I would like to create Palo Alto configuration for specific range of IP address, not based on users.
My requirement is as follow.
1. Only Microsoft teams traffic (incoming and outgoing includes calls) should be allowed.
2. Want to block all other traffic includes web browsing, file sharing, social media, media streaming.
Anyone can suggest or support to create this type of configuration.
Thanks and Regards.
Teams doesn't have a dedicated container app-id, instead it uses ms-teams, ms-teams-audio-video, ms-teams-downloading, ms-teams-editing, ms-teams-live-event, ms-teams-posting, ms-teams-sharing, and ms-teams-uploading. You can try building out an allow entry with those app-ids setup and deny all other traffic, but I'm not sure how well it'll actually function like that.
Also keep in mind that much of Teams relies on other ms-office365 app-ids and certain functions certainly won't actually function correctly unless you include access to other ms-office365 applications.
In addition to what BPry already stated, you can use URL and/or destination IP filtering to limit the traffic to Microsoft.
For any specific application you want to allow only ( applications depend on SSL and Web-browsing), you can create two policies.
- One policy to allow SSL and Web-browsing for that application to work. configure the URL Category in this policy to use custom category contains only the URLs needed for that application
- Another policy to allow that application
In some cases, you have to add one more policy to allow destination IPs for that application to work
I did that for multiple applications such as Anydesk, Skype, Zoom, etc..
I did it also for MS Teams but still facing some issues
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!