<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exchange 2010 - Applications Required? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-2010-applications-required/m-p/42347#M31103</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoPlainText"&gt;The best way to find out what you need is to create a rule that allows traffic to from the mail server from trust to untrust. Then you can use the monitor tab to see all traffic passing through that Policy. Then you can allow just those applications.&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;I suspect the imprtant ones are these.&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;outlook-web&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8,055&lt;/P&gt;&lt;P class="MsoPlainText"&gt;ms-exchange&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6,678&lt;/P&gt;&lt;P class="MsoPlainText"&gt;web-browsing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3,037&lt;/P&gt;&lt;P class="MsoPlainText"&gt;ssl&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2,929&lt;/P&gt;&lt;P class="MsoPlainText"&gt;dns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 224&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Aug 2011 18:28:24 GMT</pubDate>
    <dc:creator>skrall</dc:creator>
    <dc:date>2011-08-23T18:28:24Z</dc:date>
    <item>
      <title>Exchange 2010 - Applications Required?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-2010-applications-required/m-p/42346#M31102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a Palo Alto in front of an Exchange 2010 CAS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Palo Alto is in a back-to-back config with a "dumb" firewall in front of it that only allows port 443 inbound.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Palo Alto has the SSL cert from the Exchange box on it, so does SSL inspection on all the inbound traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions is, can anyone who has Exchange 2010 behind a Palo Alto confirm which apps I'd need to allow if I wanted to be a little smarter than simply allowing port 443 through as a service?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I drill down using App-ID into the destination IP, over the last 7 days these are the apps/sessions that I see:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;outlook-web&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;8,055&lt;/P&gt;&lt;P&gt;ms-exchange &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;6,678&lt;/P&gt;&lt;P&gt;msrpc &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;4,197&lt;/P&gt;&lt;P&gt;web-browsing&lt;/P&gt;&lt;P&gt;3,037&lt;/P&gt;&lt;P&gt;ssl &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2,929 &lt;/P&gt;&lt;P&gt;dns &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;224&lt;/P&gt;&lt;P&gt;rpc-over-http &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;37&lt;/P&gt;&lt;P&gt;webdav &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;29&lt;/P&gt;&lt;P&gt;unknown-tcp &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;25&lt;/P&gt;&lt;P&gt;insufficient-data &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;12&lt;/P&gt;&lt;P&gt;http-audio &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;10&lt;/P&gt;&lt;P&gt;http-proxy &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obviously many of those are expected, but equally some aren't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm concerned that unless the list of apps is absolutely correct people will start to find obscure pieces of access to Exchange/Outlook stop working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Aug 2011 12:46:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exchange-2010-applications-required/m-p/42346#M31102</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2011-08-14T12:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange 2010 - Applications Required?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-2010-applications-required/m-p/42347#M31103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoPlainText"&gt;The best way to find out what you need is to create a rule that allows traffic to from the mail server from trust to untrust. Then you can use the monitor tab to see all traffic passing through that Policy. Then you can allow just those applications.&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;I suspect the imprtant ones are these.&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;outlook-web&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8,055&lt;/P&gt;&lt;P class="MsoPlainText"&gt;ms-exchange&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6,678&lt;/P&gt;&lt;P class="MsoPlainText"&gt;web-browsing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3,037&lt;/P&gt;&lt;P class="MsoPlainText"&gt;ssl&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2,929&lt;/P&gt;&lt;P class="MsoPlainText"&gt;dns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 224&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Aug 2011 18:28:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exchange-2010-applications-required/m-p/42347#M31103</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-08-23T18:28:24Z</dc:date>
    </item>
  </channel>
</rss>

