01-10-2019 01:07 PM
For the last couple of weeks we are running into an interesting issue with our Office365 EDL's. We pull the Office365 API based IP/URL list into Panorama using MineMeld. This process is working perfectly. We have compared the output within MineMeld against the EDL on our firewall and they are identical. For some reason I am seeing multiple connections being blocked to IPv4 ranges that are contained in the EDL. This is occurring on multiple protocols, STUN, SSL, etc... affecting Skype For Business for a number of users. Now, what is odd, is that I can fix this issue if I take the IP range from the EDL present on the firewall and create a network object for it and place it in the same exact rule. So this tells me that the problem is with the firewall using objects in this specific EDL. The EDL has 184 different IPs or IP ranges in it. We are running 8.1.4 on all firewalls. Has anyone else run into this issue? Thank you in advance!
01-14-2019 06:11 AM
I tested this again with your version, 8.1.4, and I wasn't able to find the range that wasn't matched via EDL. Everything looks good. Could you share more details?
01-14-2019 06:53 AM
Here is the IP range: 22.214.171.124-126.96.36.199 The app affected is Skype.
Like I mentioned earlier I can clearly see the IP range on the firewall contained within the EDL but the traffic is still getting denied by policy to this specific range. Once I add an IP range Object for it to the same rule it starts matching and the traffic is allowed. I haven't checked to see if there are other ranges in the EDL being denied, so I will check that this morning and report back.
01-14-2019 08:49 AM
Thanks! Just checked again and it is matching. Which NGFW device are you using? I am testing this on a VM, wondering if it could be an issue with hw architectures with a dedicated dataplane.
01-14-2019 09:02 AM
This is a VM-300. I did notice this morning that we are missing some of the Office365/Skype AppID dependencies but I don't see any of them being used. Can you tell me which AppID's you are testing with? I am going to try and narrow it down to a specific AppID or protocol.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!