Prisma Cloud Compute : `What are the URLs to be whitelisted for successful defender to console connection on app.sg?

Prisma Cloud Compute : `What are the URLs to be whitelisted for successful defender to console connection on app.sg?

3701
Created On 05/30/24 07:38 AM - Last Modified 11/01/24 21:45 PM


Question


What are the URLs that have to be allowed for a successful Prisma Defender connection?



Environment


  • Prisma Cloud Compute
  • Prisma Cloud Enterprise Edition
  • Defender installed behind Proxy/Firewall


Answer


If the Prisma Cloud Compute Console is hosted in app.sg stack then the below will have to be whitelisted.
1. URL of the Compute Console.
     a. If self-hosted console, then allow access to the console URL
     b. If SaaS Console then get the console URL from  Manage > System > Utilities
2. For SaaS Console API path has to be allowed. eg.  API path for  app.sg is api.sg.prismacloud.io.
3. If wildfire is enabled then *.wildfire.paloaltonetworks.com has to be allowed.

The same will have to be done for twistcli scans in CI pipeline scans as well.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000010z1jCAA&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language