How to setup no decrypt for Office365 and Lync

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How to setup no decrypt for Office365 and Lync

L3 Networker

I would like to set a no decrypt policy for the applications ms-Office365 and ms-lync. But the only option in no decrypt is for URL category. How can I configure the no decrypt?

1 accepted solution

Accepted Solutions

Community Team Member

Hi,

 

You can create a Custom URL Category containing all of the Office365 URL's and IP ranges and use that custom category for the no decrypt policy.  If SNI and/or certificate CN match then it should pick up this info :

 

Office 365 URLs and IP address ranges

 

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

View solution in original post

3 REPLIES 3

Community Team Member

Hi,

 

You can create a Custom URL Category containing all of the Office365 URL's and IP ranges and use that custom category for the no decrypt policy.  If SNI and/or certificate CN match then it should pick up this info :

 

Office 365 URLs and IP address ranges

 

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Quick bump, have you verified this solution? Specifying the MS URL's in the no decryption policy to allow Lync?

 

Am I correct that when using App-ID (for MS-Lync), SSL decryption will be required (and probably eating up a lot of my available sessions)?

If so it would seem pretty obvious to use the MS URL's and let App-ID be for what it is, or what other disadvantage am I missing?

Hi,

 

It works fine for me with the following URLs in a custom category used in no decryption rule:

 

*.lync.com
*.cqd.lync.com
*.infra.lync.com
*.online.lync.com
*.resources.lync.com
*.config.skype.com
*.skypeforbusiness.com
*.pipe.aria.microsoft.com
config.edge.skype.com
pipe.skype.comaddress ranges

 

From:

https://support.office.com/en-us/article/Office-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-ab...

  • 1 accepted solution
  • 4400 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!