OWA HTTP/1.1 503 Service Unavailable intermittent error W2K Ex2K front/back-end config

After entering login info into OWA through IE6 browser, user receives the error: HTTP/1.1 503 Service Unavailable. I have Exchange 2K running on W2K servers in a front/back-end configuration. This error message occurs intermittently with no event log reference. Reboot of the front-end Exchange server resolves it for a while and users can access their mailbox through OWA. Then for no obvious reason, it happens again. The front-end server is in a DMZ, no configurations changes have been recently made to the firewall. This problem has been occurring for months and appears to be growing more frequent!
Who is Participating?
That message would appear to indicate that it stops being able to connect to the domain controllers.
One of the major issues with having a firewall in between the Exchange servers is that Exchange will talk to any of the domain controllers. You have to allow access through the firewall to all of them as Exchange will just change which one it is talking to.

Furthermore, Exchange doesn't fall over very quickly when one DC stops responding - I believe it is 30 minutes or more before Exchange goes looking for another DC. Your restarting the server forces the services to look for a domain controller and it continues responding.

It may also be the firewall closing the session.

The main thing that I would suggest would be to bring the server inside and see if the server remains active for the entire day - if it does then the firewall is causing the problem. The issue you have is that at the moment is that while the firewall is there suspicion must fall on that as being the cause or a contributor because its main job is to block traffic.

When it happens - does it occur for all users?
The most common fix for OWA problems is to flush out the temporary internet files on the client and then reconnect.

I will not pass comment on the Exchange in a DMZ... other than to post this link to my blog: http://www.sembee.co.uk/archive/2006/02/23/3.aspx

ncsc2006Author Commented:
Hi yes, when it happens, it happens for all users. It just happened again and now I have noticed an error that may be coinciding with the problem. It is in the App log on the front-end box. Process INETINFO.EXE (PID=712). All the DS Servers in domain are not responding. I have seen this error before and confirmed all necessary ports are open on the Pix (reviewed and compared to the ports in your article link as well). So, it does not appear to be a firewall problem, what other configuration issues could I have here? Again, rebooting the front-end server resolves but I cannot reboot the server 4-5 times daily.  
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.