Reverse proxy for Exchange ActiveSync

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Reverse proxy for Exchange ActiveSync

L0 Member

We have a Palto Alto cluster and I want to use them as reverse proxy for our Exchange inbound trafic. We activated decryption for this trafic and we want to allow only ActiveSync trafic / application.

 

It did not work with only allow ActiveSync application, we also had to create another rule to allow web-browsing to URL */microsoft-server-activesync because it does not detect all trafic as activesync, even though it's decrypted.

 

In attached picture the log of a part of the trafic when I sync my iphone with the native mail application.

 

Anyone already done this ? Why doesn't it detect correctly the trafic as ActiveSync ?

2 REPLIES 2

Community Team Member

Hi @karsayor ,

 

Looking at applipedia info for activesync, web-browsing should be implicitly allowed and no explicit configuration should be required.

 

That said, applications for which the firewall cannot determine dependent applications on time will require that you explicitly allow the dependent applications when defining your policies.

 

Source:

https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/app-id/applications-with-implicit-support

 

Kind regards,

-Kim.

 

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Hello ! Thanks for the reply !

 

But in case I have to specify web-browsing explicitely, it will allow all trafic to the HTTPS port including OWA / ECP /.. , which I do not want to open. I only want to allow activesync . Is there a way to do this ?

  • 1048 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!