Prisma Cloud: How to Delete network from Trusted Alert IP Addresses

Prisma Cloud: How to Delete network from Trusted Alert IP Addresses

8167
Created On 12/20/21 15:02 PM - Last Modified 04/03/24 14:37 PM


Objective


Objective is to delete a network name from the Trusted Alert IP addresses list directly from the UI. But this is not currently a feature that Prisma Cloud supports. You can only delete a CIDR range from the UI. 

Environment


Prisma Cloud

Procedure


Under Settings > Trusted IP Addresses > Add Trusted Alert IP Addresses :

You can only delete a CIDR range directly from the Network Name via the UI. But not the Network Name itself, even if it contains 0 CIDR addresses. You can do so by expanding the > and deleting the CIDR range via the trash button.  
Screenshot 2024-04-03 at 10.17.56 AM.png

An example of what an empty network looks like when you Edit Trusted Alert IP Address :

Screenshot 2024-04-03 at 10.18.44 AM.png

It is not possible for the network to be deleted via API either. 
To clean up a no longer needed trusted IP Network Name requires a database scrubbing exercise.

When Prisma Cloud ingests flow logs, we tag them with the public network as they are stored in the backend database. This is why if you create a new Trusted Network list, it is not retroactive because it only applies to newly added flow logs. It has to do with the architecture of the network ingestion, thus why we cannot delete the network from the UI.


Additional Information


View our documentation here on Alert Trusted IP Addresses. 

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004MbhCAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language