<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to allow access to OWA to selected external users? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-access-to-owa-to-selected-external-users/m-p/1154#M905</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was hoping to get couple ideas on the problem that we currently have and cannot give a solution yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About a year ago we were able to migrate our old firewalls infrastructure to PAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had 1 firewall facing internet(Sidewinder) - basically for Destination NAT functions, MS ISA server as proxy and main firewall (behind Sidewinder) and Microsoft TMG for IPSec VPN only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have migrated all of these legacy devices to a A/P Pair of 5050 with vsys - 1 vsys for Sidewinder, 1 vsys for ISA and 1 for TMG.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, because of native functionality of ISA Server, our customer was able to select certain outside(external) users to allow access to Public OWA portal while blocking the rest and users located inside customer's network all were able to connect to OWA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After we've culminated migration, this functionality being lost and it is very important to implement something similar.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tools available to us at this moment are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA5050 with 22 vsys available&lt;/P&gt;&lt;P&gt;AD access&lt;/P&gt;&lt;P&gt;Captive Portal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We were working on Reverse Proxy from other brands, but it requires additional cost and we are not allowed to do so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please, any ideas or help would be extremely appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Val&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Jun 2015 13:05:57 GMT</pubDate>
    <dc:creator>Sobolenko</dc:creator>
    <dc:date>2015-06-10T13:05:57Z</dc:date>
    <item>
      <title>How to allow access to OWA to selected external users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-access-to-owa-to-selected-external-users/m-p/1154#M905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was hoping to get couple ideas on the problem that we currently have and cannot give a solution yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About a year ago we were able to migrate our old firewalls infrastructure to PAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had 1 firewall facing internet(Sidewinder) - basically for Destination NAT functions, MS ISA server as proxy and main firewall (behind Sidewinder) and Microsoft TMG for IPSec VPN only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have migrated all of these legacy devices to a A/P Pair of 5050 with vsys - 1 vsys for Sidewinder, 1 vsys for ISA and 1 for TMG.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, because of native functionality of ISA Server, our customer was able to select certain outside(external) users to allow access to Public OWA portal while blocking the rest and users located inside customer's network all were able to connect to OWA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After we've culminated migration, this functionality being lost and it is very important to implement something similar.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tools available to us at this moment are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA5050 with 22 vsys available&lt;/P&gt;&lt;P&gt;AD access&lt;/P&gt;&lt;P&gt;Captive Portal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We were working on Reverse Proxy from other brands, but it requires additional cost and we are not allowed to do so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please, any ideas or help would be extremely appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Val&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2015 13:05:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-access-to-owa-to-selected-external-users/m-p/1154#M905</guid>
      <dc:creator>Sobolenko</dc:creator>
      <dc:date>2015-06-10T13:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow access to OWA to selected external users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-access-to-owa-to-selected-external-users/m-p/1155#M906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could create a rule leveraging CP. First create a rule in CP to the external IPs to prompt user with the CP page.&amp;nbsp; Then create a security rule to allow access by source IP filter (based on static IP address or a geographic location) and by source user in a specific AD group to be able to login.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2015 13:29:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-access-to-owa-to-selected-external-users/m-p/1155#M906</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2015-06-10T13:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow access to OWA to selected external users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-access-to-owa-to-selected-external-users/m-p/327164#M83273</link>
      <description>&lt;P&gt;what about if i want to do the same for other application , i mean for exchange Active Sync&lt;SPAN&gt;&amp;nbsp; on mobile too&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 May 2020 12:29:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-access-to-owa-to-selected-external-users/m-p/327164#M83273</guid>
      <dc:creator>Eslam.Basyouni</dc:creator>
      <dc:date>2020-05-09T12:29:06Z</dc:date>
    </item>
  </channel>
</rss>

