<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zone to Zone for OWA/activesync? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-for-owa-activesync/m-p/22947#M16735</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our users private devices are on a separate subnet/vlan and a separate PA zone using the Google DNS servers.&amp;nbsp; I have been forcing a captive portal in order to enable user ID for these devices.&amp;nbsp; This has been working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set a rule so that these devices can access our exchange server via OWA/activesync by going out to the internet and hitting the external OWA IP address.&amp;nbsp; Problem is the User-IP mapping can't occur, except via captive portal, because of the NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any down side to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Handing my internal DNS to the "private device" zone and then creating a rule so that the guest devices can do DNS resolution from my internal servers.&lt;/LI&gt;&lt;LI&gt;Allowing the "Private devices" to access my internal exchange server via a rule allowing zone to zone activesync/OWA?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the old days (ports only) this would be unwise at best.&amp;nbsp; Given the ability to only allow by appid, it seems like a reasonable idea.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Special note:&amp;nbsp; The only devices on this "personal device" vlan/subnet are private devices owned by students which we would have at least a little bit of control over.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thought?&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 16 Dec 2012 07:28:19 GMT</pubDate>
    <dc:creator>BobW</dc:creator>
    <dc:date>2012-12-16T07:28:19Z</dc:date>
    <item>
      <title>Zone to Zone for OWA/activesync?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-for-owa-activesync/m-p/22947#M16735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our users private devices are on a separate subnet/vlan and a separate PA zone using the Google DNS servers.&amp;nbsp; I have been forcing a captive portal in order to enable user ID for these devices.&amp;nbsp; This has been working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set a rule so that these devices can access our exchange server via OWA/activesync by going out to the internet and hitting the external OWA IP address.&amp;nbsp; Problem is the User-IP mapping can't occur, except via captive portal, because of the NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any down side to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Handing my internal DNS to the "private device" zone and then creating a rule so that the guest devices can do DNS resolution from my internal servers.&lt;/LI&gt;&lt;LI&gt;Allowing the "Private devices" to access my internal exchange server via a rule allowing zone to zone activesync/OWA?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the old days (ports only) this would be unwise at best.&amp;nbsp; Given the ability to only allow by appid, it seems like a reasonable idea.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Special note:&amp;nbsp; The only devices on this "personal device" vlan/subnet are private devices owned by students which we would have at least a little bit of control over.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thought?&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Dec 2012 07:28:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-for-owa-activesync/m-p/22947#M16735</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2012-12-16T07:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Zone to Zone for OWA/activesync?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-for-owa-activesync/m-p/22948#M16736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't really have an answer for you, your policy should be what you need it to be.&amp;nbsp; I think your question begs others: Do you have different policies for different users?&amp;nbsp; If its a BYOD vlan and everyone gets outbound 80/443, is the UID relevant?&amp;nbsp; Do you want to get rid of the captive portal?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For me, I'm not sure I'd bother with it, just tie down the web services the way you want and call it good.&amp;nbsp; If your wifi environment supports it, you can use some sort of EAP to see the real UID behind the IP if anything interesting were to occur.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry I didn't answer your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 22:56:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-for-owa-activesync/m-p/22948#M16736</guid>
      <dc:creator>msullivan</dc:creator>
      <dc:date>2012-12-17T22:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Zone to Zone for OWA/activesync?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-for-owa-activesync/m-p/22949#M16737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess I had an epiphany of sorts and wanted some verification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic between zones used to be a big negative.&amp;nbsp; With app level filtering, it seems it can be pretty darned safe.&amp;nbsp; Especially considering the applications I am talking about are published to the untrust zone anyway (activsync and OWA).&amp;nbsp; Currently the private devices are getting NATed and coming back in to do activesync.&amp;nbsp; Given appid publishing it seems rather silly to go through all of that AND Yes, you nailed it that I am interested in getting around the captive portal.&amp;nbsp; If they have activesync, and the IP is not NATed, I should be able to run rules&amp;nbsp; without captive portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I guess your post, at least verified with me that it i not a "bad" idea....given Appid publishing rules and all I am letting is activesync. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for listening.&lt;/P&gt;&lt;P&gt;bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 01:42:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-for-owa-activesync/m-p/22949#M16737</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2012-12-18T01:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Zone to Zone for OWA/activesync?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-for-owa-activesync/m-p/22950#M16738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;I believe you can allow the devices in the private zone to use your internal DNS servers and DMZ servers. If you are allowing these devices to reach internet via your PAN, I believe you do have some control over these devices ( unless you are giving internet access to unknown/unlimited number of devices&amp;nbsp; through your network) and you can identify the users using them via user-id agent. Also since you are allowing traffic based on applications this should not be a problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 02:41:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-to-zone-for-owa-activesync/m-p/22950#M16738</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-12-18T02:41:41Z</dc:date>
    </item>
  </channel>
</rss>

