<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: allowing MS product activation and denying web access in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-ms-product-activation-and-denying-web-access/m-p/16396#M11966</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my experience, PA is not able to recognize MS product activation traffic reliably.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes it is recognized correctly, but most of the time PA recognizes it as ms-update or even web-browsing.&lt;/P&gt;&lt;P&gt;Doesn't help either that MS is secretive about the whole activation process, would be a lot easier if it were one type of traffic (for all MS products) and/or to fixed known destinations (subnets).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you're better of with a local KMS...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Dec 2012 07:30:21 GMT</pubDate>
    <dc:creator>dieter_b</dc:creator>
    <dc:date>2012-12-18T07:30:21Z</dc:date>
    <item>
      <title>allowing MS product activation and denying web access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-ms-product-activation-and-denying-web-access/m-p/16395#M11965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a network that I want to allow MS product activation to work but web browsing and other internet activity to be denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two main security policies that apply just to this network although DNS and ntp is also allowed:&lt;/P&gt;&lt;P&gt;The first one is an application filter that allows all applications you get when you click on "software-updates".&amp;nbsp; And the port set is "application default".&lt;/P&gt;&lt;P&gt;The second rule is a deny all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I see it this should allow ms-product-activation but it doesn't.&amp;nbsp; Do I need a separate rule with just ms-product-activation.&amp;nbsp; Do I need to add any other applications to the rule to make it work?&amp;nbsp; For instance, say web-browsing and https and ports 80 and 443.&amp;nbsp; This would unfortunately allow web-browsing which I want to deny.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 01:12:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-ms-product-activation-and-denying-web-access/m-p/16395#M11965</guid>
      <dc:creator>kjh</dc:creator>
      <dc:date>2012-12-17T01:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: allowing MS product activation and denying web access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-ms-product-activation-and-denying-web-access/m-p/16396#M11966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my experience, PA is not able to recognize MS product activation traffic reliably.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes it is recognized correctly, but most of the time PA recognizes it as ms-update or even web-browsing.&lt;/P&gt;&lt;P&gt;Doesn't help either that MS is secretive about the whole activation process, would be a lot easier if it were one type of traffic (for all MS products) and/or to fixed known destinations (subnets).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you're better of with a local KMS...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 07:30:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-ms-product-activation-and-denying-web-access/m-p/16396#M11966</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2012-12-18T07:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: allowing MS product activation and denying web access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-ms-product-activation-and-denying-web-access/m-p/16397#M11967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a list available at:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://support.microsoft.com/kb/921471"&gt;http://support.microsoft.com/kb/921471&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;one url not mentioned there seems to be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wpa.one.microsoft.com:80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dunno if the above wpa url is still valid as part of the activation or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess the best would be if you could setup a local auth server for this and then just allow this particular server to reach microsoft's domains.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 09:33:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-ms-product-activation-and-denying-web-access/m-p/16397#M11967</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-12-18T09:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: allowing MS product activation and denying web access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-ms-product-activation-and-denying-web-access/m-p/578355#M116007</link>
      <description>&lt;P&gt;Hi. We used the application&amp;nbsp; ms-product-activation with good results. ( so no ssl only&amp;nbsp;ms-product-activation )&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 14:46:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-ms-product-activation-and-denying-web-access/m-p/578355#M116007</guid>
      <dc:creator>GoranBerglund</dc:creator>
      <dc:date>2024-02-26T14:46:35Z</dc:date>
    </item>
  </channel>
</rss>

