<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBF for Office 365 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116205#M98561</link>
    <description>&lt;P&gt;yes, that should work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Sep 2016 17:07:26 GMT</pubDate>
    <dc:creator>lmori</dc:creator>
    <dc:date>2016-09-27T17:07:26Z</dc:date>
    <item>
      <title>PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78249#M98550</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One of our startegic customer is requesting the possibility to route just the O365 traffic to a specific link and after researching about this&amp;nbsp;I think that the best is using MineMeld to automatically feed a list of application IP adrress&amp;nbsp;but I did't find any documentation describing how to perform this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any of you have used the MineMeld to monitor the O365 address and imput this into PANW and can share some details with me?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you and regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 18:06:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78249#M98550</guid>
      <dc:creator>rrunge1</dc:creator>
      <dc:date>2016-05-17T18:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78387#M98551</link>
      <description>&lt;P&gt;We at least one customer using PBF with IP list dynamically downloaded via DBL to route O365 traffic over a specific link. They are not using MineMeld yet, but its predecessor &lt;A href="https://panwdbl.appspot.com." target="_blank"&gt;https://panwdbl.appspot.com.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So yes, I would definitely test and use MineMeld for this scenario.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 14:17:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78387#M98551</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-05-19T14:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78388#M98552</link>
      <description>&lt;P&gt;Imori, can you share how they are using DBL to do this?&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;We at least one customer using PBF with IP list dynamically downloaded via DBL to route O365 traffic over a specific link. They are not using MineMeld yet, but its predecessor &lt;A href="https://panwdbl.appspot.com." target="_blank"&gt;https://panwdbl.appspot.com.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So yes, I would definitely test and use MineMeld for this scenario.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 14:28:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78388#M98552</guid>
      <dc:creator>rrunge1</dc:creator>
      <dc:date>2016-05-19T14:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78481#M98553</link>
      <description>&lt;P&gt;Hi rrunge1,&lt;/P&gt;
&lt;P&gt;you can use a DBL as target for the PBF rule. DBL is populated with O365 IP addresses by O365 Miners.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 07:44:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78481#M98553</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-05-23T07:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78611#M98554</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;Hi rrunge1,&lt;/P&gt;
&lt;P&gt;you can use a DBL as target for the PBF rule. DBL is populated with O365 IP addresses by O365 Miners.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P class="p1"&gt;Luigi,&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;I created the miner using the prototype&amp;nbsp;Office365.O365 &amp;nbsp;but apparently there are some&amp;nbsp;IPs missing&amp;nbsp; in the default list comparing from:&amp;nbsp;&lt;A href="https://support.content.office.net/en-us/static/O365IPAddresses.xml" target="_blank"&gt;https://support.content.office.net/en-us/static/O365IPAddresses.xml&lt;/A&gt; aren't part of&amp;nbsp;Office365.O365 miner.&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;I tried to customize the prototype&amp;nbsp;using the address above and could collect more than 1000 indicators from the xml but the processor doesn't understand the format.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 21:52:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78611#M98554</guid>
      <dc:creator>rrunge1</dc:creator>
      <dc:date>2016-05-24T21:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78624#M98555</link>
      <description>&lt;P&gt;Hi rrunge1,&lt;/P&gt;
&lt;P&gt;Microsoft splits the IP addresses and URLs used for O365 in 17 different lists, one for each O365 service.&lt;/P&gt;
&lt;P&gt;Each service has a corresponding Miner in MineMeld. If you want to gather all the IPs you need all the Miners. Basically your graph should look like this one:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2016-05-25 at 10.08.47.png" style="width: 674px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4144iC209AE7C85659F71/image-dimensions/674x453/is-moderation-mode/true?v=v2" width="674" height="453" role="button" title="Screen Shot 2016-05-25 at 10.08.47.png" alt="Screen Shot 2016-05-25 at 10.08.47.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;

&lt;P&gt;You can download the config here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://paloaltonetworks.box.com/s/4ubmkgrq72a8mdd24j733ddqdgbkyvv4" target="_blank"&gt;https://paloaltonetworks.box.com/s/4ubmkgrq72a8mdd24j733ddqdgbkyvv4&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To use it you should:&lt;/P&gt;
