<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: can we allow sign in to webex only using defined company account ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-we-allow-sign-in-to-webex-only-using-defined-company-account/m-p/509124#M105980</link>
    <description>&lt;P&gt;++You need to configure decryption to be able to read http header insertion by firewall.&lt;/P&gt;
&lt;P&gt;++Then follow below steps Ref Link :&amp;nbsp;&lt;A href="https://help.webex.com/en-us/article/m0jby2/Configure-a-list-of-allowed-domains-to-access-Webex-while-on-your-corporate-network" target="_blank" rel="noopener"&gt;https://help.webex.com/en-us/article/m0jby2/Configure-a-list-of-allowed-domains-to-access-Webex-while-on-your-corporate-network&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;++Add the HTTP header&lt;SPAN&gt;&amp;nbsp;&lt;CODE class=""&gt;CiscoSpark-Allowed-Domains:&lt;SPAN&gt;&amp;nbsp;and include a comma separated list of allowed domains. You must include the destination domains:&lt;SPAN&gt;&amp;nbsp;&lt;CODE class=""&gt;identity.webex.com, identity-eu.webex.com, idbroker.webex.com, idbroker-secondary.webex.com, idbroker-b-us.webex.com, idbroker-eu.webex.com, atlas-a.wbx2.com&lt;SPAN&gt;&amp;nbsp;and your proxy server includes the custom header for requests sent to these destination domains.&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;P class=""&gt;For example, to allow users from the&lt;SPAN&gt;&amp;nbsp;&lt;EM&gt;example.com&lt;SPAN&gt;&amp;nbsp;domain, add:&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL class=""&gt;
&lt;LI class=""&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;CiscoSpark-Allowed-Domains:example.com&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;for domain(s):&lt;CODE class=""&gt;identity.webex.com, identity-eu.webex.com, idbroker.webex.com, idbroker-secondary.webex.com, idbroker-b-us.webex.com, idbroker-eu.webex.com, atlas-a.wbx2.com&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;++Create a rule for Webex and add webex in applications and applicable security policy which we created as ttp header insertion&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;Attached few snap&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cisco.PNG" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42516iB26C5D9F8E9D011F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="cisco.PNG" alt="cisco.PNG" /&gt;&lt;/span&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P class=""&gt;&lt;SPAN&gt;&lt;CODE class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 16 Jul 2022 08:26:12 GMT</pubDate>
    <dc:creator>OmkarM</dc:creator>
    <dc:date>2022-07-16T08:26:12Z</dc:date>
    <item>
      <title>can we allow sign in to webex only using defined company account ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-we-allow-sign-in-to-webex-only-using-defined-company-account/m-p/420215#M93859</link>
      <description>&lt;P&gt;&amp;nbsp;I have followed below article and tried to configure http header insertion in URL filtering profile , but still able to login using other company account.&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.webex.com/en-us/m0jby2/Configure-a-List-of-Allowed-Domains-to-Access-Webex-While-on-Your-Corporate-Network#task_C0E05337A65BA687DD68241E79076D38" target="_blank"&gt;https://help.webex.com/en-us/m0jby2/Configure-a-List-of-Allowed-Domains-to-Access-Webex-While-on-Your-Corporate-Network#task_C0E05337A65BA687DD68241E79076D38&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also in url filtering log, no logs showing for http header. We have enabled decryption for any destination and any service but no luck.&lt;/P&gt;&lt;P&gt;Also as per finding , cisco-spark app traffic is not showing decrypted in url filtering logs. It could be due to ssl decryption exclusion for cisco-spark.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jul 2021 19:32:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-we-allow-sign-in-to-webex-only-using-defined-company-account/m-p/420215#M93859</guid>
      <dc:creator>Deepak25</dc:creator>
      <dc:date>2021-07-18T19:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: can we allow sign in to webex only using defined company account ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-we-allow-sign-in-to-webex-only-using-defined-company-account/m-p/420301#M93863</link>
      <description>&lt;P&gt;&lt;SPAN class="MUxGbd wuQ4Ob WZ8Tjf"&gt;&amp;nbsp;&lt;/SPAN&gt;If&amp;nbsp;you&amp;nbsp;are having login issues&amp;nbsp;with Webex&amp;nbsp;Meetings,&amp;nbsp;we&amp;nbsp;have some Click the&amp;nbsp;Can't access your&amp;nbsp;account? link to access&amp;nbsp;sign-in assistance.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 12:20:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-we-allow-sign-in-to-webex-only-using-defined-company-account/m-p/420301#M93863</guid>
      <dc:creator>Barber52</dc:creator>
