IL (Israel): 34.111.129.144</li><li>SA (Saudi Arabia): 35.244.157.127</li><li>ID (Indonesia): 34.111.58.152</li><li>ES (Spain): 34.111.188.248</li><li>IT (Italy): 34.8.224.70</li><li>KR (South Korea): 34.54.5.247</li><li>ZA (South Africa): 34.149.165.12</li><li>FI (Finland): 34.160.63.63</li></ul><p>Port: 443</p> cortex-xdr
distributions.traps.paloaltonetworks.com Used for the first request in registration flow where the agent passes the distribution id and obtains the ch-<xsiam-tenant>.traps.paloaltonetworks.com of its tenant. <ul><li>IP address: 35.223.6.69</li><li>Port: 443</li></ul> traps-management-service
panw-xdr-installers-prod-us.storage.googleapis.com Used to download installers for upgrade actions from the server.This storage bucket is used for all regions. <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> cortex-xdr
global-content-profiles-policy.storage.googleapis.com Used to download content updates. <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> cortex-xdr
ch-<xsiam-tenant>.traps.paloaltonetworks.com Used for all other requests between the agent and its tenant server including heartbeat, uploads, action results, and scan reports. <p>IP address by region:</p><ul><li>US (United States): 34.98.77.231</li><li>EU (Europe): 34.102.140.103</li><li>CA (Canada): 34.96.120.25</li><li>UK (United Kingdom): 35.244.133.254</li><li>JP (Japan): 34.95.66.187</li><li>SG (Singapore): 34.120.142.18</li><li>AU (Australia): 34.102.237.151</li><li>DE (Germany): 34.107.161.143</li><li>IN (India): 34.120.213.188</li><li>CH (Switzerland): 34.149.180.250</li><li>PL (Poland): 35.190.13.237</li><li>TW (Taiwan): 34.149.248.76</li><li>QT (Qatar): 34.107.129.254</li><li>FA (France): 34.36.155.211</li><li>IL (Israel): 34.128.157.130</li><li>SA (Saudi Arabia): 34.107.213.85</li><li>ID (Indonesia): 34.128.156.84</li><li>ES (Spain): 34.120.102.147</li><li>IT (Italy): 34.8.234.58</li><li>KR (South Korea): 34.54.155.245</li><li>ZA (South Africa): 35.190.79.68</li><li>FI (Finland): 136.110.165.34</li></ul><p>Port: 443</p> traps-management-service
api-<xsiam-tenant>.xdr.<region>.paloaltonetworks.com Used for API requests and responses. <p>IP address by region:</p><ul><li>US (United States): 35.222.81.194</li><li>EU (Europe): 34.90.67.58</li><li>CA (Canada): 35.203.82.121</li><li>UK (United Kingdom): 34.89.56.78</li><li>JP (Japan): 34.84.125.129</li><li>SG (Singapore): 34.87.83.144</li><li>AU (Australia): 35.189.18.208</li><li>DE (Germany): 34.107.57.23</li><li>IN (India): 35.200.158.164</li><li>CH (Switzerland): 34.65.248.119</li><li>PL (Poland): 34.116.216.55</li><li>TW (Taiwan): 35.234.8.249</li><li>QT (Qatar): 34.18.46.240</li><li>FA (France): 34.155.222.152</li><li>IL (Israel): 34.165.156.139</li><li>SA (Saudi Arabia): 34.166.58.79</li><li>ID (Indonesia): 34.128.115.238</li><li>ES (Spain): 34.175.30.176</li><li>IT (Italy): 34.154.195.120</li><li>KR (South Korea): 34.64.54.175</li><li>ZA (South Africa): 34.35.64.191</li><li>FI (Finland): 35.228.73.215</li></ul><p>Port: 443</p> -
Log forwarding to a syslog receiver    
See Integrate a syslog receiver for information about log forwarding IP addresses per region for syslog receivers.    

The following table lists the required resources for Federal (United States - Government).

FQDN IP addresses and port App-ID coverage Required for XDR Collectors
distributions-prod-fed.traps.paloaltonetworks.com Used for the first request in registration flow where the agent passes the distribution ID and obtains the ch-<xsiam-tenant>.traps.paloaltonetworks.com of its tenant. <ul><li>IP address: 104.198.132.24</li><li>Port: 443</li></ul> traps-management-service  
panw-xdr-installers-prod-fr.storage.googleapis.com Used to download installers for upgrade actions from the server. <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> cortex-xdr  
global-content-profiles-policy-prod-fr.storage.googleapis.com Used to download content updates. <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> cortex-xdr  
ch-<xsiam-tenant>.traps.paloaltonetworks.com Used for all other requests between the agent and its tenant server including heartbeat, uploads, action results, and scan reports. <ul><li>IP address: 130.211.195.231</li><li>Port: 443</li></ul> traps-management-service  
api-<xsiam-tenant>.xdr.federal.paloaltonetworks.com Used for API requests and responses. <ul><li>IP address: 130.211.195.231</li><li>Port: 443</li></ul> -  
Log forwarding to a syslog receiver      
See Integrate a syslog receiver for information about log forwarding IP addresses per region for syslog receivers.