- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-28-2021 12:53 AM
Hi Friends,
I would like to create Palo Alto configuration for specific range of IP address, not based on users.
My requirement is as follow.
1. Only Microsoft teams traffic (incoming and outgoing includes calls) should be allowed.
2. Want to block all other traffic includes web browsing, file sharing, social media, media streaming.
Anyone can suggest or support to create this type of configuration.
Thanks and Regards.
Adarsh
06-28-2021 01:27 PM
Teams doesn't have a dedicated container app-id, instead it uses ms-teams, ms-teams-audio-video, ms-teams-downloading, ms-teams-editing, ms-teams-live-event, ms-teams-posting, ms-teams-sharing, and ms-teams-uploading. You can try building out an allow entry with those app-ids setup and deny all other traffic, but I'm not sure how well it'll actually function like that.
Also keep in mind that much of Teams relies on other ms-office365 app-ids and certain functions certainly won't actually function correctly unless you include access to other ms-office365 applications.
06-28-2021 02:33 PM
Hello,
In addition to what BPry already stated, you can use URL and/or destination IP filtering to limit the traffic to Microsoft.
Cheers!
02-21-2022 12:34 AM
Hi,
For any specific application you want to allow only ( applications depend on SSL and Web-browsing), you can create two policies.
- One policy to allow SSL and Web-browsing for that application to work. configure the URL Category in this policy to use custom category contains only the URLs needed for that application
- Another policy to allow that application
In some cases, you have to add one more policy to allow destination IPs for that application to work
I did that for multiple applications such as Anydesk, Skype, Zoom, etc..
I did it also for MS Teams but still facing some issues
11-20-2023 09:48 AM
I still have this issue to allow gifs in Teams through the PAN. I worked with Palo Alto Support and we ended up allowing Shareware and freeware and also online storage and backup for the HR URL Category group. I don't like this solution. What I need to do is just allow *.media0.giphy.com through *media100.giphy.com - Is there a way to wildcard the number after Media?
11-22-2023 12:50 AM
Hi @Daniel_Erlenbu ,
That specific usage of wildcard is not supported. You can only use wildcard characters as token placeholders which isn't the case in your query.
Please read the section on how to use asterisk or caret wildcards in the following document:
Kind regards,
-Kim.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!