<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Whitelisting o365 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116075#M99727</link>
    <description>&lt;P&gt;My goal would be not to have to add 25 whitelisted miners to every single aggregator since I'd likely want to globally whitelist. Is there a better way to go about this?&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2016 22:16:33 GMT</pubDate>
    <dc:creator>chirss</dc:creator>
    <dc:date>2016-09-26T22:16:33Z</dc:date>
    <item>
      <title>Whitelisting o365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116059#M99723</link>
      <description>&lt;P&gt;I want to make sure I understand the workflow on this correctly. To whitelist o365 I would perform the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) Clone the o365 miners I want, prefixing them with wl&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Edit the input for wlwhitelist and add the wlo365 miners I created.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anything I'm missing here?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 19:22:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116059#M99723</guid>
      <dc:creator>chirss</dc:creator>
      <dc:date>2016-09-26T19:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelisting o365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116067#M99724</link>
      <description>&lt;P&gt;Hi chrisf,&lt;/P&gt;
&lt;P&gt;let's say you are aggregating multiple C2 IPv4 feeds using an aggregator node called C2Aggregator. You want to whitelist o365 IPs to avoid blacklisting o365 by mistake. Steps:&lt;/P&gt;
&lt;P&gt;- create a new o365 Miner and prefix the name with "wl". Like wlO365&lt;/P&gt;
&lt;P&gt;- select the INPUT fields of C2Aggregator and add wlO365&lt;/P&gt;
&lt;P&gt;- COMMIT&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;C2Aggregator will consider IPv4 addresses/networks coming from wlO365 as whitelist and will remove the C2 indicators overlapping the o365 networks from the aggregated feed.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 20:15:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116067#M99724</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-09-26T20:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelisting o365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116069#M99725</link>
      <description>&lt;P&gt;OK to take that one step further. Say I have 25 whitelist miners and I want to add them to a single aggregator, and then any time I bring up a new aggregator I wanted to point the wlAggregator as an input. Would this work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ideally I could white list all internal ip ranges, then anything for services required by the business.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 20:23:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116069#M99725</guid>
      <dc:creator>chirss</dc:creator>
      <dc:date>2016-09-26T20:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelisting o365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116070#M99726</link>
      <description>&lt;P&gt;Never tried, but it should work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: aggregators for domains and URLs currently (0.9.22) do not support pattern matching. That means you can't use *.example.com to whitelist all the indicators with domain example.com.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 20:30:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116070#M99726</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-09-26T20:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelisting o365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116075#M99727</link>
      <description>&lt;P&gt;My goal would be not to have to add 25 whitelisted miners to every single aggregator since I'd likely want to globally whitelist. Is there a better way to go about this?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 22:16:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116075#M99727</guid>
      <dc:creator>chirss</dc:creator>
      <dc:date>2016-09-26T22:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelisting o365</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116112#M99728</link>
      <description>&lt;P&gt;Hi chirsf,&lt;/P&gt;
&lt;P&gt;no, this is the best way to do it. Basically you should:&lt;/P&gt;
&lt;P&gt;- create&amp;nbsp;the o365 Miners *without* wl prefix&lt;/P&gt;
&lt;P&gt;- create an aggregator *with* wl prefix&lt;/P&gt;
&lt;P&gt;- attach your wl aggregator to your threat indicators aggregator&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would also define a static list Miner for each wl aggregator to use for manually whitelist false positives.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Something like the schema below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2016-09-27 at 11.02.04.png" style="width: 636px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5689iA9DC808763C7E151/image-dimensions/636x371/is-moderation-mode/true?v=v2" width="636" height="371" role="button" title="Screen Shot 2016-09-27 at 11.02.04.png" alt="Screen Shot 2016-09-27 at 11.02.04.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 09:03:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/whitelisting-o365/m-p/116112#M99728</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-09-27T09:03:00Z</dc:date>
    </item>
  </channel>
</rss>

