Connection issues for Microsoft (Skype, Office365) after enabling DPI services

Description

When you enable App Control and block the signature ID 5 or ID 7, it may cause connection issues with Microsoft applications such as Skype, Skype for Business and Office 365.

Image

Image

SID 5 is for TCP Random Encryption and SID 6 is for UDP Random Encryption.  This article shows you how to create a Access Rule to fix such communication issues for Microsoft Applications. This article also applies to excluding traffic from DPI-SSL.

Resolution

 Create Address Group with Microsoft FQDNs & IPs

  1. Login to your SonicWall management page and click Manage tab on top of the page.
  2.  Navigate to Objects |Address Objects page. On right Side, Click on Address Groups Tab and select View as Custom.
  3. Click Add button under Address Groups, to get Add Address Object Group Window.
  4.  Name: MS_Applications.
  5.  Add Address Objects, which you created for MS FQDNs & IPs to Right side of table.
  6.  Click OK.
    Image

Skype relevant objects:

NameZoneTypeIP/HostName
api.skype.comWANFQDNapi.skype.com
apps.skype.comWANFQDNapps.skype.com
community.skype.comWANFQDNcommunity.skype.com
download.skype.comWANFQDNdownload.skype.com
login.skype.comWANFQDNlogin.skype.com
pipe.skype.comWANFQDNpipe.skype.com
secure.skype.comWANFQDNsecure.skype.com
.lync.comWANFQDN.lync.com
.pipe.aria.microsoft.comWANFQDN.pipe.aria.microsoft.com
.infra.lync.comWANFQDN.infra.lync.com
.online.lync.comWANFQDN.online.lync.com
.resources.lync.comWANFQDN.resources.lync.com
pipe.skype.comWANFQDNpipe.skype.com
swx.cdn.skype.comWANFQDNswx.cdn.skype.com
.config.skype.comWANFQDN.config.skype.com
config.edge.skype.comWANFQDNconfig.edge.skype.com
.sfbassets.comWANFQDN.sfbassets.com
.urlp.sfbassets.comWANFQDN.urlp.sfbassets.com
.skypeforbusiness.comWANFQDN.skypeforbusiness.com
skypemaprdsitus.trafficmanager.netWANFQDNskypemaprdsitus.trafficmanager.net
graph.skype.comWANFQDNgraph.skype.com
.users.storage.live.comWANFQDN.users.storage.live.com
SKYPE-01WANNetwork 64.4.23.0/255.255.255.0
SKYPE-02WANNetwork65.55.223.0/255.255.255.0
SKYPE-03WANNetwork11.221.77.0/255.255.255.0
SKYPE-04WANNetwork157.55.56.0/255.255.255.0
SKYPE-05WANNetwork157.55.130.0/255.255.255.0
SKYPE-06WANNetwork155.55.235.0/255.255.255.0
SKYPE-07WANNetwork157.56.22.0/255.255.255.0


Office relevant Objects

You can visit Microsoft Services : Office365 URLs and IPs

Create Access Rule to By-Pass DPI

  1. Login to your SonicWall management page and click Manage tab on top of the page.
  2. Navigate to Rules | Access Rules page. On right side, click Add button..
  3.  In Add Rule Window, create an Access Rule From LAN To WAN zone as below.Image
  4. Then click Advanced and enable Disable DPI  checkbox. Click Add .
    Image

Related Articles

  • SonicOS 8.1.0 FAQ
    Read More
  • SonicWall GEN8 TZs and GEN8 NSas Settings Migration
    Read More
  • Getting started with SonicWall firewalls
    Read More
not finding your answers?