Skip to main content
HS08
Visitor III
May 24, 2026
Solved

Allow access to microsoft

  • May 24, 2026
  • 4 replies
  • 95 views

We have policy to allow all servers access to microsoft then i have a firewall policy and set the destination to all microsoft internet service.

However i found some microsoft url still blocked by implicit denied and this mean microsoft internet service not contains all microsoft url. Anyone know how to solve this?

 

 

Best answer by sjoshi

It is not matching Microsoft ISDB since those IP address belongs to Akamai.
You need to add Akamai ISDB to make it work.

All this IP are matching Akamai ISDB
Hansolo-kvm11 # diagnose internet-service match root 23.52.40.97 255.255.255.255
Internet Service: 7929993(Akamai-CDN), matched entry num: 3, matched num: 3

Hansolo-kvm11 # diagnose internet-service match root 23.40.40.33 255.255.255.255
Internet Service: 7929993(Akamai-CDN), matched entry num: 3, matched num: 3

Hansolo-kvm11 # diagnose internet-service match root 23.202.33.105 255.255.255.255
Internet Service: 7929993(Akamai-CDN), matched entry num: 3, matched num: 3

Hansolo-kvm11 # diagnose internet-service match root 23.40.40.82 255.255.255.255
Internet Service: 7929993(Akamai-CDN), matched entry num: 3, matched num: 3

You can also refer below link to check the Geo location where it shows IP belongs to Akamai
https://www.maxmind.com/en/geoip-web-services-demo

4 replies

sjoshi
Staff
sjoshiAnswer
Staff
May 25, 2026

It is not matching Microsoft ISDB since those IP address belongs to Akamai.
You need to add Akamai ISDB to make it work.

All this IP are matching Akamai ISDB
Hansolo-kvm11 # diagnose internet-service match root 23.52.40.97 255.255.255.255
Internet Service: 7929993(Akamai-CDN), matched entry num: 3, matched num: 3

Hansolo-kvm11 # diagnose internet-service match root 23.40.40.33 255.255.255.255
Internet Service: 7929993(Akamai-CDN), matched entry num: 3, matched num: 3

Hansolo-kvm11 # diagnose internet-service match root 23.202.33.105 255.255.255.255
Internet Service: 7929993(Akamai-CDN), matched entry num: 3, matched num: 3

Hansolo-kvm11 # diagnose internet-service match root 23.40.40.82 255.255.255.255
Internet Service: 7929993(Akamai-CDN), matched entry num: 3, matched num: 3

You can also refer below link to check the Geo location where it shows IP belongs to Akamai
https://www.maxmind.com/en/geoip-web-services-demo

Thanks, Salon
funkylicious
SuperUser
SuperUser
May 25, 2026

the easiest way would be to allow also Akamai-CDN in the firewall policy with the other ISDB objects, since the destination IP addresses in your case are not part of Microsoft ISDB.

diagnose internet-service match root 23.52.40.33 255.255.255.255
Internet Service: 7929993(Akamai-CDN), matched entry num: 3, matched num: 3
 

"jack of all trades, master of none"
AEK
SuperUser
SuperUser
May 25, 2026

Try add Akamai-CDN ISDB in the policy and see if it helps.

AEK
HS08
HS08Author
Visitor III
May 25, 2026

hi.. yes add akamai-cdn is solved the issue. Thanks