&lt;P&gt;- upload the file to the VM via SCP or SFTP (you can use Filezilla on Windows)&lt;/P&gt;
&lt;P&gt;- login into the VM via SSH&lt;/P&gt;
&lt;P&gt;- and then&lt;/P&gt;
&lt;PRE&gt;$ sudo -u minemeld cp office365-config.yml /opt/minemeld/local/config/committed-config.yml
$ sudo service minemeld restart&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 08:45:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78624#M98555</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-05-25T08:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78805#M98556</link>
      <description>&lt;P&gt;Thanks Luigi, i's working now!&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2016 17:52:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78805#M98556</guid>
      <dc:creator>rrunge1</dc:creator>
      <dc:date>2016-05-30T17:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78869#M98557</link>
      <description>&lt;P&gt;Great ! Thanks for letting me know !&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2016 08:11:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/78869#M98557</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-06-01T08:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116079#M98558</link>
      <description>&lt;P&gt;Is this safe without overwriting the other configurations in place?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 00:25:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116079#M98558</guid>
      <dc:creator>chirss</dc:creator>
      <dc:date>2016-09-27T00:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116113#M98559</link>
      <description>&lt;P&gt;Hi chirsf,&lt;/P&gt;
&lt;P&gt;you should merge the 2 configs by hand:&lt;/P&gt;
&lt;P&gt;- sudo -u minemeld vi /opt/minemeld/local/config/committed-config.yml&lt;/P&gt;
&lt;P&gt;- the config format is straightforward, it's basically a list of nodes:&lt;/P&gt;
&lt;PRE&gt;nodes:
    node1:
        [...]
    node2:
        [...]
&lt;/PRE&gt;
&lt;P&gt;- you should append the list of nodes from the O365 config files to the list of nodes of the current committed-config:&lt;/P&gt;
&lt;PRE&gt;nodes:
    node1:
        [...]
    node2:
        [...]
    o365:
        [...]
    ...&lt;/PRE&gt;
&lt;P&gt;- restart minemeld service "sudo service minemeld restart"&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 09:08:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116113#M98559</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-09-27T09:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116198#M98560</link>
      <description>&lt;P&gt;So just delete the nodes: entry and then cat file &amp;gt;&amp;gt; otherfile ?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 15:57:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116198#M98560</guid>
      <dc:creator>chirss</dc:creator>
      <dc:date>2016-09-27T15:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116205#M98561</link>
      <description>&lt;P&gt;yes, that should work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 17:07:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116205#M98561</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-09-27T17:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116223#M98562</link>
      <description>&lt;P&gt;So the fun part is it shows up in the nodes section, but not in the config. It does work and does pull the data down.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 19:34:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116223#M98562</guid>
      <dc:creator>chirss</dc:creator>
      <dc:date>2016-09-27T19:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116238#M98563</link>
      <description>&lt;P&gt;Aha I had to hit load. All good now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is that file the only thing you really need to restore the system should you have to reimage or rebuild?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 20:58:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116238#M98563</guid>
      <dc:creator>chirss</dc:creator>
      <dc:date>2016-09-27T20:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116244#M98564</link>
      <description>&lt;P&gt;All the information you need to rebuild the instance is stored under /opt/minemeld/local/config.&lt;/P&gt;
&lt;P&gt;You may&amp;nbsp;also want to backup local/data (after stopping minemeld-engine) if you want to save&amp;nbsp;the current set of indicators.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 21:21:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/116244#M98564</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-09-27T21:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: PBF for Office 365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/127569#M98565</link>
      <description>&lt;P&gt;Thanks for adding the ability to easily modify the config! &amp;nbsp;Cut and paste and all done. &amp;nbsp;Everything looks good so far!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Nov 2016 00:03:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-for-office-365/m-p/127569#M98565</guid>
      <dc:creator>rkoenig</dc:creator>
      <dc:date>2016-11-19T00:03:29Z</dc:date>
    </item>
  </channel>
</rss>

