Limiting Access to Office365 only

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Limiting Access to Office365 only

L1 Bithead

Hi All,

So we have a PA FW with PANOS 9.1.x

We have a requirement for a specific inside vlan to have internet access to office365 only (teams,outlook etc etc)..

tried with app-id using the office (365-enterprise-access and consumer) access to no avail, Suspect this did not work due to the FW not able to decrypt the ssl traffic.

we also do not have EDL setup as yet.. might be the go option going forward.

so the short workaround for now was to create a custom URL group list (*.microsoft.com,*.office.com etc)and allow it on the FWs

 

are there any other methods of doing this?

I know for instance on Fortinet you can use internet services Database which is easy to configure. but PAN? not so much.

 

thanks in adv

 

 

 

4 REPLIES 4

Cyber Elite
Cyber Elite

@Ants,

As soon as you want to limit application access you'll really want to push to get SSL decryption enabled and setup. That's the only way that the firewall can fully inspect traffic and allow for the use of app-id reliably; without that you'll be left using custom URL categories that you'll need to self maintain and keep updated. 

I personally really recommend that you use EDLs for these exceptions when possible so that they can be dynamically updated without having to commit a change. Assuming you have anyone actively working on changes on the firewall that aren't ready to be committed, having a least a temporary EDL of domains can help bypass delays due to other pending changes. 

Cyber Elite
Cyber Elite

Hi @Ants ,

 

The PANW EDL Hosting Service provides a way to identify O365 destinations and update them automatically as @BPry recommended.

 

https://docs.paloaltonetworks.com/resources/edl-hosting-service

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

L1 Bithead

thanks for the feedback.. much appreciated.

will look at implementing the EDL method for time being.

 

regards

L2 Linker

Hello @Ants 

 

Another way is to make use of the Microsoft Endpoint List which is published weekly (and updated every Friday as far as I know) to create a custom EDL which can allow only parts of the O365 that you like.

 

I hope this helps.

 

 

Don't forget to Like if you find this post helpful
  • 1013 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!