The following table lists the required resources for the federal government of the United States, including FQDNs, IP addresses, ports, and App-ID coverage for your deployment:
All ports are 443 unless otherwise specified.
Source | Compliance level | IP Addresses |
|---|---|---|
Egress | FedRAMP Moderate | 34.122.220.113, 35.223.83.172 |
FedRAMP High | 34.136.155.252, 34.133.46.50 | |
Outbound IPs for Engines | FedRAMP Moderate | 34.123.127.174:443, 34.71.135.18:443 |
FedRAMP High | 34.123.153.175:443, 35.223.253.2:443 |
These resources handle agent registration, heartbeats, data uploads, and API connections. All ports are 443 unless specified otherwise.
Resource/Function | FQDN | IP Address & Port | App-ID |
|---|---|---|---|
Initial registration Used for the first request in registration flow where the agent passes the distribution ID and obtains the |
| 104.198.132.24 |
|
Agent heartbeat and data upload Used for all other requests between the agent and its tenant server, including heartbeat, uploads, action results, and scan reports. |
| 130.211.195.231 |
|
EDR data upload Used for EDR data upload. |
| 130.211.195.231 |
|
API gateway Used for API requests and responses. |
| 130.211.195.231 | N/a |
Verdict requests Used for get-verdict requests. |
| 35.222.50.74 |
|
Live terminal Used in live terminal flow. |
| 35.188.188.91 |
|
App proxy |
| 35.186.217.42 | N/a |
These resources are hosted on Google Cloud Platform. All ports are 443 unless otherwise specified.
Resource/function | FQDN | IP Addresses | App-ID |
|---|---|---|---|
Installers Used to download installers for upgrade actions from the server. |
| IP ranges in GCP |
|
Legacy payloads Used to download the executable for the live terminal for Cortex XDR agents earlier than version 7.1.0. |
| IP ranges in GCP |
|
Content updates Used to download content updates. |
| IP ranges in GCP |
|
Scanning verdicts Used to download extended verdict request results in scanning. |
| IP ranges in GCP |
|
Required only for deployments utilizing Broker VM features. All ports are 443, unless otherwise stated.
Resource/Function | FQDN | IP Addresses | App-ID |
|---|---|---|---|
Broker connection |
| 34.71.185.11 | N/a |
Registration Used for the first request in the registration flow, for Broker VMs to obtain their specific connection URLs. |
| 104.198.132.24 |
|
XSIAM gateway Broker VM 3.0 and above |
| N/a | N/a |
Time sync (NTP) Used by the Broker VM to ensure accurate timestamping for forwarded logs. | N/a | UDP port 123 | N/a |
Required for administrator login and Single Sign-On. All ports are 443 unless specified
Resource | FQDN | IP Addresses and Port | App-ID |
|---|---|---|---|
Identity service |
| 34.107.215.35 | N/a |
Login service |
| 34.107.190.184 | N/a |
Allow traffic from these IPs to your network when collecting data from SaaS and Cloud resources.
IP Addresses | App-ID |
|---|---|
|
|
If you want to send logs to a syslog receiver, you need to enable access to Cortex XSIAM IP addresses for your region in your firewall. For more information, see Integrate a syslog receiver.