Avatar of RemcoVi
RemcoVi
Flag for Netherlands asked on

Windows SBS 2011 / Exchange 2010, change listening port of OWA and keep autodiscover working

I have a situation where i can't get my autodiscover to work for some reason.
I have a Windows Small Business Server 2011 Standard wich contains Exchange 2010 offcourse.

I need to adjust the listening port of my OWA, because the default HTTPS port is used for a primary application.

So i found wizards and read alot about it and i have managed to change the port to 3500.

When i go to the url: https://remote.companyname.com:3500/owa everything looks great and my multidomain certificate is working and it looks great.

But for some reason when i start Outlook, Outlook pops up a message about my certificate and the first 2 checkmarks are ok, but the 3rd isn't.

When i view the certificate the name corresponding in that certificate is one i can't find in my Exchange Management Console at the certificate overview and i think this one is from the company where the first SSL certificate is from, wich i used last year.

When i do a connection test in with my outlook i receive an error 0x80004005.

Anyone who has the time and would like do the effort to help me with the last piece to get this up and running?
SBSExchangeOutlook

Avatar of undefined
Last Comment
RemcoVi

8/22/2022 - Mon
Cliff Galiher

By definition, autodiscover works by using defaults so the "auto" part can kick in. By changing your setup to a manual port, you inherently broke autodiscover.

The proper solution to your issue is to run a second application server (ALWAYS recommended) and if external access is required, have two public IPs and publish the app using a reverse proxy. This keeps your configuration clean, secure, industry standard, resolves port conflicts, and if you virtualze. Actually gives you better server utilization resulting in lower overall costs in energy and performance.

-Cliff
RemcoVi

ASKER
True, but in this case i have no choice. The application stealing my HTTPS is their core application and they want to use OWA for synching with their mobile 2.

Getting an internet connection with multiple IP adresses is not possible on that location, so i have no choice.

So any idea how to get this up and running?

Other solution is Port Redirection in my router, but i don't think OWA accept it when i redirect an external port 3500 to an internal 443 port and everything will still keep working.
Cliff Galiher

It simply cannot be done. They want two contradictory goals. They might as well asks you to make their servers run MS-DOS since there are fewer viruses for that OS, but they want all their 64-bit windows 2008 R2 programs to keep working in that DOS environment.

Sometimes the hardest job of an IT pro is telling the boss/client that they have to make a choice. If you cannot build the environment they want or they are unwilling to orovide the resources for it, then they have to choose which features and functions get dropped. That is the position you now find yourself in.

-Cliff
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
RemcoVi

ASKER
I think i need to make a new question or maybe you could help me.
The only solution i have is changing the external port of my Citrix Fundamentals environment.

Is this possible?

Because then i could use this internet connection for the replies above and then i can change the port 3500 back to 443.
ASKER CERTIFIED SOLUTION
Cliff Galiher

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
RemcoVi

ASKER
I though i had replied this message, but appearantly not.

Thanks for you advice and the customer is waiting for a fiber connection wich will come standard with multiple IP adresses.

Again thanks