Security policy FQDN
Hello,
by following this Microsoft link to allow access the Outlook App to Exchange OnPrem:
I see that you need to enable fqdn to allow access.
Am I wrong or Zyxel firewalls not resolve the IP class?
I add this roule:
sometimes rule not working
Accepted Solution
-
Can FQDN resolve IP subnet?
No I FQDN can lookup the IP's of a DNS name bbc.co.uk
151.101.0.81
151.101.64.81
151.101.192.81
151.101.128.81You can do *bbc.co.uk for WILDCARD for subdomain by DNS that happens LAN to WAN for the IP's it gets
1
All Replies
-
Those addresses are server need to access which means this is outgoing traffic.
I thought you need a rule is LAN → WAN , dst: AppOutlook
0 -
Let's leave aside for the moment the question of whether it is needed (for incoming or outgoing access).
Can FQDN resolve IP subnet?
Example: outlook.cloud.microsoft -> 13.107.6.152/31 + 13.107.18.10/31 + …
or is it really necessary to specify the various subnets manually?0 -
It can. It works with FQDN objects.
0 -
from specific firmware or what?
I can confirm that if I enter the various IPs manually in the rules (13.107.6.152/31, 13.107.18.10/31, 13.107.128.0/22, ...) the application works.
If I leave the FQDNs alone (outlook.cloud.microsoft, outlook.office.com, outlook.office365.com) the app doesn't work.0 -
FQDN object should work with now alive appliance.
But sounds like you have FQDN object which mean your firmware should support this feature.
Maybe try the latest firmware ?
0 -
Can FQDN resolve IP subnet?
No I FQDN can lookup the IP's of a DNS name bbc.co.uk
151.101.0.81
151.101.64.81
151.101.192.81
151.101.128.81You can do *bbc.co.uk for WILDCARD for subdomain by DNS that happens LAN to WAN for the IP's it gets
1
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 147 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 262 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight