• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 817
  • Last Modified:

SBS 2003 with ISA 2004 - Enabling Outlook Web Access

Hey All,

I am having a major issue with SBS 2003 & ISA 2004. I need to get access to OWA from outside the business.

Exchange and OWA work fine inside the local network its the outside to inside that there is a problem!

Network Info below:-



What I have done so far....

- Run Configure E-mail and Internet Connection Wizard
- Entered my DNS Settings and IP of Router (
- Specified my network WAN & LAN in the drop downs
- Click Enable Firewall
- Put a tick in the E-mail box
- Allow Access to the following Web Site Services from the Internet: Outlook Web Access, Remote Web Workplace, Outlook Mobile Access, Outlook via the Internet
- Then it gives me a summary about what I want it to do
- Click finish

I then get an error:
An error occurred while configuring your Universal Plug and Play Router.

To Cancel the wizard now without configuring remaining components, click Cancel.
To continue configuring remaining components without configuring the router, click OK.

In either case, you must run the wizard again. When the Wizard asks you if you want to automatically configure your router, click No. You must then Manually configure the router by using the information in Appendix C of the Getting Started guide.

- So I click ok

Now the issue is that when I re run the wizard again there is no option at all that I can see that says that I don't want it to configure my device by UPnP? Am I missing something?

I have a Linksys X3000 Router and I have made sure that UPnP is on as well and it still comes up with the error.

Ok on the Router side of things:

Port Forwarding is enable for:-
Https to IP Address =
Http to IP Address =

So I am really stuck on where to go next with this. Is this a problem with ISA, SBS or my Router?!

Or maybe all 3?

Thanks for your help in advance
  • 4
  • 3
  • 2
2 Solutions
To be honest, I never use UPnP. I would just disable it on the router, then run the CEICW again.  If your connection to the internet is already working, then you can just choose the option for "Do not change connection type".  With the ports forwarded as they are it should work.

If not, can you tell me if you see the following rule in ISA?
SBS OWA Web Publishing Rule

Then we can dig into the settings for this rule and it's web listener.
I've unfortunately retired all the SBS2003 boxes I had, so can't easily test this for you, however I've usually followed this man's guide:
And had success - I doubt it's your Linksys causing the problem, ISA's a more likely candidate, but you could test this theory by seeing if it works from a laptop temporarily connected in the 192.168.1.x range.
dan4132Author Commented:
Hey Guys,

Thanks for the response. I definatly agree with you that I think ISA is the culprit here.

I have taken screenshots of my config so you can have a look to see if anything points out at you thats wrong.
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

dan4132Author Commented:
Ok I found the problem.. it was the Web listener that didn't have all networks selected. (Pic Attached)

But now I have a new problem when I try to access mywebsite/exchange:

The page cannot be displayed  
Explanation: There is a problem with the page you are trying to reach and it cannot be displayed.


Try the following:

Refresh page: Search for the page again by clicking the Refresh button. The timeout may have occurred due to Internet congestion.
Check spelling: Check that you typed the Web page address correctly. The address may have been mistyped.
Access from a link: If there is a link to the page you are looking for, try accessing the page from that link.


Technical Information (for support personnel)

Error Code: 500 Internal Server Error. The target principal name is incorrect. (-2146893022)
There's a few causes for this error - try looking at the MS article here:
http://technet.microsoft.com/en-us/library/bb794843.aspx (scroll down to "Certificate Issues") or the ISAServer article here:
dan4132Author Commented:
Figured out it was to do with the Certificate not matching but have corrected that...

Now another problem... :-/

I have now managed to get to the login page on exchange but it will not let me login. It doesn't come up with an error.. just flashes back to the login page as soon as I press enter..

I found this in ISA...
I don't know where to start with this one.  Looking at your firewall rules, there seems to be a number that shouldn't be needed and the order is really weird.  You shouldn't have needed to set the web listener to listen on anything except the external network.  It looks like you've modified the listener to use FBA instead of integrated authentication (on SBS by default the Exchange Virtual Server handles this - only one should be configured for FBA).

There used to be a good article on the web about rule order in ISA for SBS (I think by Amy Babinchak) but I can no longer find it.  If I remember correctly, she recommends most additional access rules to be placed between the SBS Protected Networks Access Rule and the SBS Internet Access rule.  I'm attaching a screenshot of the default rule order.

Honestly I wouldn't even try to troubleshoot it until I got it back to a more standard configuration.  There's just too many things that could be happening here.  Best of luck.
dan4132Author Commented:
Awesome you solved it for me.. I reordered and disabled all of the unused ones for the time being before I delete them.

And it was as you said because it was using form based instead of integrated authentication.

Much appreciated guys for your input!
Glad you got it working!
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Cloud Class® Course: MCSA MCSE Windows Server 2012

This course teaches how to install and configure Windows Server 2012 R2.  It is the first step on your path to becoming a Microsoft Certified Solutions Expert (MCSE).

  • 4
  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now