<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allowing Lync: enabling SSL decryption blocks it in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-lync-enabling-ssl-decryption-blocks-it/m-p/70646#M40566</link>
    <description>&lt;P&gt;Actually, I tried that ("As a test, I added a no-decrypt rule for MS/Lync URL's, but that doesn't really make a difference.") using the list of URL's &amp;amp; IP addresses at: &lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.office.com/en-gb/article/Office-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-abb1-355ea5aa88a2?ui=en-US&amp;amp;rs=en-GB&amp;amp;ad=GB#BKMK_LYO" target="_blank"&gt;https://support.office.com/en-gb/article/Office-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-abb1-355ea5aa88a2?ui=en-US&amp;amp;rs=en-GB&amp;amp;ad=GB#BKMK_LYO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But it still seems to fail on session age-outs..&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1981i2891582FD10455D8/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="age out 2.PNG" title="age out 2.PNG" border="0" /&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Jan 2016 15:31:09 GMT</pubDate>
    <dc:creator>Arne-VDH</dc:creator>
    <dc:date>2016-01-10T15:31:09Z</dc:date>
    <item>
      <title>Allowing Lync: enabling SSL decryption blocks it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-lync-enabling-ssl-decryption-blocks-it/m-p/70632#M40562</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In a test setup I'm trying to allow MS-Lync while SSL decryption is enabled.&lt;/P&gt;
&lt;P&gt;I've got a general rule to enable SSL Decryption with the proper certificate installed on the clients end.&lt;/P&gt;
&lt;P&gt;In my security policies I've got a rule to allow Lync based on App-ID.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1978iD19B4765B36E6F6D/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="Allow-Lync.PNG" title="Allow-Lync.PNG" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;Lync however refuses to even sign in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only thing I have noticed that DNS requests seeem to age out for a to me unknown reason:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1979iEA57808155E7483E/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="age out.PNG" title="age out.PNG" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a test, I added a no-decrypt rule for MS/Lync URL's, but that doesn't really make a difference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As soon as I disable the decryption rule, all works fine (but of course allows more than I would want). How can I exclude lync from being decrypted, or even better, how do I get Lync to get through with decryption enabled?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On: &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/List-of-Applications-Excluded-from-SSL-Decryption/ta-p/62201" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/List-of-Applications-Excluded-from-SSL-Decryption/ta-p/62201&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;there is a comment at the bottom from someone stating the issue that Lync is failing when SSL decryption is enabled, but he refers to a broken link. Any suggestions?&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jan 2016 16:41:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-lync-enabling-ssl-decryption-blocks-it/m-p/70632#M40562</guid>
      <dc:creator>Arne-VDH</dc:creator>
      <dc:date>2016-01-09T16:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing Lync: enabling SSL decryption blocks it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-lync-enabling-ssl-decryption-blocks-it/m-p/70641#M40563</link>
      <description>&lt;P&gt;You have to stop decryption for lync otherwise it will fail. To stop decrypting you can create a customer URL category and inside that you have specify the URL used by your lync.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To find out the URL used by lync:&lt;/P&gt;
&lt;P&gt;1&amp;gt; Create a URL filtering profile which have action for all category as alert.&lt;/P&gt;
&lt;P&gt;2&amp;gt; Create a security policy to allow only lync traffic for one specific host and apply the URL filtering profile in this security policy.&lt;/P&gt;
&lt;P&gt;3&amp;gt;Create another security policy to deny everything for that sepecific host.&lt;/P&gt;
&lt;P&gt;4&amp;gt; Do a commit and check if the lync is working or not if it is not working allow more applicaitons.&lt;/P&gt;
&lt;P&gt;5&amp;gt; Now if the lycn is working you will get the URL allowed by the security policy from URL logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Take these URLs and apply them into customer url Category. Call the custom URL cateogry into the no decrypt rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jan 2016 04:29:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-lync-enabling-ssl-decryption-blocks-it/m-p/70641#M40563</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-01-10T04:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing Lync: enabling SSL decryption blocks it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-lync-enabling-ssl-decryption-blocks-it/m-p/70646#M40566</link>
      <description>&lt;P&gt;Actually, I tried that ("As a test, I added a no-decrypt rule for MS/Lync URL's, but that doesn't really make a difference.") using the list of URL's &amp;amp; IP addresses at: &lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.office.com/en-gb/article/Office-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-abb1-355ea5aa88a2?ui=en-US&amp;amp;rs=en-GB&amp;amp;ad=GB#BKMK_LYO" target="_blank"&gt;https://support.office.com/en-gb/article/Office-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-abb1-355ea5aa88a2?ui=en-US&amp;amp;rs=en-GB&amp;amp;ad=GB#BKMK_LYO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But it still seems to fail on session age-outs..&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1981i2891582FD10455D8/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="age out 2.PNG" title="age out 2.PNG" border="0" /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jan 2016 15:31:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-lync-enabling-ssl-decryption-blocks-it/m-p/70646#M40566</guid>
      <dc:creator>Arne-VDH</dc:creator>
      <dc:date>2016-01-10T15:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing Lync: enabling SSL decryption blocks it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-lync-enabling-ssl-decryption-blocks-it/m-p/70647#M40567</link>
      <description>&lt;P&gt;Could you attach the custom url category that you have created for not decrypt. Also the screenshot for the URL filtering logs.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jan 2016 17:30:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-lync-enabling-ssl-decryption-blocks-it/m-p/70647#M40567</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-01-10T17:30:42Z</dc:date>
    </item>
  </channel>
</rss>