      <dc:date>2021-07-19T12:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: can we allow sign in to webex only using defined company account ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-we-allow-sign-in-to-webex-only-using-defined-company-account/m-p/420434#M93874</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183271"&gt;@Deepak25&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Have you taken a packet capture and verified that the header is actually being inserted when it traverses the firewall? WebEx is where that header actually gets read to determine if the account should be able to login or not, and if you're able to login with a domain not specified in the header it would point towards your insertion not working.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 17:17:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-we-allow-sign-in-to-webex-only-using-defined-company-account/m-p/420434#M93874</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-07-19T17:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: can we allow sign in to webex only using defined company account ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-we-allow-sign-in-to-webex-only-using-defined-company-account/m-p/426261#M94467</link>
      <description>&lt;P&gt;We can't do pcap as traffic is https. I am suspecting header used in cisco webex login.&lt;/P&gt;&lt;P&gt;In my testing I am using http header "CiscoSpark-Allowed-Domains" , not sure whether this header correct or not.&lt;/P&gt;&lt;P&gt;Did decryption. Also in Device &amp;gt; decryption exclusion , disabled webex related domains to allow decryption for those domains, but no luck.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Deepak25_0-1628716653674.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35627i3E5195E033F52ABB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Deepak25_0-1628716653674.png" alt="Deepak25_0-1628716653674.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 21:20:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-we-allow-sign-in-to-webex-only-using-defined-company-account/m-p/426261#M94467</guid>
      <dc:creator>Deepak25</dc:creator>
      <dc:date>2021-08-11T21:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: can we allow sign in to webex only using defined company account ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-we-allow-sign-in-to-webex-only-using-defined-company-account/m-p/509124#M105980</link>
      <description>&lt;P&gt;++You need to configure decryption to be able to read http header insertion by firewall.&lt;/P&gt;
&lt;P&gt;++Then follow below steps Ref Link :&amp;nbsp;&lt;A href="https://help.webex.com/en-us/article/m0jby2/Configure-a-list-of-allowed-domains-to-access-Webex-while-on-your-corporate-network" target="_blank" rel="noopener"&gt;https://help.webex.com/en-us/article/m0jby2/Configure-a-list-of-allowed-domains-to-access-Webex-while-on-your-corporate-network&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;++Add the HTTP header&lt;SPAN&gt;&amp;nbsp;&lt;CODE class=""&gt;CiscoSpark-Allowed-Domains:&lt;SPAN&gt;&amp;nbsp;and include a comma separated list of allowed domains. You must include the destination domains:&lt;SPAN&gt;&amp;nbsp;&lt;CODE class=""&gt;identity.webex.com, identity-eu.webex.com, idbroker.webex.com, idbroker-secondary.webex.com, idbroker-b-us.webex.com, idbroker-eu.webex.com, atlas-a.wbx2.com&lt;SPAN&gt;&amp;nbsp;and your proxy server includes the custom header for requests sent to these destination domains.&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;P class=""&gt;For example, to allow users from the&lt;SPAN&gt;&amp;nbsp;&lt;EM&gt;example.com&lt;SPAN&gt;&amp;nbsp;domain, add:&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL class=""&gt;
&lt;LI class=""&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;CiscoSpark-Allowed-Domains:example.com&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;for domain(s):&lt;CODE class=""&gt;identity.webex.com, identity-eu.webex.com, idbroker.webex.com, idbroker-secondary.webex.com, idbroker-b-us.webex.com, idbroker-eu.webex.com, atlas-a.wbx2.com&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;++Create a rule for Webex and add webex in applications and applicable security policy which we created as ttp header insertion&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;Attached few snap&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cisco.PNG" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42516iB26C5D9F8E9D011F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="cisco.PNG" alt="cisco.PNG" /&gt;&lt;/span&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P class=""&gt;&lt;SPAN&gt;&lt;CODE class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;CODE class=""&gt;&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2022 08:26:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-we-allow-sign-in-to-webex-only-using-defined-company-account/m-p/509124#M105980</guid>
      <dc:creator>OmkarM</dc:creator>
      <dc:date>2022-07-16T08:26:12Z</dc:date>
    </item>
  </channel>
</rss>

