FedRAMP and US federal Cortex XSIAM required resources ↗
Configure firewall access for FedRAMP and US federal government Cortex XSIAM deployments. The following tables list required FQDNs, IP addresses, ports, and App-ID coverage.
Cortex XSIAM egress and engine resources
All ports are 443 unless otherwise specified.
| Source | Compliance Level | IP Addresses |
|---|---|---|
| Egress | FedRAMP Moderate | 34.122.220.113, 35.223.83.172 |
| FedRAMP High | 34.136.155.252, 34.133.46.50 | |
| Outbound IPs for Engines | FedRAMP Moderate | 34.123.127.174:443, 34.71.135.18:443 |
| FedRAMP High | 34.123.153.175:443, 35.223.253.2:443 | |
Core Cortex XSIAM communication resources
These resources handle agent registration, heartbeats, data uploads, and API connections. All ports are 443 unless specified otherwise.
| Resource/Function | FQDN | IP Address & Port | App-ID |
|---|---|---|---|
Initial registrationUsed for the first request in registration flow where the agent passes the distribution ID and obtains the ch-<tenant-name>.traps.paloaltonetworks.com of its tenant |
distributions-prod-fed.traps.paloaltonetworks.com |
104.198.132.24 | traps-management-service |
| Agent heartbeat and data uploadUsed for all other requests between the agent and its tenant server, including heartbeat, uploads, action results, and scan reports. | ch-<tenant-name>.traps.paloaltonetworks.com |
130.211.195.231 | traps-management-service |
| EDR data uploadUsed for EDR data upload. | dc-<tenant-name>.traps.paloaltonetworks.com |
130.211.195.231 | traps-management-service |
| API gatewayUsed for API requests and responses. | api-<tenant-name>.xdr.federal.paloaltonetworks.com |
130.211.195.231 | N/a |
| Verdict requestsUsed for get-verdict requests. | cc-<tenant-name>.traps.paloaltonetworks.com |
35.222.50.74 | traps-management-service |
| Live terminalUsed in live terminal flow. | wss://lrc-fed.paloaltonetworks.com |
35.188.188.91 | cortex-xdr |
| App proxy | app-proxy.federal.paloaltonetworks.com |
35.186.217.42 | N/a |
Cortex XSIAM content updates and GCP storage
These resources are hosted on Google Cloud Platform. All ports are 443 unless otherwise specified.
| Resource/function | FQDN | IP Addresses | |
|---|---|---|---|
| <p> </p> |
FQDN | IP Addresses | App-ID |
| InstallersUsed to download installers for upgrade actions from the server. | panw-xdr-installers-prod-fr.storage.googleapis.com |
IP ranges in GCP | cortex-xdr |
| Legacy payloadsUsed to download the executable for the live terminal for Cortex XDR agents earlier than version 7.1.0. | panw-xdr-payloads-prod-fr.storage.googleapis.com |
IP ranges in GCP | cortex-xdr |
| Content updatesUsed to download content updates. | global-content-profiles-policy-prod-fr.storage.googleapis.com |
IP ranges in GCP | cortex-xdr |
| Scanning verdictsUsed to download extended verdict request results in scanning. | panw-xdr-evr-prod-fr.storage.googleapis.com |
IP ranges in GCP | cortex-xdr |
Cortex XSIAM Broker VM resources
Required only for deployments utilizing Broker VM features. All ports are 443, unless otherwise stated.
| Resource/Function | FQDN | IP Addresses | App-ID |
|---|---|---|---|
| Broker connection | br-<tenant-name>.xdr.federal.paloaltonetworks.com |
34.71.185.11 | N/a |
| <p>Registration</p><p>Used for the first request in the registration flow, for Broker VMs to obtain their specific connection URLs.</p> | distributions-prod-fed.traps.paloaltonetworks.com |
104.198.132.24 | traps-management-service |
| <p>XSIAM gateway</p><p>Broker VM 3.0 and above</p> | xsiam-gateway |
N/a | N/a |
| <p>Time sync (NTP)</p><p>Used by the Broker VM to ensure accurate timestamping for forwarded logs.</p> | N/a | UDP port 123 | N/a |
Cortex XSIAM authentication and SSO
Required for administrator login and Single Sign-On. All ports are 443 unless specified
| Resource | FQDN | IP Addresses and Port | App-ID |
|---|---|---|---|
| Identity service | identity.paloaltonetworks.com |
34.107.215.35 | N/a |
| Login service | login.paloaltonetworks.com |
34.107.190.184 | N/a |
Cortex XSIAM ingress for third-party data collection
Allow traffic from these IPs to your network when collecting data from SaaS and Cloud resources.
| IP Addresses | App-ID |
|---|---|
| <ul><li>34.68.217.16</li><li>34.69.175.202</li></ul> | cortex-xdr |
Cortex XSIAM log forwarding to a syslog receiver
If you want to send logs to a syslog receiver, you need to enable access to Cortex XSIAM IP addresses for your region in your firewall. For more information, see Integrate a syslog receiver.