Link to home
Start Free TrialLog in
Avatar of seriousfoodit
seriousfooditFlag for United Kingdom of Great Britain and Northern Ireland

asked on

Accessing OWA through a Watchguard Firebox X1000

Hi, can anyone tell me how to configure a firebox x1000 to allow remote users to connect in to OWA via the Intranet? I have set up SSL on the exchange server and created a service in the firebox using a NAT address from our firewall IP address to the exchange server but i still cannot connect to it.

Thanks in advance
Avatar of upul007
upul007
Flag of Sri Lanka image

A good place to start would be to look at the watchguard connection details tab (cant remember what its called) when someone external is trying to connect to the mail server. If there are Deny remarks you need to relook at why or what filter is causing the issue. I dont have access to a firebox till monday. Post a pointer to this in the firewall section. You will get quick help.
Your question is an oxymoron, "allow remote users to connect in to OWA via the Intranet"

There is nothing you need to do on the firebox for users to browse via the INTRANET. Have them point to the internal hostname.

For Browsing via the INTERNET...
Which Version are you using?

I know it's a stupid question, but do you have the users browsing to https://?

I have in my Policy Manager the  HTTPS Policy on... Incoming "Enabled and Allowed" From "Any" to  Public ip address -> Internal ip address.
Make sure if you have multiple IP address browsing in the right one is pointing to the internal address.

-Yossi
Avatar of seriousfoodit

ASKER

Thanks for the comments, I mean't to say Internet rather than Intranet, sorry about that. I have created a HTTPS Policy pointing from the public ip address -----> internal ip address in the Watchguard. When I go to the internet and type https://publicip:443/exchange, it just goes to a ie error page. I have also tried typing https://publicip/exchange, with the same error page. Everything looks correct and I am just a bit lost now.
are you getting dns page can't be found, or a number page?
Are you seeing it hit the traffic monitor?
We have looked at traffic monitor and there are no records of the connection being denied or accepted. The error page in ie is as below:
---------------------------------------------------------------
Internet Explorer cannot display the webpage
   
   Most likely causes:
You are not connected to the Internet.
The website is encountering problems.
There might be a typing error in the address.
 
   What you can try:
   Check your Internet connection. Try visiting another website to make sure you are connected.  
   Retype the address.  
   Go back to the previous page.  
    More information
This problem can be caused by a variety of issues, including:

Internet connectivity has been lost.
The website is temporarily unavailable.
The Domain Name Server is not reachable.
The Domain Name Server does not have a listing for the website's domain.
If this is an HTTPS (secure) address, click tools, click Internet Options, click Advanced, and check to be sure the SSL and TLS protocols are enabled under the security section.
------------------------------------------------------------

Not sure what is going on! It doesn't look like the connection is reaching the Firewall.
 
Make sure logging is turned on for that policy, or else you won't see it.
I'm looking over your first post... Did you custom create the policy, or did you use the one from the list?
We used the one from the list https service
Do you have logging on?
Have you been able to access the site within the lan?
yes can access within the lan and we have logging on now.
Tell you what, here is my email address. yossi@akselrud.com. Email me with a number I can reach you and when I get into the office in 45 Min. I will call you, and go over the settings I have.
I missed something.... Logging is on now... Do you see it hitting the firewall?

I should have asked this first... You are not trying to get to the external address from within the lan, right?
We have had someone externally try to use OWA and the firewall is blocking the port 443 along with their ip address.
ASKER CERTIFIED SOLUTION
Avatar of yakselrud
yakselrud
Flag of Afghanistan image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Just sent you contact info, thanks.