<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Skype is not working with allow rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117882#M45601</link>
    <description>&lt;P&gt;Thanks for the help guys. I did the allow all rule with one source and when Skype didnt work we realised its not FW issue. However, we pluged the machine directly with the router towards the internet and it didn't work also, then we change the DNS to public on (8.8.8.8) and everything was working perfectly. They have an issue with their DNS server.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Oct 2016 18:38:03 GMT</pubDate>
    <dc:creator>MohamedSharief</dc:creator>
    <dc:date>2016-10-05T18:38:03Z</dc:date>
    <item>
      <title>Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117171#M45549</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a demand to allow skype for internal employees. However, we've created a security rule to allow the following applications:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-skype&lt;/P&gt;&lt;P&gt;-skype-probe&lt;/P&gt;&lt;P&gt;-ssl/web-browsing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still skype couldn't connect with an error message "please check your internet connection and try again".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I've added *.skype.com/* in the URL filteration &amp;gt; still doesn't work&lt;/P&gt;&lt;P&gt;Also I tried to user web-browsing instead of ssl &amp;gt; still doesn't work&lt;/P&gt;&lt;P&gt;and finally I've added both ssl &amp;amp; web-browsing &amp;gt; still doesn't work&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I checked the traffic log I found the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Session end reason: tcp-rst-from-client &amp;amp; tcp-fin &amp;amp; n/a&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know exactly whats going on here?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 10:25:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117171#M45549</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-10-03T10:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117180#M45550</link>
      <description>&lt;P&gt;1-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Appliance Model: PA-500&lt;/P&gt;&lt;P&gt;2-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PAN-OS version: 7.1.3&lt;/P&gt;&lt;P&gt;3-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Applications Version: 599-3443&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 11:07:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117180#M45550</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-10-03T11:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117190#M45552</link>
      <description>&lt;P&gt;What rule is the traffic actually hitting as it stands, and where is the allow rule in corelation within your lists of security policies? It sounds like you are hitting a pretty strict deny rule, as if this was a consumer version of Skype then it will fall back to port 80/443. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 13:06:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117190#M45552</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-10-03T13:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117198#M45554</link>
      <description>&lt;P&gt;Traffic is hitting the same rule created for Skype as mentioned in traffic log. The rule I've created is located in the top of the policies.&lt;/P&gt;&lt;P&gt;The weird thing is skype is not even allowing me to enter a username and password, the front page of skype never displayed, it will just start loading then "check your internet connection" will pops up.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 13:26:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117198#M45554</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-10-03T13:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117201#M45555</link>
      <description>&lt;P&gt;Can you please check if you have denied unknown-udp sessions dropped on high UDP ports towards Microsoft public IP addresses?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have found a situation where skype and skype-probe is allowed with application rule, TCP 443 is allowed as service (in seperate rule ofc) and Skype still isn't working. I've noticed connection towards Microsoft IP addresses on high UDP ports 'recognised' as unknown-udp and of course dropped. Skype should be working without having to allow unknown-udp session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone else has similar problems with Skype?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 13:51:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117201#M45555</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-10-03T13:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117208#M45556</link>
      <description>&lt;P&gt;I've already thought about adding unknown-udp to the policy and infomred the client to made the changes. Waiting his reply now.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 13:56:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117208#M45556</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-10-03T13:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117214#M45557</link>
      <description>&lt;P&gt;Aaaaaand its still not working. Even when we added the unknown-udp to the policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the traffic log I noticed when the type is "end" the session end reason is either "tcp-rst-from-client" or "tcp-fin" but when the type is start the session end reason is always n/a.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 14:13:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117214#M45557</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-10-03T14:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117241#M45559</link>
      <description>&lt;P&gt;I would test with a single source IP address allocated an 'any any' rule without any blocks in place and see if you still recieve the error. That would at the very least tell you if it's actually a rule issue. If that works I would request a config export since it seems like you are working with someone offsite and don't have direct access to the equipment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 15:59:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117241#M45559</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-10-03T15:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117266#M45561</link>
      <description>&lt;P&gt;Great idea BPry. I'll make sure to implement that tomorrow. Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 18:24:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117266#M45561</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-10-03T18:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117412#M45567</link>
