<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need to create firewall policy that allows only Microsoft teams and rest all need to block in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/467111#M102753</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For any specific application you want to allow only ( applications depend on SSL and Web-browsing), you can create two policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- One policy to allow SSL and Web-browsing for that application to work. configure the URL Category in this policy to use custom category contains only the URLs needed for that application&lt;/P&gt;&lt;P&gt;- Another policy to allow that application&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In some cases, you have to add one more policy to allow destination IPs for that application to work&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did that for multiple applications such as Anydesk, Skype, Zoom, etc..&lt;/P&gt;&lt;P&gt;I did it also for MS Teams but still facing some issues&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Feb 2022 08:34:47 GMT</pubDate>
    <dc:creator>alawi.alalattas</dc:creator>
    <dc:date>2022-02-21T08:34:47Z</dc:date>
    <item>
      <title>Need to create firewall policy that allows only Microsoft teams and rest all need to block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/415541#M93271</link>
      <description>&lt;P&gt;Hi Friends,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to create Palo Alto configuration for specific range of IP address, not based on users.&lt;/P&gt;&lt;P&gt;My requirement is as follow.&lt;/P&gt;&lt;P&gt;1. Only Microsoft teams traffic (incoming and outgoing includes calls) should be allowed.&lt;/P&gt;&lt;P&gt;2. Want to block all other traffic includes web browsing, file sharing, social media, media streaming.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone can suggest or support to create this type of configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Regards.&lt;/P&gt;&lt;P&gt;Adarsh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 07:53:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/415541#M93271</guid>
      <dc:creator>adarshp2005</dc:creator>
      <dc:date>2021-06-28T07:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: Need to create firewall policy that allows only Microsoft teams and rest all need to block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/415734#M93294</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150952"&gt;@adarshp2005&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Teams doesn't have a dedicated container app-id, instead it uses ms-teams, ms-teams-audio-video, ms-teams-downloading, ms-teams-editing, ms-teams-live-event, ms-teams-posting, ms-teams-sharing, and ms-teams-uploading. You can try building out an allow entry with those app-ids setup and deny all other traffic, but I'm not sure how well it'll actually function like that.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also keep in mind that much of Teams relies on other ms-office365 app-ids and certain functions certainly won't actually function correctly unless you include access to other ms-office365 applications.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 20:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/415734#M93294</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-06-28T20:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Need to create firewall policy that allows only Microsoft teams and rest all need to block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/415750#M93298</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In addition to what BPry already stated, you can use URL and/or destination IP filtering to limit the traffic to Microsoft.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-endpoints?view=o365-worldwide" target="_blank"&gt;https://docs.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-endpoints?view=o365-worldwide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 21:33:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/415750#M93298</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-06-28T21:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: Need to create firewall policy that allows only Microsoft teams and rest all need to block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/467111#M102753</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For any specific application you want to allow only ( applications depend on SSL and Web-browsing), you can create two policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- One policy to allow SSL and Web-browsing for that application to work. configure the URL Category in this policy to use custom category contains only the URLs needed for that application&lt;/P&gt;&lt;P&gt;- Another policy to allow that application&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In some cases, you have to add one more policy to allow destination IPs for that application to work&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did that for multiple applications such as Anydesk, Skype, Zoom, etc..&lt;/P&gt;&lt;P&gt;I did it also for MS Teams but still facing some issues&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 08:34:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/467111#M102753</guid>
      <dc:creator>alawi.alalattas</dc:creator>
      <dc:date>2022-02-21T08:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: Need to create firewall policy that allows only Microsoft teams and rest all need to block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/566396#M114471</link>
      <description>&lt;P&gt;I still have this issue to allow gifs in Teams through the PAN.&amp;nbsp; I worked with Palo Alto Support and we ended up allowing Shareware and freeware and also online storage and backup for the HR URL Category group. I don't like this solution. What I need to do is just allow *.media0.giphy.com&amp;nbsp; through *media100.giphy.com - Is there a way to wildcard the number after Media?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 17:48:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/566396#M114471</guid>
      <dc:creator>Daniel_Erlenbu</dc:creator>
      <dc:date>2023-11-20T17:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Need to create firewall policy that allows only Microsoft teams and rest all need to block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/566652#M114505</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310107"&gt;@Daniel_Erlenbu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That specific usage of wildcard is not supported.&amp;nbsp;&lt;SPAN&gt;You can only use wildcard characters as token placeholders which isn't the case in your query.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please read the section on how to use asterisk or caret wildcards in the following document:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/advanced-url-filtering/administration/configuring-url-filtering/url-category-exceptions/guidelines-for-url-category-exceptions#iddcac739a-a03b-4728-8293-b5d8d0d8a2ac" target="_blank"&gt;https://docs.paloaltonetworks.com/advanced-url-filtering/administration/configuring-url-filtering/url-category-exceptions/guidelines-for-url-category-exceptions#iddcac739a-a03b-4728-8293-b5d8d0d8a2ac&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 08:50:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-create-firewall-policy-that-allows-only-microsoft-teams/m-p/566652#M114505</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-11-22T08:50:00Z</dc:date>
    </item>
  </channel>
</rss>

