<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: outlook 365 traffic is getting dropped with R80.10 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17402#M2940</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh, my bad!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding that error, I personally don't know what is the reason, although for me it seems like the traffic is matching with a "wrong" service. What objects are you using in your "services &amp;amp; applications" column from the relevant rule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding using the predefined application for Office365, it would be good although it seems this error is something that "happens" before that. Anyway, if you use the application (given that HTTPS inspection is not being used) just be sure that you're using HTTPS Categorization in order to identify the application based on the CN of the server certificate. This way you could not make a granular policy for O365 (since Microsoft does not use certificates with different CNs for each application), although you should be able to allow O365.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 23 Apr 2018 14:03:53 GMT</pubDate>
    <dc:creator>Victor_MR</dc:creator>
    <dc:date>2018-04-23T14:03:53Z</dc:date>
    <item>
      <title>outlook 365 traffic is getting dropped with R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17396#M2934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="direction: ltr;"&gt;We have R80.10 with jumbo take 70, and we use outlook with office365.&lt;/P&gt;&lt;P style="direction: ltr;"&gt;We added all the relevant FQDNs and IP addresses from Microsoft, but still, when trying to open new profile in outlook, we are getting blocked.&lt;/P&gt;&lt;P style="direction: ltr;"&gt;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;Many block messages appear, we are not sure which is relevant.&lt;/P&gt;&lt;P style="direction: ltr;"&gt;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;I can see drops of -&amp;nbsp; for several addresses of&amp;nbsp; microsoft - dropped by "fw_conn_post_inspect Reason: Handler 'ssl_v3_code' drop;"&lt;/P&gt;&lt;P style="direction: ltr;"&gt;Could not find any SK on this.&lt;/P&gt;&lt;P style="direction: ltr;"&gt;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;Can anyone give assistance on this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Apr 2018 08:55:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17396#M2934</guid>
      <dc:creator>Dalit_Ben_Izhak</dc:creator>
      <dc:date>2018-04-22T08:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: outlook 365 traffic is getting dropped with R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17397#M2935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="direction: ltr;"&gt;https inspection is no active&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Apr 2018 09:10:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17397#M2935</guid>
      <dc:creator>Dalit_Ben_Izhak</dc:creator>
      <dc:date>2018-04-22T09:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: outlook 365 traffic is getting dropped with R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17398#M2936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Instead of adding all those urls/IP lists Microsoft issues, just use the predefined Application to allow Office365.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Apr 2018 17:47:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17398#M2936</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-04-22T17:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: outlook 365 traffic is getting dropped with R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17399#M2937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume you're not using HTTPS inspection since you're using FQDN and IP addresses. This could be really challenging since Microsoft uses a long list of FQDN and domains, and the IP addresses assigned to them maybe quite dynamic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of Gateway are you using? Are you using also Software Blades more than Firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 05:09:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17399#M2937</guid>
      <dc:creator>Victor_MR</dc:creator>
      <dc:date>2018-04-23T05:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: outlook 365 traffic is getting dropped with R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17400#M2938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="direction: ltr;"&gt;Hi Victor,&lt;/P&gt;&lt;P style="direction: ltr;"&gt;Thanks for replying.&lt;/P&gt;&lt;P style="direction: ltr;"&gt;It's stated in the original description&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;We have R80.10 with jumbo take 70, both mgmt+gw.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;We Don't use https inspection, and other blades are active, yes.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 09:08:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17400#M2938</guid>
      <dc:creator>Dalit_Ben_Izhak</dc:creator>
      <dc:date>2018-04-23T09:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: outlook 365 traffic is getting dropped with R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17401#M2939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="direction: ltr;"&gt;Thanks, tried that, no change unfortunately&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 09:09:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17401#M2939</guid>
      <dc:creator>Dalit_Ben_Izhak</dc:creator>
      <dc:date>2018-04-23T09:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: outlook 365 traffic is getting dropped with R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17402#M2940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh, my bad!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding that error, I personally don't know what is the reason, although for me it seems like the traffic is matching with a "wrong" service. What objects are you using in your "services &amp;amp; applications" column from the relevant rule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding using the predefined application for Office365, it would be good although it seems this error is something that "happens" before that. Anyway, if you use the application (given that HTTPS inspection is not being used) just be sure that you're using HTTPS Categorization in order to identify the application based on the CN of the server certificate. This way you could not make a granular policy for O365 (since Microsoft does not use certificates with different CNs for each application), although you should be able to allow O365.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 14:03:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17402#M2940</guid>
      <dc:creator>Victor_MR</dc:creator>
      <dc:date>2018-04-23T14:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: outlook 365 traffic is getting dropped with R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17403#M2941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using the application on a rule with destination Internet? Are you using inline layers / no layers / or a separate APCL/URLF policy?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 18:14:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/outlook-365-traffic-is-getting-dropped-with-R80-10/m-p/17403#M2941</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-04-23T18:14:35Z</dc:date>
    </item>
  </channel>
</rss>

