Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Enterprise EDR: Linux installs fail due to Network Rules (Palo Alto Firewall)

Enterprise EDR: Linux installs fail due to Network Rules (Palo Alto Firewall)

Environment

  • Enterprise EDR (Formerly CB ThreatHunter) Sensor: All Versions
  • Linux: All Supported Versions
  • Network Firewall: Palo Alto (PAN-OS)

Symptoms

  • Sensor installs fail with frequency
  • Checks for IP Addresses used for Registration show regular changes 

Cause

Palo Alto Firewall can be configured to block URL-based connections if the IP Address changes.

Resolution

Refer to Palo Alto's guide on configuring URL filtering:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClmgCAC 

Additional Notes


Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
630
Contributors