mdrabble Posted March 10, 2021 Posted March 10, 2021 Does Smoothwall have the Office 365 address ranges available to create firewall rules to only allow traffic between MS and On Premise Exchange Boxes that are configured in a Hybrid mode? I can create a new address object group but means having to enter each address one at a time - unless someone can tell me a quicker way. Thankfully my on premise box has been offline for over a month while I have been doing some moving of VMs and was to secure communication for when I turn it back on. Cheers
ibpalle Posted March 11, 2021 Posted March 11, 2021 We have a KB that lists the IP ranges located here: https://kb.smoothwall.com/hc/en-us/articles/360010312859 - Microsoft has one as well, which is likely to be more up to date: https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide#skype-for-business-online-and-microsoft-teams 1
mdrabble Posted March 11, 2021 Author Posted March 11, 2021 We have a KB that lists the IP ranges located here: https://kb.smoothwall.com/hc/en-us/articles/360010312859 - Microsoft has one as well, which is likely to be more up to date: https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide#skype-for-business-online-and-microsoft-teams I had the one from MS - was wondering if there was a quicker way of add the IP Addresses in bulk without adding them one at a time.
free780 Posted March 11, 2021 Posted March 11, 2021 If you purchase a firewall with Dynamic Updatable Objects the Firewall will poll the Microsoft list and keep your rules up to date with using FQDNs. Exchange Hybrid Servers should be restricted to Exchange Online ranges. I asked Smoothwall about this feature over a year ago given the use of CloudFront and M365. 1
mdrabble Posted March 15, 2021 Author Posted March 15, 2021 Thankfully my Exchange box had been powered down since Jan as I was moving VMs around and running updates and forgot to power it back up. Since all this faff with patching etc, though better restrict Exchange to MS Addresses only. Still in two minds if I should keep it off until I actually need to use it.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now