Solved

Publishing Exchange 2007 OWA using NTLM with Forefront TMG?

Posted on 2010-08-26
10
1,043 Views
Last Modified: 2012-06-21
Is there any benefit to making a separate rule for OWA in TMG so that NTLM can be used for authentication from the TMG server to the CAS?  This article suggests it when using ISA 2006, but I haven't been able to tell any difference and security shouldn't be an issue since we use SSL: http://www.isaserver.org/tutorials/Publishing-Exchange-2007-OWA-Exchange-ActiveSync-RPCHTTP-2006-ISA-Firewall-Part6.html 
0
Comment
Question by:mbromb
  • 5
  • 2
  • 2
10 Comments
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 33536732
Tom is as good a source of info on this subject as any - and, now that he works for Microsoft in the Forefront team - he is well worth listening to. If he is unsure of the reasoning - but states it needs doing - then it ceases to be a question of benefit and moves into the 'what screws up if I don't do it that way' territory.

Again - he states he is not sure why it has to be done and if he doesn't know, given his access to the developers, then I doubt we will be able to give a rationale for it either.



0
 

Accepted Solution

by:
mbromb earned 0 total points
ID: 33536755
I'm just rereading the following MS articles.  I think it's making more sense to me now.

http://technet.microsoft.com/en-us/library/bb794751.aspx#AppendixD
http://technet.microsoft.com/en-us/library/bb232199(EXCHG.80).aspx
0
 

Author Closing Comment

by:mbromb
ID: 33536875
Good Explanations in these articles
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 3

Expert Comment

by:aymanq
ID: 33536881
No benefit at all

YOu will still have to use FBA from outside , and between ISA and CAS is SSL as you say so there is no extra security feature, the article was just to illustrate this ability
0
 

Author Comment

by:mbromb
ID: 33536900
Well, if TMG is handling the authentication for you, and it is using NTLM then I would think you would get the benefit of NTLM even if using froms-based.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 33539288
I see you have accepted your own answer so therefore no further input is required.
0
 

Author Comment

by:mbromb
ID: 33542709
I would be willing to talk to the moderators or do what I can to give away the points if my answer is incomplete.  the documents state the benefits, and it seems they apply with ISA or TMG when publishing Exchange, but if I've got that wrong then that's a better answer.  If using forms-based on the listener nullifies using NTLM for delegation I would like to know.
0
 
LVL 3

Expert Comment

by:aymanq
ID: 33548708
I still beleive that using NTLM over SSL channel is same as using Basic authentication over SSL from security perspective.

You wont be required to enter your password again as ISA or TMG will use your password entered through FBA and use it against internal OWA VD.

The only thing I can see is if you didnt enable OWA Virtual Directory fro basic authentication "enabled by default" then you will need to use Integrated Windows Authentication delegation only.
0
 

Author Comment

by:mbromb
ID: 33558964
From a security perspective I agree, but I wanted to know the difference from a functional perspective.   According to the articles i posted above, there are additional functiona available using NTLM as the delegation auth.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question