<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Lync 2013 | Skype 2015 &amp;gt; How to setup Security (app-id / ports) for transparent AV/Sip/Web Services in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lync-2013-skype-2015-gt-how-to-setup-security-app-id-ports-for/m-p/70576#M40549</link>
    <description>&lt;P&gt;Palo’s&lt;/P&gt;
&lt;P&gt;I have searched, read these forums and have gone through many manuals, suggestions from the Internet regarding Palo (2020 Series) configuration to secure Lync 2013 / Skype Business 2015: but still experiencing some issues with how to setup our Firewall for Federation access.&lt;/P&gt;
&lt;P&gt;From a company perspective, our Lync is working great, our external road warriors can use Lync via VPN or Publically with all functions.&lt;/P&gt;
&lt;P&gt;The issues come up where we have Federated (open or controlled either way) with external users / other companies. Seems there is a configuration issue somewhere on our Palo where:&lt;/P&gt;
&lt;P&gt;A Federated User:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Can see us (presence status) online&lt;/LI&gt;
&lt;LI&gt;Can send us an IM&lt;/LI&gt;
&lt;LI&gt;Can send us a file&lt;/LI&gt;
&lt;LI&gt;Can send us a meeting&lt;/LI&gt;
&lt;LI&gt;Can send us a whiteboard&lt;/LI&gt;
&lt;LI&gt;CANNOT Lync Call Us&lt;/LI&gt;
&lt;LI&gt;CANNOT Desktop Share to Us..&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;So, our Lync is setup as close to Microsoft guides as possible, using 3x public IP’s per service. It’s the 3&lt;SUP&gt;rd&lt;/SUP&gt; IP (av.domain.com) service that needs ports (tcp/udp/rtp) 50,000-59,999, 3478, 5061 and 443/80.&lt;/P&gt;
&lt;P&gt;We even gone as far as using an “any” rule to test if its our Edge Server, but its not Edge… something we missed… Has anyone successfully deployed Lync 2013 / Skype Business 2015 using App-ID level? Can you share your settings just for Lync/Skype.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greatly appreciated&lt;/P&gt;</description>
    <pubDate>Fri, 08 Jan 2016 15:47:06 GMT</pubDate>
    <dc:creator>SharedMedia</dc:creator>
    <dc:date>2016-01-08T15:47:06Z</dc:date>
    <item>
      <title>Lync 2013 | Skype 2015 &gt; How to setup Security (app-id / ports) for transparent AV/Sip/Web Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lync-2013-skype-2015-gt-how-to-setup-security-app-id-ports-for/m-p/70576#M40549</link>
      <description>&lt;P&gt;Palo’s&lt;/P&gt;
&lt;P&gt;I have searched, read these forums and have gone through many manuals, suggestions from the Internet regarding Palo (2020 Series) configuration to secure Lync 2013 / Skype Business 2015: but still experiencing some issues with how to setup our Firewall for Federation access.&lt;/P&gt;
&lt;P&gt;From a company perspective, our Lync is working great, our external road warriors can use Lync via VPN or Publically with all functions.&lt;/P&gt;
&lt;P&gt;The issues come up where we have Federated (open or controlled either way) with external users / other companies. Seems there is a configuration issue somewhere on our Palo where:&lt;/P&gt;
&lt;P&gt;A Federated User:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Can see us (presence status) online&lt;/LI&gt;
&lt;LI&gt;Can send us an IM&lt;/LI&gt;
&lt;LI&gt;Can send us a file&lt;/LI&gt;
&lt;LI&gt;Can send us a meeting&lt;/LI&gt;
&lt;LI&gt;Can send us a whiteboard&lt;/LI&gt;
&lt;LI&gt;CANNOT Lync Call Us&lt;/LI&gt;
&lt;LI&gt;CANNOT Desktop Share to Us..&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;So, our Lync is setup as close to Microsoft guides as possible, using 3x public IP’s per service. It’s the 3&lt;SUP&gt;rd&lt;/SUP&gt; IP (av.domain.com) service that needs ports (tcp/udp/rtp) 50,000-59,999, 3478, 5061 and 443/80.&lt;/P&gt;
&lt;P&gt;We even gone as far as using an “any” rule to test if its our Edge Server, but its not Edge… something we missed… Has anyone successfully deployed Lync 2013 / Skype Business 2015 using App-ID level? Can you share your settings just for Lync/Skype.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greatly appreciated&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2016 15:47:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lync-2013-skype-2015-gt-how-to-setup-security-app-id-ports-for/m-p/70576#M40549</guid>
      <dc:creator>SharedMedia</dc:creator>
      <dc:date>2016-01-08T15:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: Lync 2013 | Skype 2015 &gt; How to setup Security (app-id / ports) for transparent AV/Sip/Web Se</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lync-2013-skype-2015-gt-how-to-setup-security-app-id-ports-for/m-p/70650#M40568</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you post the MS guide/specifications and your topology&amp;nbsp;for Lync 2013. A few questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Are you doing any decryption on the traffic?&lt;/P&gt;
&lt;P&gt;2. STUN protocol is working properly?&lt;/P&gt;
&lt;P&gt;3. my-lync-video and my-lync-audio applications are allowed?&lt;/P&gt;
&lt;P&gt;4. Does the Lync Call and desktop sharing work if bypass PA?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest to open a case with Technical Support&amp;nbsp;to look into this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 02:08:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lync-2013-skype-2015-gt-how-to-setup-security-app-id-ports-for/m-p/70650#M40568</guid>
      <dc:creator>abjain</dc:creator>
      <dc:date>2016-01-11T02:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Lync 2013 | Skype 2015 &gt; How to setup Security (app-id / ports) for transparent AV/Sip/Web Se</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lync-2013-skype-2015-gt-how-to-setup-security-app-id-ports-for/m-p/70695#M40580</link>
      <description>&lt;P&gt;Abjain,&lt;/P&gt;
&lt;P&gt;Configs in General... note we do not use DNS for natting, this was optional..&lt;/P&gt;
&lt;P&gt;Based on Microsoft Ports, we know the App-ID related to Lync, but... should we use ports or App-ID's?&lt;/P&gt;
&lt;P&gt;Keeping in mind the App-ID "sip" uses port 5060, and there is an OLD OCS app-ID for port 5061.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG title="Lync2013" alt="Lync2013" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1987i71EE0BA4B3C28782/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Are you doing any decryption on the traffic? NO&lt;/P&gt;
&lt;P&gt;2. STUN protocol is working properly? YES&lt;/P&gt;
&lt;P&gt;3. my-lync-video and my-lync-audio applications are allowed? YES&lt;/P&gt;
&lt;P&gt;4. Does the Lync Call and desktop sharing work if bypass PA? YES&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 18:48:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lync-2013-skype-2015-gt-how-to-setup-security-app-id-ports-for/m-p/70695#M40580</guid>
      <dc:creator>SharedMedia</dc:creator>
      <dc:date>2016-01-11T18:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Lync 2013 | Skype 2015 &gt; How to setup Security (app-id / ports) for transparent AV/Sip/Web Se</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lync-2013-skype-2015-gt-how-to-setup-security-app-id-ports-for/m-p/70727#M40585</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are a lot of components involved, so I would suggest opening a case with TAC as per your time zone and have them take a look. If 'any' rule did not help, it has to be something else, like a ALG issue or something.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2016 00:58:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lync-2013-skype-2015-gt-how-to-setup-security-app-id-ports-for/m-p/70727#M40585</guid>
      <dc:creator>abjain</dc:creator>
      <dc:date>2016-01-12T00:58:55Z</dc:date>
    </item>
  </channel>
</rss>

