HI,
I have ISA 2004 and Exchange 2003 and can't get the OWA to work. Here is the scenario:
The front end firewall is an ASA and is allowing in HTTPS to the DMZ NIC on the ISA. The ISA has two NICs 1 on the LAN and 1 in the DMZ. OWA works from the LAN. I have installed a digital cert from a third party CA on the Exchange server and exported with private keys and imported onto the ISA server. Form based authentication is turned off on Exchange.
ISA publishing rule:
Allow from anywhere , TO the external dns A record that matches the name on the digital cert eg webmail.domain.ie
Listener: External nic, 443, cert webmail.domain.ie, OWA Form based auth, always auth: yes
Public name: request for following sites: webmail.domain.ie
3 paths are in
Bridging 443 and all users
When I browse to
https://webmail.domain.ie (do not need /exchange as I have edited IIS on Exchange to accept it) from outside of the network I get the login page.
When I enter credentials I get:
Technical Information (for support personnel)
Error Code: 403 Forbidden. The server denied the specified Uniform Resource Locator (URL). Contact the server administrator. (12202)
It is driving me nuts. I have put an entry in on the host file on the ISA server for webmail.domain.ie and pointed it to the LAN IP of the Exchange server. The Internal domain is domain.local
In Exchange:
Default Website: Enable Anonymous Access
/Exchange: Basic Auth
/Exch Web: Anonymous
/Public: Basic Auth
I am getting the following in monitoring
Log type: Web Proxy (Reverse)
Status: 12210 An Internet Server API (ISAPI) filter has finished handling the request. Contact your system administrator.
Rule:
Source: ( 78.152.229.10:0)
Destination: ( 10.0.0.*:443)
Request: GET
http://webmail.domain.ie/CookieAuth.dll?GetPic?image=logon_IE_bot.gif Filter information: Req ID: 07a524f2
Protocol: https
User: anonymous
and
Log type: Web Proxy (Reverse)
Status: 12202 The ISA Server denied the specified Uniform Resource Locator (URL).
Rule: Default rule
Source: External ( 78.152.229.10:0)
Destination: ( 10.0.0.*:443)
Request: GET
http://webmail.domain.ie/ Filter information: Req ID: 07a52e12
Protocol: https
User: internaldomain\username
Any help would be grateful
Thanks
Start Free Trial