      <description>&lt;P&gt;I've created "any to any" policy where the source address is the engineer's laptop, then added skype, skype-probe and unkown-udb to the list of applications and committed the changes. This time I got a warning that to enable skype I must add msn-base, ssl and web-browsing. I committed without adding those then tried but failed, then I added apps in warning but still doesn't work. When I checked the logs again I got on start session n/a as session end reason and on end session tcp-rst-from-client &amp;amp; tcp-fin as session end reasons.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea on whats going on guys?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 07:01:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117412#M45567</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-10-04T07:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117459#M45570</link>
      <description>&lt;P&gt;Have you tried the same rule, but with Any/Any as application and service? If Skype still does not work then I would suspect that it might be a client problem.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 09:50:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117459#M45570</guid>
      <dc:creator>LCMember1959</dc:creator>
      <dc:date>2016-10-04T09:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117493#M45572</link>
      <description>&lt;P&gt;I will try that Terje.&lt;/P&gt;&lt;P&gt;When I added the policy "any any" today and commit the changes I got a warning that msn-base, ssl and web-browsing should be allowed as dependency apps also, but when I checked in &lt;A href="https://applipedia.paloaltonetworks.com/" target="_blank"&gt;https://applipedia.paloaltonetworks.com/&lt;/A&gt; its not required. To double check this I shoot the command #show predefined application skype and those dependency apps were included. But again I've already tried and added them and still doesn't work.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 12:43:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117493#M45572</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-10-04T12:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117494#M45573</link>
      <description>&lt;P&gt;I guess what I meant as an 'any any' rule was that it would be any destination and any applicaiton. This placed above all other security rules will let you know if this is a firewall issue or a network issue. If you still can't get to Skype with a set source address, any destination, and any application set to allow then it would indicate that your firewall isn't at fault here; something in front of your firewall is to blame for the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 13:25:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117494#M45573</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-10-04T13:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117552#M45575</link>
      <description>&lt;P&gt;Anything in the threat log that shows traffic being blocked?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 16:53:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117552#M45575</guid>
      <dc:creator>RFalconer</dc:creator>
      <dc:date>2016-10-04T16:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117719#M45587</link>
      <description>&lt;P&gt;Is nothing working with Skype or just for example video conversation?&lt;/P&gt;&lt;P&gt;I had the problem lately that chat and audio were working but video wasn't.&lt;/P&gt;&lt;P&gt;It turned out I was missing the "Jabber" application in the allow rule.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 07:58:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117719#M45587</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2016-10-05T07:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117882#M45601</link>
      <description>&lt;P&gt;Thanks for the help guys. I did the allow all rule with one source and when Skype didnt work we realised its not FW issue. However, we pluged the machine directly with the router towards the internet and it didn't work also, then we change the DNS to public on (8.8.8.8) and everything was working perfectly. They have an issue with their DNS server.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 18:38:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/117882#M45601</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-10-05T18:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/137291#M47778</link>
      <description>&lt;P&gt;Nice job, we were experiencing the same issue. &amp;nbsp;What made you decided to try external DNS servers? &amp;nbsp;Is there a specific URL that is not being resolved?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2017 01:17:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/137291#M47778</guid>
      <dc:creator>rkoenig</dc:creator>
      <dc:date>2017-01-13T01:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/139101#M48068</link>
      <description>&lt;P&gt;I believe that might be the reason but honestly I didn't try changing the DNS server on the testing machine till I ran out of all options on PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sharief&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 13:48:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/139101#M48068</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2017-01-24T13:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: Skype is not working with allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/141881#M48457</link>
      <description>&lt;P&gt;Facing same problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Skype in my Organization with these Destination and apps (need simple solution).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;skype&lt;BR /&gt;skype-probe&lt;BR /&gt;office365-consumer-access&lt;BR /&gt;ssl&lt;BR /&gt;stun&lt;BR /&gt;web-browsing&lt;BR /&gt;websocket&lt;BR /&gt;ms-lync-base&lt;BR /&gt;ms-lync-audio&lt;BR /&gt;ms-lync-video&lt;BR /&gt;rtcp&lt;BR /&gt;rtp-base&lt;/P&gt;&lt;P&gt;unknown-udp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;91.190.216.0/21&lt;BR /&gt;65.52.0.0/14&lt;BR /&gt;64.4.0.0/18&lt;BR /&gt;52.234.0.0/11&lt;BR /&gt;40.0.0.0/8&lt;BR /&gt;213.199.0.0/16&lt;BR /&gt;157.56.0.0/14&lt;BR /&gt;13.107.0.0/16&lt;BR /&gt;111.221.0.0/17&lt;BR /&gt;104.40.0.0/13&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Skype website:&lt;/P&gt;&lt;P&gt;To work correctly, Skype requires unrestricted outgoing TCP access to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;All destination ports above 1024 (recommended)&lt;P&gt;or&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Ports 80 and 443&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;support.skype.com/en/faq/FA148/which-ports-need-to-be-open-to-use-skype-for-windows-desktop&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sajid&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 15:44:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-is-not-working-with-allow-rule/m-p/141881#M48457</guid>
      <dc:creator>SajidAliSajid</dc:creator>
      <dc:date>2017-02-08T15:44:28Z</dc:date>
    </item>
  </channel>
</rss>

