Solved

Exchange server 2007 / windows server 2003- domain authentication question

Posted on 2007-11-29
5
268 Views
Last Modified: 2010-03-06
Hi,
I have a domain that is called "mycompany.local" in Active Directory.
When installing Exchange server 2007 I ran into a problem trying to get Outlook Anywhere to work. I can't get it to work if the Exchange server is not accessed with the ".local" domain name, autentication don't work if I define an external hostname with ".com" domain.
I can edit all the hosts files and enter the ".local" domain name there but we use NAT and the hostname is different when the users is inside or outside the firewall.

How can I make this work?
Does the AD domain need to be the same as external domain to make Outlook Anywhere work or is there a way around this?
Is it a way to make Outlook Anywhere work without renaming/reinstalling the domain?
0
Comment
Question by:rj2
  • 3
  • 2
5 Comments
 
LVL 15

Expert Comment

by:JimboEfx
Comment Utility
What certificate is your CAS server using? Outlook anywhere requires a trusted cert with a SAN attribute if i recall correctly for it to work internally and externally.

http://exchangepedia.com/blog/2007/08/outlook-anywhere-and-exchanges-self.html

http://www.msexchange.org/articles_tutorials/exchange-server-2007/mobility-client-access/securing-exchange-2007-client-access-server-3rd-party-san-certificate.html
0
 
LVL 10

Author Comment

by:rj2
Comment Utility
It uses certificate for mycompany.com
0
 
LVL 10

Author Comment

by:rj2
Comment Utility
What I would like ideally is to keep my internal AD domain mycompany.local, use external domain mycompany.com and just make Outlook Anywhere work. But so far I have only been able to connect using Outlook Anywhere from outside the firewall using hostname "mail.mycompany.local" and setting the IP in the hosts file. Even though the SSL certificate is for "mail.mycompany.com"
0
 
LVL 15

Accepted Solution

by:
JimboEfx earned 250 total points
Comment Utility
First of all check this forum post:
http://forums.msexchange.org/m_1800438631/mpage_1/key_/tm.htm#1800455745

If that doesn't work I suppose you may find some use in the articles below.

Configuring Outlook Anywhere to Use an SSL Certificate with Redirection
http://technet.microsoft.com/en-us/library/bb310764.aspx

How to Configure an External Host Name for Outlook Anywhere (though i think you have already done this)
http://technet.microsoft.com/en-us/library/aa996902.aspx

How to Configure SSL Certificates to Use Multiple Client Access Server Host Names
http://technet.microsoft.com/en-us/library/aa995942.aspx
0
 
LVL 10

Author Comment

by:rj2
Comment Utility
It is working now. The link http://forums.msexchange.org/m_1800438631/mpage_1/key_/tm.htm#1800455745 was right on. Thanks.
0

Featured Post

Wish Marketing would stop bothering you?

Is your marketing department constantly asking for new email signature updates? Are they requesting a different design for every department? Do they need yet another banner added? Don’t let it get you down! There is an easy way to manage all of these requests...

Join & Write a Comment

Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now