<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow Office 365 not getting desired results... in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64369#M38613</link>
    <description>&lt;P&gt;That's what we did...Just dumped the URLs into a custom URL Category.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Sep 2015 18:21:46 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2015-09-09T18:21:46Z</dc:date>
    <item>
      <title>Allow Office 365 not getting desired results...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64335#M38593</link>
      <description>&lt;P&gt;Hei,&lt;/P&gt;&lt;P&gt;We recently moved over to a full O365 solution and I am trying to customise the ruleset to Allow for O365 traffic when all other traffic is blocked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately I have hit a wall and cannot seem to get the application to be allowed. I am hoping one of you can point out what I have done wrong and how to correct it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have used Addresses (with FQDN) and Address Groups where I have defined all the sites that MS states are required. List is here: &lt;A href="https://support.office.com/en-au/article/Office-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-abb1-355ea5aa88a2?ui=en-US&amp;amp;rs=en-AU&amp;amp;ad=AU" target="_blank"&gt;Office 365 URLs and IPs&lt;/A&gt;&amp;nbsp;[Ideally I'd avoid using IPs as these are subject to change. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; ]&lt;/P&gt;&lt;P&gt;I then changed the top level policy to allow for the Address Group.&lt;/P&gt;&lt;P&gt;In testing, the client pc is able to start Office and receives the login screen but no login is able to complete. In the Monitor of PAN it details Destination as an IP and Application as "not-applicable"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also tried using the predefined Application setting (ms-office365), but then on the client pc it does not even resolve to the login screen, just displaying a bland "Unable to connect" pop-up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any advice!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2015 12:34:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64335#M38593</guid>
      <dc:creator>LCMember172</dc:creator>
      <dc:date>2015-09-09T12:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Allow Office 365 not getting desired results...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64336#M38594</link>
      <description>&lt;P&gt;Try one more thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Allow everything from that test machine and check the logs what all application are required to allow the access to office365 don't use URL filtering first. Then narrow down the security policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create a deny any any for that IP and check what all applicaiton are blocked and then add them to the allowed rule.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2015 13:02:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64336#M38594</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-09-09T13:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: Allow Office 365 not getting desired results...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64347#M38603</link>
      <description>&lt;P&gt;I have previously tried that and according to the Monitor, the Applications are (ms-office365-base), (web-browsing) and (ssl).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, these machines will be used by students in exams, so allowing for internet based traffic would be a bad idea...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2015 14:00:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64347#M38603</guid>
      <dc:creator>LCMember172</dc:creator>
      <dc:date>2015-09-09T14:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Allow Office 365 not getting desired results...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64352#M38605</link>
      <description>&lt;P&gt;Use URL categories , not FQDN !! they are absolutly not the same thing !!!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2015 14:57:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64352#M38605</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-09-09T14:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: Allow Office 365 not getting desired results...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64355#M38608</link>
      <description>&lt;P&gt;You can get two things from the logs application and IP/fdqn. Now add applicaiton and Destination address in rules in this way it will not allow access to other webistes.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2015 15:28:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64355#M38608</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-09-09T15:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Allow Office 365 not getting desired results...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64369#M38613</link>
      <description>&lt;P&gt;That's what we did...Just dumped the URLs into a custom URL Category.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2015 18:21:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64369#M38613</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-09-09T18:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: Allow Office 365 not getting desired results...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64410#M38629</link>
