Enterprise DLP
Prerequisite Ports and FQDNs for Enterprise DLP
Table of Contents
Expand All
|
Collapse All
Enterprise DLP Docs
Prerequisite Ports and FQDNs for Enterprise DLP
Allow access to the following IP addresses and open ports required to successfully
forward traffic to Enterprise Data Loss Prevention (E-DLP).
- Strata Cloud Manager Ports and FQDNsEnterprise DLP stores DLP incident data in regional storage buckets based on DLP incident traffic origin source. You must allow access to all of the listed FQDNs and ports on your network regardless regardless of the region and DLP incident source.The hawkeye.services-edge.paloaltonetworks.com FQDN automatically resolves to the closest Enterprise DLP server to scan forwarded traffic, and to store the traffic contents, evidence, time of scan, and snippets.(Switzerland and Brazil) Enterprise DLP scans forwarded traffic, stores traffic contents evidence, time of scan, and snippets in the respective regions. However, Enterprise DLP stores incident metadata in the region where you deployed your Strata Cloud Manager tenant.Regions
FQDNs Ports AustraliaAPACBrazilCanadaEuropeFranceIndiaJapanSwitzerlandUnited KingdomUnited States of America- http://ocsp.paloaltonetworks.com
- http://crl.paloaltonetworks.com
- http://ocsp.godaddy.com
- http://crl.godaddy.com
TCP 80 - https://api.paloaltonetworks.com
- https://apitrusted.paloaltonetworks.com
- certificatetrusted.paloaltonetworks.com
- certificate.paloaltonetworks.com
- hawkeye.services-edge.paloaltonetworks.com
- dlp.hawkeye.services-edge.paloaltonetworks.com
- ace.hawkeye.services-edge.paloaltonetworks.com
- urlcat.hawkeye.services-edge.paloaltonetworks.com
- enforcer-hawkeye.services-edge.paloaltonetworks.com
TCP 443 - Panorama Country Ports and FQDNsYou must allow access to all of the Enterprise DLP ports and FQDNs Required for All Regions on your network regardless of the region and DLP incident traffic source.Enterprise DLP stores DLP incident data in regional storage buckets based on DLP incident traffic source. You can allow the Default Cloud Content Server FQDN to automatically resolve to the closest Enterprise DLP server to scan forwarded traffic, and to store the file contents, evidence, time of scan, and snippets. Alternatively, you can configure a Regional Cloud Content Server FQDN to forward traffic to a specific Enterprise DLP server and storage bucket.The Cloud Content Server FQDN you allow on your network must be the same as the one you configure in the Cloud Content Settings to successfully forward traffic to Enterprise DLP.(Switzerland and Brazil) You must use the Default Regional Cloud Content Server FQDN. Enterprise DLP stores scans forwarded traffic, stores traffic contents evidence, time of scan, and snippets in the respective regions. However, Enterprise DLP stores incident metadata in the region where you deployed your Strata Cloud Manager tenant.Regions
FQDNs DLP Service Ports Required for All Regions- http://ocsp.paloaltonetworks.com
- http://crl.paloaltonetworks.com
- http://ocsp.godaddy.com
- http://crl.godaddy.com
TCP 80- https://api.paloaltonetworks.com
- https://apitrusted.paloaltonetworks.com
- certificatetrusted.paloaltonetworks.com
- certificate.paloaltonetworks.com
- dlp.hawkeye.services-edge.paloaltonetworks.com
- ace.hawkeye.services-edge.paloaltonetworks.com
- urlcat.hawkeye.services-edge.paloaltonetworks.com
- enforcer-hawkeye.services-edge.paloaltonetworks.com
TCP 443RegionsRegional Cloud Content Server FQDN Port DefaultBrazilSwitzerlandhawkeye.services-edge.paloaltonetworks.comTCP 443APACapac.hawkeye.services-edge.paloaltonetworks.comTCP 443Australiaau.hawkeye.services-edge.paloaltonetworks.comTCP 443Canadaca.hawkeye.services-edge.paloaltonetworks.comTCP 443Europeeu.hawkeye.services-edge.paloaltonetworks.comTCP 443Francefr.hawkeye.services-edge.paloaltonetworks.comTCP 443Indiain.hawkeye.services-edge.paloaltonetworks.comTCP 443Japanjp.hawkeye.services-edge.paloaltonetworks.comTCP 443United Kingdomuk.hawkeye.services-edge.paloaltonetworks.comTCP 443United States of Americaus.hawkeye.services-edge.paloaltonetworks.comTCP 443 - Panorama FedRAMP Ports and FQDNsEnterprise DLP supports FedRAMP Mod and High environments.
FQDNs Ports FedRAMP Impact Level- http://ocsp.paloaltonetworks.com
- http://crl.paloaltonetworks.com
- http://ocsp.godaddy.com
- http://crl.godaddy.com
TCP 80 ModerateHigh- https://api.paloaltonetworks.com
- https://apitrusted.paloaltonetworks.com
- certificatetrusted.paloaltonetworks.com
- certificate.paloaltonetworks.com
- hawkeye.services-edge.pubsec-cloud.paloaltonetworks.com
- dlp.hawkeye.services-edge.paloaltonetworks.com
- ace.hawkeye.services-edge.paloaltonetworks.com
- urlcat.hawkeye.services-edge.paloaltonetworks.com
- enforcer-hawkeye.services-edge.paloaltonetworks.com
TCP 443