?
Solved

Using NTLM with RCP/HTTP Authentication for Exchange

Posted on 2006-06-28
8
Medium Priority
?
390 Views
Last Modified: 2008-01-09
We are using RCP/HTTP for Exchange access for all portable machines on our network.  We are able to get RCP/HTTP to work external from our network using Basic Authentication, and We are able to get NTLM to work when inside our network.  Unfortunatly, we cannot get NTLM to work outside our network.  When we start Outlook on an machine that was verified working locally, it waits then asks for a login.  The user can then try logging in using the user id alone as well as the basic authentication format (doman\username)  and it will not authenticate.  

Any ideas what might be causing the issue?
 
We have a fully qualified domain and are using a Sonicwall hardware firewall and have forwarded WAN requests from the following ports to the exchange server:

5800 - 5900  (TCP/UDP)
993  (TCP)
143 (TCP)
135-139 (TCP/UDP)
389  (TCP/UDP)
443  (TCP)
88   (TCP/UDP)
80  (TCP)
636 (TCP)
0
Comment
Question by:bitslv
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 104

Expert Comment

by:Sembee
ID: 17003987
The ONLY port you need for RPC over HTTPS to work is 443. Nothing else. The other ports can be closed unless you need them to be open. In fact some of those ports are dangerous to have open to the Internet - 135 especially.

Simon.
0
 

Author Comment

by:bitslv
ID: 17004114
I understand that and closed the unused ports including 135.  Unfortunatly, I still cannot understand why I cannot Get NTLM to work outside the network.  Port 443 is open.  Why would basic work, but not NTLM?
0
 
LVL 104

Expert Comment

by:Sembee
ID: 17004191
What authentication settings have you got set on the /rpc virtual directory in IIS Manager?

Simon.
0
Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 

Author Comment

by:bitslv
ID: 17004316
Basic Authentication was checked only.  Should "Integrated Windows Authentication" also be checked?

Thanks,

Brook

0
 

Author Comment

by:bitslv
ID: 17004570
The Default Domain and Realm are the same.  I selected the top three authentication methods.  

I still need to test externally, but which authentication methods do you suggest?
0
 
LVL 104

Accepted Solution

by:
Sembee earned 2000 total points
ID: 17004866
If basic authentication was enabled, then that would stop NTLM from working. You need to have both integrated and basic enabled. Do not enable anonymous.

Although it doesn't really matter, because RPC over HTTPS using https which is encrypted anyway.

Simon.
0
 

Author Comment

by:bitslv
ID: 17013669
That was it.  Thank you very much for your help.
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question