<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Permissions to Outlook by VS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250762#M49050</link>
    <description>&lt;P&gt;You dont need to, only having fw blade enabled on the layer is good enough.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jun 2025 23:52:30 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-06-05T23:52:30Z</dc:date>
    <item>
      <title>Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250302#M48911</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We need to create a rule in our FW, that allows access for Outlook mail consumption to a user with IP 10.x.x.x.x/32&lt;BR /&gt;We do not have APPC or URLF&lt;BR /&gt;We only have the instance with the blade FW running (We have a VSX environment)&lt;BR /&gt;The detail is that we have created a rule using as destination an 'Updatable Object', as Office 365, but the FW ignores the rule and the user can not access (does not load the main page), the only way is to change the destination by ANY, and then if it works.&lt;/P&gt;
&lt;P&gt;Questions.&lt;/P&gt;
&lt;P&gt;1. Updatable Object, does it work with a particular blade?&lt;BR /&gt;2. If you only have your VS working as FW, in what ways could we control the traffic to a particular destination, would it be using FQDN?&lt;BR /&gt;3. What are the domains that Outlook normally consumes so that someone can use webmail?&lt;/P&gt;
&lt;P&gt;Thanks for your comments&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jun 2025 18:05:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250302#M48911</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-06-01T18:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250303#M48912</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82839"&gt;@Matlu&lt;/a&gt;&amp;nbsp;what‘s OUTLOOK as destination? You mean &lt;A href="https://outlook.com" target="_blank"&gt;https://outlook.com&lt;/A&gt;&amp;nbsp;or dou you mean outlook as client for an onpremise exchange or O365 exchange?&amp;nbsp;&lt;BR /&gt;If you use an updatable object you need a working DNS on your gateway and your client and they have to be using the same DNS servers (meaning the DNS resolution has to be the same results on the client and on the gateway)&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jun 2025 20:00:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250303#M48912</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-06-01T20:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250310#M48914</link>
      <description>&lt;P&gt;Hey bud,&lt;/P&gt;
&lt;P&gt;You only need technically fw blade enabled to use updatable object. I always only use it like that on ordered layer with fw blade enabled and works just fine.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 00:58:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250310#M48914</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T00:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250311#M48915</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;Indeed, our need is that the user can access via web, to &lt;A href="https://outlook.com" target="_blank" rel="noopener"&gt;https://outlook.com&lt;/A&gt;, but the problem is that when I make the security rule putting as destination the Updatable Object of 'Office 365', this does not work, because the user can not access the web.&lt;BR /&gt;The only way is putting as destination in 'Any'.&lt;BR /&gt;For it to consume &lt;A href="https://Outlook.com" target="_blank" rel="noopener"&gt;https://outlook.com&lt;/A&gt;, do you need to place other 'Updatable Objects'?&lt;BR /&gt;Or the correct way for this permission is another one?&lt;BR /&gt;We only have the FW blade available&lt;BR /&gt;Thanks for your comments&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 03:45:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250311#M48915</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-06-02T03:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250312#M48916</link>
      <description>&lt;P&gt;I can check in the lab tomorrow...what is EXACT name of the updatable object?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 03:59:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250312#M48916</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T03:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250313#M48917</link>
      <description>&lt;P&gt;It's Office 365&lt;BR /&gt;If it is not feasible to use Updatable Object for this purpose, what would be the most favorable option when you only have the FW blade available?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 04:08:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250313#M48917</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-06-02T04:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250330#M48923</link>
      <description>&lt;P&gt;Let me do some lab tests soon and will update you buddy.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 10:06:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250330#M48923</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T10:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250335#M48927</link>
      <description>&lt;P&gt;I suspect you have to enable HTTPS Inspection to do this, regardless of other configuration requirements.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 10:24:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250335#M48927</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-06-02T10:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250337#M48929</link>
      <description>&lt;P&gt;I just ran below command on the lab fw:&lt;/P&gt;
&lt;P&gt;[Expert@CP-GW:0]# dynamic_objects -uo "Office365 Services"&lt;/P&gt;
