<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft Lync 2010 - 2013 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21930#M16007</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there is a document from Palo Alto Networks and Citrix Netscaler (as load balancer for Lync) describing a reference setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://media.paloaltonetworks.com/documents/panw-netscaler-lync.pdf" title="http://media.paloaltonetworks.com/documents/panw-netscaler-lync.pdf"&gt;http://media.paloaltonetworks.com/documents/panw-netscaler-lync.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Dec 2012 20:03:41 GMT</pubDate>
    <dc:creator>Anon1</dc:creator>
    <dc:date>2012-12-11T20:03:41Z</dc:date>
    <item>
      <title>Microsoft Lync 2010 - 2013</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21926#M16003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anyone rolled out MS Lync 2010 servers in your network and worked out the policies &amp;amp; rules for the Lync traffic. If so would someone be willing to share the details. I am very new to the PANOS and i do not want to create security risk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance,&lt;/P&gt;&lt;P&gt;PlanoGuy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2012 19:40:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21926#M16003</guid>
      <dc:creator>planotexasguru</dc:creator>
      <dc:date>2012-12-10T19:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Lync 2010 - 2013</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21927#M16004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is an example of the "Single Consolidated Edge" we are using.&amp;nbsp; Good Luck!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;IMG alt="Lync Topology.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4892_Lync Topology.jpg" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2012 21:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21927#M16004</guid>
      <dc:creator>msullivan</dc:creator>
      <dc:date>2012-12-10T21:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Lync 2010 - 2013</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21928#M16005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the diagram Mike, it will be usefull. however i am looking for something more basic to the policies and rules and what they will look like in the PA-500 GUI...&lt;/P&gt;&lt;P&gt;Thanks Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2012 21:51:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21928#M16005</guid>
      <dc:creator>planotexasguru</dc:creator>
      <dc:date>2012-12-10T21:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Lync 2010 - 2013</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21929#M16006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Plano,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in my case, the PAN is the internal firewall.&amp;nbsp; I created custom application for the Lync ports (8057, 5061, 5062, 4443).&amp;nbsp; I created an application group for all the FE -&amp;gt; Edge services that includes the aforementioned ports and additionally included ssl and stun.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I made App Override policies for the Lync ports so they were mapped correctly and implemented security rules per the diagram.&amp;nbsp; So it sort if looks like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Custom App:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="12-11-2012 11-27-56 AM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4893_12-11-2012 11-27-56 AM.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;App Group:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="12-11-2012 11-28-14 AM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4894_12-11-2012 11-28-14 AM.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;App Override:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="12-11-2012 11-31-41 AM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4898_12-11-2012 11-31-41 AM.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Sec Pol:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="12-11-2012 11-33-03 AM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4900_12-11-2012 11-33-03 AM.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obviously, your actual mileage may vary, but this should get you close for the FE &amp;lt;-&amp;gt; Edge server policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2012 19:38:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21929#M16006</guid>
      <dc:creator>msullivan</dc:creator>
      <dc:date>2012-12-11T19:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Lync 2010 - 2013</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21930#M16007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there is a document from Palo Alto Networks and Citrix Netscaler (as load balancer for Lync) describing a reference setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://media.paloaltonetworks.com/documents/panw-netscaler-lync.pdf" title="http://media.paloaltonetworks.com/documents/panw-netscaler-lync.pdf"&gt;http://media.paloaltonetworks.com/documents/panw-netscaler-lync.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2012 20:03:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21930#M16007</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2012-12-11T20:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Lync 2010 - 2013</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21931#M16008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a fantastic document.&lt;/P&gt;&lt;P&gt;Thank you for posting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 15:16:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21931#M16008</guid>
      <dc:creator>parkerbc</dc:creator>
      <dc:date>2013-02-06T15:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Lync 2010 - 2013</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21932#M16009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/10392"&gt;msullivan&lt;/A&gt; - Why do you need to create custom apps and app override policies? Can it not work with service (port) based policies? What setting have you configured for custom apps. I am interested in knowing about the timeout values.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 15:51:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21932#M16009</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2014-08-26T15:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Lync 2010 - 2013</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21933#M16010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't need to setup custom apps and overrides, but I do for two reasons:&lt;/P&gt;&lt;P&gt;- Seeing the app identified makes for better reporting&lt;/P&gt;&lt;P&gt;- If you want reporting and consistant functionality, you best use app overrides because the next App ID update might break production rules.&amp;nbsp; Case in point, some Lync traffic was originally identified as SSL (that's fine with me), then PA came out with an update and now identifies the same traffic over port 443 as ms-lync (or something like that).&amp;nbsp; That broke our clients for a few minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to tune timeouts, you'll need to create a custom app.&amp;nbsp; I use the defautl timeouts for Lync connections, but I do have some custom timeouts for other long lived app connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 16:59:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21933#M16010</guid>
      <dc:creator>msullivan</dc:creator>
      <dc:date>2014-08-26T16:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Lync 2010 - 2013</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21934#M16011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/10392"&gt;msullivan&lt;/A&gt; - can you please share screenshot for the details of custom apps?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 08:44:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-lync-2010-2013/m-p/21934#M16011</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2014-09-23T08:44:23Z</dc:date>
    </item>
  </channel>
</rss>

