Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security analyst is developing a custom integration in Cortex XSOAR that needs to interact with an internal REST API. The API uses a non-standard port (e.g., 8443) and is only accessible from specific network segments. During testing, the integration consistently fails to connect to the API, reporting 'Connection refused' errors. The XSOAR engine's network connectivity to the API server has been verified. What is the most likely cause of this connection issue?

  1. AIncorrect API endpoint URL configured in the integration.
  2. BFirewall blocking outbound connections from the XSOAR engine to the API's non-standard port.
  3. CAPI rate limiting is being exceeded by the integration.
  4. DMissing `verify_ssl` parameter in the HTTP request.
Show answer & explanation

Correct answer: B. Firewall blocking outbound connections from the XSOAR engine to the API's non-standard port.

A 'Connection refused' error, especially when network connectivity has been verified (e.g., ping, traceroute to the IP), strongly suggests that a firewall is actively blocking the connection at the target port. Internal APIs on non-standard ports are often protected by strict firewall rules. Even if the XSOAR engine can reach the API server's IP, it might not be allowed to establish a connection on port 8443.

Why the other options are wrong

  • A. An incorrect URL would likely result in a 'Host not found' or '404 Not Found' error, not 'Connection refused'.
  • C. API rate limiting typically results in HTTP 429 Too Many Requests errors, not 'Connection refused'.
  • D. Missing `verify_ssl` would lead to SSL certificate errors, not 'Connection refused'.

Connection Refused Error

An error indicating that a server actively declined a connection attempt, often due to firewall rules or the service not running on the specified port.

  • Suggests the target host is reachable but explicitly rejected the connection.
  • Common causes include firewalls, incorrect port, or the service not listening.
  • Distinguished from 'Host not found' or 'Timeout' errors.

Memory trick: Connection Refused means the door is shut, not that the house is gone.

More Integrations questions