Hi,
As newby in the UTM world I'm study the webfiltering.
I hope my question is here on the right place
I thought I noticed a false web block on our connection to office365.
So I created a exclusion on the webfilter for the URLs autodiscovery.companyname.nl (dutch domain) and autodiscovery.companyname.onmicrosoft.com.
At first I selected all the exclusion options and the blocks were gone, however when I deselected the allow and block loggin I noticed the block was not gone at all.
However I know the rule is working :)
I played with the webfilterlog filter and filtered on autodiscovery.companyname.
What I see now is very strange (to my)
I see a patter in the logs for autodiscovery.companyname.nl and autodiscovery.companyname.onmicrosoft.com.
On none regulair times I see four log notifications for autodiscovery.companyname.nl.
The first three are blocked requests with error = "Connection refused"
The forth notification is an accept.
A few seconds later I got 4 notifications for autodiscovery.companyname.onmicrosoft.com with the same pattern.
First three times a blocked request follwed by one accept.
I tried this with and without the earlier called exclusions for the URL's
The results are the same.
So There is no problem with the webfilter Only I discoverd the problem(?) at testig the webfilter
Has some one an idea what's going on with the connections at office365?
Best regards
Peter
This thread was automatically locked due to age.