Solved

RPC OVER HTTP WORKS INTERNALLY BUT NOT EXTERNALLY

Posted on 2006-06-27
15
454 Views
Last Modified: 2010-03-06
I setup RPC over HTTP on my Exchange 2003 box that runs windows 2003 server.  RPC over HTTP works internally but not externally.  Can anyone give me some clue??  I do have a firewall and its a sonicwall. Do I need to add specific ports.  I added ports 6001, 6002, and 6004 and forwarded them to my exchange server.
0
Comment
Question by:Matt Pessolano
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
  • 4
15 Comments
 
LVL 31

Expert Comment

by:LeeDerbyshire
ID: 16992909
Depending on whether your using HTTP or HTTPS, you will need to forward port 80 or 443.
0
 
LVL 6

Expert Comment

by:Michael S
ID: 16992935
Those ports don't need to be forwarded on your firewall - they are ports that Exchange uses internally.

You need to have SSL forwarded with a certificate installed in IIS, and configure RPC over HTTPS to point to your external DNS.

Follow this link for more info:

http://www.amset.info/exchange/rpc-http-server.asp

Jay
0
 
LVL 1

Author Comment

by:Matt Pessolano
ID: 16993078
i deleted those other post and forwarded port 80 to my exchange server and I get the login prompt but then it never connects
0
Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

 
LVL 31

Expert Comment

by:LeeDerbyshire
ID: 16993183
Have a look under the Tutorials section of this link:
http://www.msexchange.org/pages/search.asp?query=rpc
There are lots of RPC/HTTPS articles there.
0
 
LVL 31

Expert Comment

by:LeeDerbyshire
ID: 16993346
Come to think of it, do you have a computer (say a laptop) that can be connected to the server either directly via the LAN, and also from the Internet?  Since you said that it works internally, it would be good if you could use a computer that is known to work internally, and then try to get it to connect externally.  That way, you can be sure that all your settings are right, and that you need to look at the firewall.
0
 
LVL 1

Author Comment

by:Matt Pessolano
ID: 16993419
yea I do that is what I am using.  A laptop.  
0
 
LVL 31

Expert Comment

by:LeeDerbyshire
ID: 16993507
Is there any way you can get the laptop connected externally, get the IP address, and then temporarily allow all traffic from that IP to the server - just to see if there is a firewall problem?  As far as I know, this doesn't require any other ports beside the HTTP/S ones, but it's possible that a sophisticated firewall might need to be told more about the kind of traffic going through it.
0
 
LVL 6

Expert Comment

by:Michael S
ID: 16993547
You have to have an SSL certificate in order for it to work externally.  It is a misnomer to call it RPC over HTTP, when it is in reality RPC over HTTPS.  If you try to connect just over HTTP, you'll be banging your head against a wall for days.
0
 
LVL 1

Author Comment

by:Matt Pessolano
ID: 16993566
no right now im just doing rpc/http  im still not getting anywhere
0
 
LVL 1

Author Comment

by:Matt Pessolano
ID: 16993572
i tried the firewall portion as well. Im allowed access.  Does the global catalog server have to be windows 2003 in order for this to work?
0
 
LVL 6

Expert Comment

by:Michael S
ID: 16993646
On the computer that you say works internall, go to Start/Run and type in outlook.exe /rpcdiag.

Under the Conn heading if it is working properly it will say HTTPS.  If it is not working properly it will say TCP/IP.
0
 
LVL 1

Author Comment

by:Matt Pessolano
ID: 16994158
when i type that in Outlook just pops up.  I dont get anything else.
0
 
LVL 31

Expert Comment

by:LeeDerbyshire
ID: 16994361
Make sure that you don't already have OL running.  The /rpcdiag switch will open OL as normal, but there should be another window appearing on the screen somewhere.
0
 
LVL 1

Author Comment

by:Matt Pessolano
ID: 16994381
it says tcp/ip
0
 
LVL 6

Accepted Solution

by:
Michael S earned 500 total points
ID: 16994447
I would start over and follow this link:

http://www.amset.info/exchange/rpc-http.asp

You will need an SSL certificate.  You can either use your own CA or download a temporary one from www.rapidssl.com

Simon's guide works very well, along with the one at http://www.petri.co.il/configure_rpc_over_https_on_a_single_server.htm

Good luck!
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
This article explains how to install and use the NTBackup utility that comes with Windows Server.
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question