<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Newbee Needs Help in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45959#M33770</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have an Inbound NAT rule associated with the security policy? Untrust to Untrust for the zones, public facing ip for the destination address and then dnat it to your private ip address hosting the services in question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 08 Oct 2011 20:22:42 GMT</pubDate>
    <dc:creator>gswcowboy</dc:creator>
    <dc:date>2011-10-08T20:22:42Z</dc:date>
    <item>
      <title>Newbee Needs Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45956#M33767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;I am trying to setup outlook web access (Exchange 2010) for my network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;Here is what I have done thus far:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;Object -&amp;gt; Addresses: Setup the internal address of the exchange server.&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;Policy -&amp;gt; Security: Created a rule with the following data (Name: owa - Source Zone: untrusted - Address/User: any - Dest Zone: trusted - Dest Address: OWA - Dest Application: Outlook-web (factory defined) Dest Service: service-https (Factory Defined)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;When I go to commit the changes I get this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;device: Rule 'OWA' application dependency warning:&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;- Application 'outlook-web' requires 'ssl' allowed in the policy&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;- Application 'outlook-web' requires 'web-browsing' allowed in the policy&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;Configuration committed successfully&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;Not sure what its telling me to do..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;Thanks in advance&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;Wayne&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Oct 2011 12:37:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45956#M33767</guid>
      <dc:creator>WayneFusco</dc:creator>
      <dc:date>2011-10-08T12:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Newbee Needs Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45957#M33768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Never Mind - I figured it out..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sweet!!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Oct 2011 12:42:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45957#M33768</guid>
      <dc:creator>WayneFusco</dc:creator>
      <dc:date>2011-10-08T12:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Newbee Needs Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45958#M33769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay maybe not. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dont know what needs to happen to connect from the outside world..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Oct 2011 13:42:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45958#M33769</guid>
      <dc:creator>WayneFusco</dc:creator>
      <dc:date>2011-10-08T13:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Newbee Needs Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45959#M33770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have an Inbound NAT rule associated with the security policy? Untrust to Untrust for the zones, public facing ip for the destination address and then dnat it to your private ip address hosting the services in question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Oct 2011 20:22:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45959#M33770</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-10-08T20:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Newbee Needs Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45960#M33771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you break it down for me,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remember i am a newbee..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the NAT policy I have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SZ: untrust DZ: trust DI: none SA: any DA: OWA ST: dyn ip &amp;amp; port ether1/3 &amp;amp; my pubic ip DT: address:owa port:433&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this on the right track?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Oct 2011 00:16:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45960#M33771</guid>
      <dc:creator>WayneFusco</dc:creator>
      <dc:date>2011-10-09T00:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: Newbee Needs Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45961#M33772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For any incoming connection, the NAT policy shouldbe like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Original&lt;/P&gt;&lt;P&gt;SRC Zone: untrust, src IP: any &lt;/P&gt;&lt;P&gt;Dst Zone: untrust, dst IP: public IP of OWA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Translated:&lt;/P&gt;&lt;P&gt;Src IP: any any&lt;/P&gt;&lt;P&gt;Dst IP: private IP, Static IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For security:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Src Zone: Untrust, src IP: any&lt;/P&gt;&lt;P&gt;Dst Zone: DMZ, dst IP: public IP&lt;/P&gt;&lt;P&gt;Application: SSL (as OWA is encrypted)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jones&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Oct 2011 11:15:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45961#M33772</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-10-09T11:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Newbee Needs Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45962#M33773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;- Application 'outlook-web' requires 'ssl' allowed in the policy - &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;In your policy In services allow tcp-443&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;- Application 'outlook-web' requires 'web-browsing' allowed in the policy - &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;In your policy In services allow tcp-80.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt"&gt;See if this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 13:46:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbee-needs-help/m-p/45962#M33773</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-11T13:46:21Z</dc:date>
    </item>
  </channel>
</rss>

