<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exchange Question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-question/m-p/44758#M32862</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 11.6999998092651px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1237" data-externalid="" data-presence="null" data-userid="32027" data-username="gabrielhill" href="https://live.paloaltonetworks.com/people/gabrielhill" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;gabrielhill&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please let us know, if the Exchange server is connected with an SSL connection, then you might need to implement SSL-Decryption, in order to inspect the content of the email.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Feb 2015 18:19:26 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2015-02-20T18:19:26Z</dc:date>
    <item>
      <title>Exchange Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-question/m-p/44757#M32861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I feel this may be a dumb question, but I was hoping somebody could give me clarification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had some issues with users receiving malware or a virus through a separate email account (ex testcompany.com), them opening it, and then it would send the email to users in their contact list, which included sending emails internally through the local exchange server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My original thought was that we could move the exchange server directly behind the palo alto, into a "services" zone, and apply anti-virus / wildfire policies to it, to prevent malicious files from flowing internally and spamming tons of internal users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After testing this, it does not seem that this works the way I expected. It seems that the Palo Alto doesn't recognize traffic between the end user (outlook) and the exchange server in the way I was hoping. It does not seem to inspect attachments with local email. Is there anyway to accomplish this type of security with a Palo Alto device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(ZONE INT) &amp;lt;------ &amp;gt; (ZONE SERVICES) &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2015 18:05:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exchange-question/m-p/44757#M32861</guid>
      <dc:creator>gabrielhill</dc:creator>
      <dc:date>2015-02-20T18:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-question/m-p/44758#M32862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 11.6999998092651px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1237" data-externalid="" data-presence="null" data-userid="32027" data-username="gabrielhill" href="https://live.paloaltonetworks.com/people/gabrielhill" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;gabrielhill&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please let us know, if the Exchange server is connected with an SSL connection, then you might need to implement SSL-Decryption, in order to inspect the content of the email.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2015 18:19:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exchange-question/m-p/44758#M32862</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-02-20T18:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-question/m-p/44759#M32863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt; . I am using an SSL connection. I have the certificate uploaded, and I have a SSL decryption policy as a test (just my PC and the Exchange server). I have it set to ssl-inbound-inspection. I try to send&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to send an .dll file to my email address, the Palo alto is not showing it in the data filtering potion, nor is it blocking this (I have a rule that should prevent these types of files from flowing through).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also tried taking the encryption setting off between my client and the exchange server, but it still does not block any attachments. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2015 19:02:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exchange-question/m-p/44759#M32863</guid>
      <dc:creator>gabrielhill</dc:creator>
      <dc:date>2015-02-20T19:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-question/m-p/44760#M32864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please double check the session details ( from your machine and exchange server) from the CLI of the PAN firewall:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin&amp;gt; show session all filter ssl-decrypt yes count yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin&amp;gt; show session all filter source x.x.x.x destination y.y.y.y&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; there should be a "*" symbol which will confirm that the session is getting decrypted&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;366417&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; msrpc&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACTIVE&amp;nbsp; FLOW *&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2015 20:39:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exchange-question/m-p/44760#M32864</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-02-20T20:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-question/m-p/44761#M32865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt;, show session all filter ssl-decrypt yes count yes - shows that I do have session that match this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show session all filter source x.x.x.x destination y.y.y.y - I do not see an "*" by the msrpc or ms-exchange connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the certificate from the exchange server imported, and everything shows valid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything I can do that could pinpoint me to the cause?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Feb 2015 05:02:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exchange-question/m-p/44761#M32865</guid>
      <dc:creator>gabrielhill</dc:creator>
      <dc:date>2015-02-21T05:02:08Z</dc:date>
    </item>
  </channel>
</rss>