&lt;P&gt;Output is way too long to copy it here, but outlook.com is 100% there. If it does not work, maybe try add domain object as .*outlook.com and uncheck fqdn option and see if that works.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 10:31:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250337#M48929</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T10:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250340#M48930</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;See what I attached. I just tested with that object in the policy with no ssl inspection on and worked fine.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 11:28:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250340#M48930</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T11:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250356#M48941</link>
      <description>&lt;P&gt;Bro,&lt;/P&gt;
&lt;P&gt;I'll try it today and update you&lt;/P&gt;
&lt;P&gt;One query, the command you shared to test, I guess it should be run on the VS instance where I'm working this permission, right?&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 13:17:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250356#M48941</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-06-02T13:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250357#M48942</link>
      <description>&lt;P&gt;Thats right. Btw, command works for ANY updatable object used in policy, just make sure to put EXACT name as it shows in smart console.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 13:18:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250357#M48942</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T13:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250359#M48943</link>
      <description>&lt;P&gt;With the command shown by Andy you'll see if the updatable object will be fine. Using "Office 365 services" or "Exchange services" is the correct way. That's what updatable objects are for. Maybe something goes wrong...&lt;/P&gt;
&lt;P&gt;Follow&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk178775" target="_blank"&gt;sk178775 - Security Gateway does not enforce a rule with Updatable Object in the Access Control Policy&lt;/A&gt;&amp;nbsp;to check your gateway&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 13:29:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250359#M48943</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-06-02T13:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250360#M48944</link>
      <description>&lt;P&gt;Excellent sk&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 13:33:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250360#M48944</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T13:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250394#M48956</link>
      <description>&lt;P&gt;Hey, Andy&lt;/P&gt;
&lt;P&gt;Your recommendation seems to have taken effect in my environment.&lt;BR /&gt;I have a question, does Check Point have a kind of “Debug Flow”, as it exists in other vendor like Fortinet, which helps you to know by CLI, in which rule a particular traffic is doing MATCH?&lt;/P&gt;
&lt;P&gt;It happens to be working with your recommendation what I needed, but we have a problem with our LOG SERVERS, and we can't see the real traffic at this moment.&lt;/P&gt;
&lt;P&gt;I want to rely on a “Packet Capture” class to help me know if the traffic is MATCHing or not with the rule we have created.&lt;/P&gt;
&lt;P&gt;Cheers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 21:50:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250394#M48956</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-06-02T21:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250395#M48957</link>
      <description>&lt;P&gt;K, great!&lt;/P&gt;
&lt;P&gt;If you are looking for something similar to what I attached on Fortigate (by the way, for what its worth, fortimanager is way better for that), closest I can think of is below.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 21:55:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250395#M48957</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T21:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250396#M48958</link>
      <description>&lt;P&gt;Interesting tool, but I have a question, in the “destination” field, how would you filter if your original destination is a domain?&lt;/P&gt;
&lt;P&gt;Do you have to first do a NSLOOKUP on your PC, and resolve your domain as &lt;A href="https://outlook.com" target="_blank"&gt;https://outlook.com&lt;/A&gt;, and take any IP that NSLOOKUP gives you, to put it in the command syntax?&lt;/P&gt;
&lt;P&gt;Or is there another way?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 22:01:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250396#M48958</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-06-02T22:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250397#M48959</link>
      <description>&lt;P&gt;Excellent question!&lt;/P&gt;
&lt;P&gt;Sadly, you can NOT do domains, ONLY ip addresses. So you can do nslookup as you said and then test it that way. I dont sadly know of any other way.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 22:04:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250397#M48959</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T22:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250761#M49049</link>
      <description>&lt;P&gt;Hey, Bro&lt;BR /&gt;When working with “DOMAINS”, do you know if it is necessary to enable also the HTTPS Inspection in the GW?&lt;BR /&gt;The rule you created is not working, and it seems that since you created it it doesn't work.&lt;BR /&gt;Unfortunately I had a problem with the logs of our box and I had no way to confirm if the rule was working or not.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2025 23:40:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250761#M49049</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-06-05T23:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to Outlook by VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250762#M49050</link>
      <description>&lt;P&gt;You dont need to, only having fw blade enabled on the layer is good enough.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2025 23:52:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permissions-to-Outlook-by-VS/m-p/250762#M49050</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-05T23:52:30Z</dc:date>
    </item>
  </channel>
</rss>

