<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reverse proxy for Exchange ActiveSync in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/reverse-proxy-for-exchange-activesync/m-p/583893#M116672</link>
    <description>&lt;P&gt;Hello ! Thanks for the reply !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But in case I have to specify web-browsing explicitely, it will allow all trafic to the HTTPS port including OWA / ECP /.. , which I do not want to open. I only want to allow activesync . Is there a way to do this ?&lt;/P&gt;</description>
    <pubDate>Tue, 16 Apr 2024 13:14:28 GMT</pubDate>
    <dc:creator>karsayor</dc:creator>
    <dc:date>2024-04-16T13:14:28Z</dc:date>
    <item>
      <title>Reverse proxy for Exchange ActiveSync</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reverse-proxy-for-exchange-activesync/m-p/583371#M116616</link>
      <description>&lt;P&gt;We have a Palto Alto cluster and I want to use them as reverse proxy for our Exchange inbound trafic. We activated decryption for this trafic and we want to allow &lt;U&gt;&lt;STRONG&gt;only&lt;/STRONG&gt; &lt;/U&gt;ActiveSync trafic / application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It did not work with only allow ActiveSync application, we also had to create another rule to allow web-browsing to URL&amp;nbsp;*/microsoft-server-activesync because it does not detect all trafic as activesync, even though it's decrypted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In attached picture the log of a part of the trafic when I sync my iphone with the native mail application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone already done this ? Why doesn't it detect correctly the trafic as ActiveSync ?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 12:30:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reverse-proxy-for-exchange-activesync/m-p/583371#M116616</guid>
      <dc:creator>karsayor</dc:creator>
      <dc:date>2024-04-11T12:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse proxy for Exchange ActiveSync</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reverse-proxy-for-exchange-activesync/m-p/583890#M116670</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/389687115"&gt;@karsayor&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Looking at applipedia info for activesync, web-browsing should be implicitly allowed and no explicit configuration should be required.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, a&lt;SPAN&gt;pplications for which the firewall cannot determine dependent applications on time will require that you explicitly allow the dependent applications when defining your policies.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Source:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/app-id/applications-with-implicit-support" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/app-id/applications-with-implicit-support&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 13:02:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reverse-proxy-for-exchange-activesync/m-p/583890#M116670</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-04-16T13:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse proxy for Exchange ActiveSync</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reverse-proxy-for-exchange-activesync/m-p/583893#M116672</link>
      <description>&lt;P&gt;Hello ! Thanks for the reply !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But in case I have to specify web-browsing explicitely, it will allow all trafic to the HTTPS port including OWA / ECP /.. , which I do not want to open. I only want to allow activesync . Is there a way to do this ?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 13:14:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reverse-proxy-for-exchange-activesync/m-p/583893#M116672</guid>
      <dc:creator>karsayor</dc:creator>
      <dc:date>2024-04-16T13:14:28Z</dc:date>
    </item>
  </channel>
</rss>

