Solved

sbs 2011 not able to connect to owa externally

Posted on 2013-11-09
9
749 Views
Last Modified: 2014-01-06
Access from mobile device clients suddenly stopped working.  Worked with SonicWALL and the firewall appears to be forwarding correctly.  To further validate, the firewall settings were backed up and restored to a previously known working configuration.

Internal clients can access the https://server/owa without any trouble, but external clients cannot access OWA.

File Not Found

The requested URL was not found on this server: /owa

Open in new window


Access to https://server works and displays the SonicWALL Network Security Login (SSLVPN).

No known changes to the server configuration aside from updates.

Any advice would be greatly appreciated!
0
Comment
Question by:tj-a
9 Comments
 
LVL 24

Accepted Solution

by:
diverseit earned 167 total points
Comment Utility
Hi tj-a,

have you verified the NAT Policies and Access Rules in the SonicWALL?
0
 

Author Comment

by:tj-a
Comment Utility
Thanks diverseit, good point.  the rules are working for the SonicWALL https sslvpn connection, but that's redirecting to the SonicWALL device itself.  Maybe there should be a rule to redirect to the iis owa, but I believe it only works at a port level.  Maybe I should point to the iis server and have it redirect to the sw for access to the sw sslvpn?
0
 
LVL 9

Assisted Solution

by:guswebb
guswebb earned 166 total points
Comment Utility
Sounds like external requests on port 443 are not getting through to your IIS server. First check the firewall port forwarding rules.
0
 
LVL 35

Assisted Solution

by:Cris Hanna
Cris Hanna earned 167 total points
Comment Utility
is sonicwall https using port 443?
If so, you need to change that or neither owa or rwa will work
0
Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

 
LVL 24

Expert Comment

by:diverseit
Comment Utility
When you say,
Access from mobile device clients suddenly stopped working.
Mobile devices are typically setup via EAS and would be connecting outbound exclusively (WLAN > WAN). No inbound rules are needed for this to function if you are using EAS and Outlook Anywhere. Are you filtering outbound traffic?

As @CrisHanna_MVP said, if you are using the SonicWALL WAN IP address for HTTP or HTTPS port forwarding to a server, then the default Management port must be changed to another unused port number (e.g. 8080, 444, 4444, etc.). You can change this under the System > Administration page.

SonicWALL SSL-VPN should be running on default port 4433...not 443. Check to see if this has been changed to 443.

OWA access on the SonicWALL typically has 3 NAT policies: inbound, outbound and loopback (for internal domain request, e.g. https://owa.servername.com); and 1 firewall Access Rule for OWA from WAN to <whichever Zone the server is in...DMZ, LAN,etc.>.

Make sense?
0
 

Author Closing Comment

by:tj-a
Comment Utility
Turns out, there was a rule on the WAN for the SonicWALL management port.  Not sure why restoring the previously working settings didn't fix the issue, but once I unchecked https management on the WAN port, i was able to connect to exchange via https and from mobile clients.  

Thanks for steering me in the right direction!!
0
 

Author Comment

by:tj-a
Comment Utility
My apologies, I didn't realize the grade was set to less than an "A".  It took a couple of times to submit from my cell phone and I must have inadvertently selected a lower grade.  Definitely an "A" grade!
0
 
LVL 24

Expert Comment

by:diverseit
Comment Utility
No problem! Thanks for the clarification.

Cheers!
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
Resolve Outlook connectivity issues after moving mailbox to new Exchange 2016 server
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now