SSL / Outlook Web Access not identified by App-ID

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

SSL / Outlook Web Access not identified by App-ID

L2 Linker

I have a customer that is using a PA-5020, and when users try to go to certain Outlook Web Access sites, it won't work for them.  Checking the logs, I can see where the user initiates a connection over port 443 to the destination OWA server, but App-ID identifies it as 'unknown' instead of 'ssl'.  I never see the SSL setup, and the user's connection times out.  The same user on the same machine can go to a different OWA site without difficulty.  He can also get to the problematic OWA site when connected to the Internet via alternate means.  

 

We are not doing SSL Decrypt on this traffic, and SSL and web-browsing outbound is permitted.  NAT rules are configured correctly (else he wouldn't be able to get to anything, much less a different OWA site).  

 

Anyone have any thoughts on this?  Why wouldn't OWA over SSL work for individual sites, but work fine for others?

 

Thanks in advance!

3 REPLIES 3

Cyber Elite
Cyber Elite

Do you know what version of Exchange is running behind this not working OWA?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

L6 Presenter

Hi there...I would suggest doing a packet capture on the OWA traffic and compare the working one against the non-working one.  Check the SSL handshake for client hello and cert exchange to see if it is indeed SSL traffic.

L2 Linker

All -

 

Turns out that it was the outside OWA system blocking our requests for connection.  As soon as we routed the user through an alternate gateway, it began working again.  We contacted the system admins of that OWA server, and they were able to permanently fix it on their end.

 

Thanks for trying to help!

  • 2709 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!