| Where Can I Use This? | What Do I Need? |
- NGFW
- Prisma Access
- Windows, Windows 10 UWP, macOS, iOS, and Linux endpoints
|
- GlobalProtect Gateway license or Prisma Access license with
the Mobile User subscription
|
To support business continuity and remote workforces, you can use Palo Alto Networks
firewalls and the GlobalProtect app to securely enable remote access to Microsoft
Office 365 applications. This topic provides guidance on implementing Microsoft's
recommendations for Office 365 access to optimize the user experience and decrease
the bandwidth load on your enterprise network infrastructure.
Microsoft recommends the following for Office 365 applications:
- Split tunnel Office 365 applications instead of routing them over a VPN
tunnel.
- Split tunnel Office 365 applications using specific, optimized
Microsoft-provided IP address ranges instead of split tunneling using fully
qualified domain names (FQDNs).
Split-tunnel
traffic is not inspected by the firewall and, therefore, does not
receive the threat prevention capabilities offered by Palo Alto
Networks. Carefully review your security requirements before enabling
this feature to decide whether split tunneling Office 365 traffic meets
your environmental needs.
This use case focuses on implementing split tunnel exclusions based on the
access route for the following Office 365 applications:
- Skype for Business Online and Microsoft Teams
- SharePoint Online and OneDrive for Business
- Exchange Online
The GlobalProtect app supports the split tunnel exclude access route feature, which
enables you to send latency-sensitive and high-bandwidth traffic directly outside of
the VPN tunnel rather than tunneling all traffic. For the best performance and most
efficient use of VPN capacity, you should route traffic destined for the dedicated
IP address ranges associated with these Office 365 applications (referred to as the
Optimize category in Microsoft documentation) directly outside of the VPN tunnel.
The firewall supports up to 200 exclude access routes (combining both IPv4 and IPv6
routes). The number of IP address ranges in the Office 365 Optimize category is well
within this limit, currently requiring approximately 20 IPv4 ranges and 30 IPv6
ranges.