<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Post OS Upgrade for PA-5220 from 9.1.4 to 10.2.3-h4 Users Started Experiencing Issues with Accessing MS Office 365 Applications Internally in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/post-os-upgrade-for-pa-5220-from-9-1-4-to-10-2-3-h4-users/m-p/540677#M1197</link>
    <description>&lt;P&gt;Hi There,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently, we upgraded the OS on our PA-5220 from 9.1.4 to 10.2.3-h4. Immediately after we upgraded to 10.2.3-h4 our helpdesk began receiving calls from users reporting that they cannot get logged into MS Office365 Applications, it'll never bring them to the MS prompt to input their Office365 email/password it'll just say "Can't reach this page."&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From monitoring the traffic on the firewall, it looks like when a PC in the trust zone is trying to reach out to the ADFS server in the DMZ zone the session is being reset on the server side.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not certain if maybe the U-Turn NAT rules we have in place to utilize our Microsoft Traffic Manager to route traffic to our ADFS servers got messed up after the OS upgrade on PA-5220. As a temporary work around, we had to update the DNS record to not utilize the Microsoft Traffic Manager alias and instead add the actual ADFS IP addresses and users are able to get to MS Office365 applications.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I appreciate your support in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You,&lt;/P&gt;
&lt;P&gt;Krystin&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 May 2023 21:28:19 GMT</pubDate>
    <dc:creator>Krystin</dc:creator>
    <dc:date>2023-05-01T21:28:19Z</dc:date>
    <item>
      <title>Post OS Upgrade for PA-5220 from 9.1.4 to 10.2.3-h4 Users Started Experiencing Issues with Accessing MS Office 365 Applications Internally</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/post-os-upgrade-for-pa-5220-from-9-1-4-to-10-2-3-h4-users/m-p/540677#M1197</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently, we upgraded the OS on our PA-5220 from 9.1.4 to 10.2.3-h4. Immediately after we upgraded to 10.2.3-h4 our helpdesk began receiving calls from users reporting that they cannot get logged into MS Office365 Applications, it'll never bring them to the MS prompt to input their Office365 email/password it'll just say "Can't reach this page."&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From monitoring the traffic on the firewall, it looks like when a PC in the trust zone is trying to reach out to the ADFS server in the DMZ zone the session is being reset on the server side.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not certain if maybe the U-Turn NAT rules we have in place to utilize our Microsoft Traffic Manager to route traffic to our ADFS servers got messed up after the OS upgrade on PA-5220. As a temporary work around, we had to update the DNS record to not utilize the Microsoft Traffic Manager alias and instead add the actual ADFS IP addresses and users are able to get to MS Office365 applications.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I appreciate your support in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You,&lt;/P&gt;
&lt;P&gt;Krystin&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 21:28:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/post-os-upgrade-for-pa-5220-from-9-1-4-to-10-2-3-h4-users/m-p/540677#M1197</guid>
      <dc:creator>Krystin</dc:creator>
      <dc:date>2023-05-01T21:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Post OS Upgrade for PA-5220 from 9.1.4 to 10.2.3-h4 Users Started Experiencing Issues with Accessing MS Office 365 Applications Internally</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/post-os-upgrade-for-pa-5220-from-9-1-4-to-10-2-3-h4-users/m-p/541140#M1222</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check the logs to see if there is any blocked traffic. The newer code has new features, etc. Also check out the external dynamic list that PAN has available for o365 since its IP's rotate a lot:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1683237846829.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49983i40228A78FFFC1CD2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1683237846829.png" alt="OtakarKlier_0-1683237846829.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 22:04:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/post-os-upgrade-for-pa-5220-from-9-1-4-to-10-2-3-h4-users/m-p/541140#M1222</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-05-04T22:04:20Z</dc:date>
    </item>
  </channel>
</rss>

