Link to home
Start Free TrialLog in
Avatar of rj2
rj2

asked on

Exchange server 2007 / windows server 2003- domain authentication question

Hi,
I have a domain that is called "mycompany.local" in Active Directory.
When installing Exchange server 2007 I ran into a problem trying to get Outlook Anywhere to work. I can't get it to work if the Exchange server is not accessed with the ".local" domain name, autentication don't work if I define an external hostname with ".com" domain.
I can edit all the hosts files and enter the ".local" domain name there but we use NAT and the hostname is different when the users is inside or outside the firewall.

How can I make this work?
Does the AD domain need to be the same as external domain to make Outlook Anywhere work or is there a way around this?
Is it a way to make Outlook Anywhere work without renaming/reinstalling the domain?
Avatar of James Montgomery
James Montgomery

What certificate is your CAS server using? Outlook anywhere requires a trusted cert with a SAN attribute if i recall correctly for it to work internally and externally.

http://exchangepedia.com/blog/2007/08/outlook-anywhere-and-exchanges-self.html

http://www.msexchange.org/articles_tutorials/exchange-server-2007/mobility-client-access/securing-exchange-2007-client-access-server-3rd-party-san-certificate.html
Avatar of rj2

ASKER

It uses certificate for mycompany.com
Avatar of rj2

ASKER

What I would like ideally is to keep my internal AD domain mycompany.local, use external domain mycompany.com and just make Outlook Anywhere work. But so far I have only been able to connect using Outlook Anywhere from outside the firewall using hostname "mail.mycompany.local" and setting the IP in the hosts file. Even though the SSL certificate is for "mail.mycompany.com"
ASKER CERTIFIED SOLUTION
Avatar of James Montgomery
James Montgomery

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of rj2

ASKER

It is working now. The link http://forums.msexchange.org/m_1800438631/mpage_1/key_/tm.htm#1800455745 was right on. Thanks.