Original post here: http://blogs.technet.com/b/lync/archive/2014/04/16/update-your-firewall-now-with-this-new-crl-endpoint.aspx
The Lync team has recently discovered additional steps for Lync Online admins to take to ensure smooth service performance. This applies to Lync Online tenants, and hybrid deployments where some users are homed in Lync Online after being moved from a Lync Server on-premises deployment.
As a result of the recent acquisition of Verisign by Symantec, you’ll need to add this new certificate revocation list (CRL) endpoint to your list of allowed locations:
Outgoing TLS and HTTPS
Add this new rule to your firewall or proxy server to avoid Lync sign-in issues and ensure a secure connection to Office 365.
IMPORTANT: You must add this allowed CRL endpoint to any device that is filtering web traffic: firewalls, load balancers, proxy servers, web security software/appliances, and so on.
For additional information about this change, please see the following Service Announcement from Symantec:
For more information
Lync Online URLs and IP Address Ranges
Set up your network for Lync Online
a lot of thanks 4 the information