Link to home
Start Free TrialLog in
Avatar of pramod1
pramod1Flag for United States of America

asked on

outlook web access, exchange 2010 windows server 2008

I  have installed new exchange server 2010 .I have migrated from exchange 2003 to exchange 2010.

on exchange 2003 i had owa address configured in my watchguard firewall.

Iwant to congifure new owa address which starts with https:

I already see default https  policy name their with port 443.(any trusted-any external)

do i need to create seperate https address for new OWA ?(any external - publi ip-internal ip

please help



Avatar of NJComputerNetworks
NJComputerNetworks
Flag of United States of America image

probably... does you rule forward 443 to a specific internal IP address?  This is probably pointing to your OLD OWA server...  So, you most likely have to update the internal IP with the IP of the new Exchange 2010 server.

What is your OWA address, I can try to connect if you like...
ASKER CERTIFIED SOLUTION
Avatar of NJComputerNetworks
NJComputerNetworks
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of pramod1

ASKER

as i told earlier i had earlier exchange server 2003
people are still using that server as some mailboxes are still there. for people who are using owa.
owa.isherman.com/exchange (this is for old exchnage server) and has configured owa in firewall
from any external-public ip-internal ip of exchange
my new exchange 2010
https://sherman-mail2.shermaninternational.com/owa

my new owa stands with https address so i just can't update the old owa address as it is just http.

so that was my question

should i create another https owa address as i see a deafult https address with port 443 in my firewall

Avatar of pramod1

ASKER

thanks for reply but here the thing is:
as i told earlier i had earlier exchange server 2003
people are still using that server as some mailboxes are still there. for people who are using owa.
owa.isherman.com/exchange (this is for old exchnage server) and has configured owa in firewall
from any external-public ip-internal ip of exchange
my new exchange 2010
https://sherman-mail2.shermaninternational.com/owa

my new owa stands with https address so i just can't update the old owa address as it is just http.

so that was my question

should i create another https owa address as i see a deafult https address with port 443 in my firewall

OK... sorry, I guess I diddn't fully understand...

But I think I get it now...

You need both old and new OWA working....

So, yes, you will have to create an ADDITIONAL rule...

allow 443 traffic destined for 98.141.137.84 public IP to your Internal IP address of the Exchange 2010 server.

Avatar of pramod1

ASKER

when i try to create https policy the firewall gives me error

it conflicts with auto congigured  ssl-vvn policy at port 443 and says cannot create https policy.

how should i create then.
Avatar of pramod1

ASKER

I AM GETTING THE FOLLOWING ERROR WHILE CRAETING HTTPS POLICY FOR MY NEW OWA IN MY FIREWALL

"PRIMARY AND BACK UP IP ADDRESS OF SSL-VPN CANNOT BE USED AS THE NAT FROM IP IN SNAT AND SERVER LOAD BALANCING POLICIES WITH THE SAME LISTENING PORT OF SSL-VPN"

YOUR OWA HTTPS VIOLATES SUCH CONDITION.