[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

OWA SSL not working outside of LAN

Posted on 2008-06-20
11
Medium Priority
?
590 Views
Last Modified: 2010-04-21
We're trying to do the whole RCP over HTTPS deal and the HTTPS OWA client work inside the LAN but outside we get a warning of a certificate error (in IE 7) and then a page cannot be displayed. We have a Sonicwall 2040 Firewall, Exchange 2003 SP2, SBS 2003 and IIS 6.0. I believe I have the port completely wide open on the sonic wall.

We have our main DC/AD server and then 4 other servers including our Exchange Server (of which we have just 1 of).

Please help!
0
Comment
Question by:pstiffsae
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
11 Comments
 
LVL 16

Expert Comment

by:LegendZM
ID: 21832089
Are you using a self signed certificate, or have you purchased one from an authorized authority? (such as godaddy)
0
 

Author Comment

by:pstiffsae
ID: 21832097
Yes, have a free one from FreeSSL for the next month.
0
 
LVL 16

Expert Comment

by:LegendZM
ID: 21832122
That would be why you're getting a certificate error. Unless you install the certificate on each user's computer, because it's not from a signed authority. You can purchase one from Godaddy for ~30$/yr and be done with the error message :)
0
NFR key for Veeam Agent for Linux

Veeam is happy to provide a free NFR license for one year.  It allows for the non‑production use and valid for five workstations and two servers. Veeam Agent for Linux is a simple backup tool for your Linux installations, both on‑premises and in the public cloud.

 

Author Comment

by:pstiffsae
ID: 21832162
Wait, for real, it's THAT easy?
0
 

Author Comment

by:pstiffsae
ID: 21832167
Can you explain a bit further?
0
 
LVL 16

Accepted Solution

by:
LegendZM earned 2000 total points
ID: 21832198
Sure,

The certificate error (if you can provide a screen shot and use the attach file function that would be great) Is because the certificate you're using is not from a trusted certificate authority. There are plenty of them out there, Verisign, Thawte, Godaddy (one of the cheapest ones but still trusted), and will eliminate the certificate error because they're in the trusted list within web browsers phones etc.

Now on the firewall, make sure port 443 and 80 are port forwarded to the server hosting exchange/IIS (they go hand in hand)  Also make sure forms based authentication is on/configured:
http://www.petri.co.il/configuring_forms_based_authentication_in_exchange_2003.htm
0
 

Author Comment

by:pstiffsae
ID: 21832209
Yeah, but when you continue on to the site, I get a page cannot be displayed error and no warning of the certificate error on IE 6. I can access the HTTPS site while in office, at home, I cannot. I get a page cannot be displayed.
0
 

Author Comment

by:pstiffsae
ID: 21832331
No, you were right on. I need to get a trust cert and I did't have the port forwarded to the exchange server properly on the firewall.
0
 

Author Closing Comment

by:pstiffsae
ID: 31469198
You literally saved me from another night of pulling my hair out. Thank you!
0
 
LVL 16

Expert Comment

by:LegendZM
ID: 21832348
Ok, lets go back a step

You have: Exchange 2003 SP2, SBS 2003 and IIS 6.0.

Is the Exchange 2003 sp2 on the SBS or is SBS separate, likewise, is IIS6 a server in itself? Or do you have all of this encompassed under the SBS server. Let's assume it's all encompassed.

You need more than having all the ports 'open' on the firewall, you need to Forward incoming requests on port 80, 443 to the internal ip 192.168.x.x (or another internal ip) of the SBS 2003 server.
0
 
LVL 16

Expert Comment

by:LegendZM
ID: 21832357
Glad I could help. :)
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
As much as Microsoft wants to kill off PST file support, just as they tried to do with public folders, there are still times when it is useful or downright necessary to export Exchange mailboxes to PST files. Thankfully, it is still possible to e…
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question