      <description>&lt;P&gt;Still not getting the desired results. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried the following (and a combination of the following):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Taken all the URLs and placed them in a&amp;nbsp;new URL category in Objects. Placed this into the main Policy that allows for traffic irrespective of when we have to close access to the internet. Result = access still blocked&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Taken all the individual IPs (599 of them) and placed them into a URL category in Objects. And updated this to the main rule. Result = no access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) In a pique of curiosity - I created the rule to allow for all traffic to "www.*.com" and "*.com". And that didnt work either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4) I have opened up all traffic, took a copy of the destinations that were used, created a rule for them and tried that once the blocks were in place...nope.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5) I have gone through the Application filters and updated the main policy to allow for ms-office365 and all other derivaties I could find...but that didnt work either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So - any other tips? I am not a network specialist (clients &amp;amp; scripting&amp;nbsp;are my main) but I cannot understand why it is not working or what is actually been blocked. Unfortunatley too much information is been hidden within the "not-application" description in the Monitor. I can see that the IPs are within the correct subnet range and ports are correct (80 and 443) for Office365 traffic. But why are the applications getting hidden by "not-applicable"?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2015 12:36:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64410#M38629</guid>
      <dc:creator>ABAdmin</dc:creator>
      <dc:date>2015-09-10T12:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Allow Office 365 not getting desired results...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64458#M38636</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/35305"&gt;@ABAdmin﻿&lt;/a&gt;&amp;nbsp;From TAC, I've been told to not use IP addresses in custom URL categories. &amp;nbsp;Only use them in address groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2015 19:44:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64458#M38636</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-09-10T19:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Allow Office 365 not getting desired results...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64469#M38640</link>
      <description>&lt;P&gt;Ok will give that a try, thanks for the tip.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 06:04:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64469#M38640</guid>
      <dc:creator>ABAdmin</dc:creator>
      <dc:date>2015-09-11T06:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Allow Office 365 not getting desired results...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64488#M38643</link>
      <description>&lt;P&gt;Also, last night I was looking through our applications as my company use O365 too. &amp;nbsp;I'm not sure what part of the service you're using but we allow:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ms-office365-base&lt;/P&gt;&lt;P&gt;outlook-web-online&lt;BR /&gt;sharepoint-base&lt;BR /&gt;sharepoint-online&lt;BR /&gt;sharepoint-documents&lt;BR /&gt;office-on-demand&lt;BR /&gt;skydrive-base&lt;BR /&gt;live-mesh-base&lt;BR /&gt;SSL&lt;BR /&gt;web-browsing&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 12:58:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64488#M38643</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-09-11T12:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Allow Office 365 not getting desired results...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64490#M38645</link>
      <description>&lt;P&gt;&lt;SPAN&gt;A custom&amp;nbsp;URL category added to a URL filtering profile on the rule with the required office 365 app-ids may work but it may also be a bit hit and miss.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;URL categories are very handy when you want to more accurately match traffic against a specific rule.&amp;nbsp;The good thing about URL categories is these are used as an additional match criteria for the rule. For example if you want to all allow traffic on an office 365 with an SSL and web-browsing dependancy app-ids coming from a trusted zone going to the untrusted zone and a URL category is applied with the appropriate URL matches, all three components will need to match before the traffic will be allowed by this rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my experience they have proven more reliable way of ensuring the right traffic hits the right rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 13:25:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64490#M38645</guid>
      <dc:creator>ethiSEC</dc:creator>
      <dc:date>2015-09-11T13:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: Allow Office 365 not getting desired results...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64775#M38766</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz﻿&lt;/a&gt;: We added those previously and nothing - traffic was still blocked for some or other reason&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the end we resolved this by adding every IPv4 address MS has listed to Addresses with an appropriate Tag.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Address Groups we created a Dynamic Group based on the aforementioned Tag.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Policies we allowed for the Address Group. And now our clients are able to authenticate the Office 365 license. The authentication process is ridiculousloy slow though. With all traffic enabled, license authentication takes a second or two. With the internet restricted and this rule in place...it takes 2 - 3 minutes to authenticate. Very strange this, not to sure where the optimisation must be done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we only need to get a license, we only added all IPs relating to Portal and ID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Ps: But...to cover our bases - I have also added the IPv6 to Addresses,&amp;nbsp;URLs to URL Category and created an Application Group based on the needed O365 applications in the PAN-2020. Nothing wrong with a little overkill &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers and thanks for the help&lt;/P&gt;&lt;P&gt;Anthony&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 07:32:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-office-365-not-getting-desired-results/m-p/64775#M38766</guid>
      <dc:creator>ABAdmin</dc:creator>
      <dc:date>2015-09-18T07:32:03Z</dc:date>
    </item>
  </channel>
</rss>

