?
Solved

Exchange 2010 OWA 403 error

Posted on 2014-01-08
7
Medium Priority
?
863 Views
Last Modified: 2014-02-04
When attempting to connect to OWA via mail.mydomain.com from the internet I am receiving the following:

Error code: 403 forbidden. The server denied the specific uniform resource locator.

I have this set as a published rule in ISA server 2006. Since I am receiving the 403 error I am going to assume this is some sort of an authentication issue.

Under the listener tab > properties, I have the authentication mode set to HTML for authentication and windows (active directory)

Now on the authentication delegation tab, I have it set to "no delegation, but client may authenticate directly"

On the exchange server, the CAS is set to basic authentication.

Thank you
0
Comment
Question by:Yeloball
7 Comments
 
LVL 13

Expert Comment

by:Norm Dickinson
ID: 39765752
This may be a simple denial from your router or firewall blocking the connection. Make sure you have set up port forwarding for the connection to work.
0
 

Author Comment

by:Yeloball
ID: 39765768
Port forwarding on the ISA server or another firewall on the network?
0
 
LVL 13

Expert Comment

by:Norm Dickinson
ID: 39765778
Port forwarding starts at the public-facing side of your network - typically the router on smaller networks. Start by looking there to see if the settings are in place to allow it to forward the proper ports - they vary depending on what protocol you are using - to the correct internal IP address for processing by your email / ISA server. If there are other firewalls on the network from there, work your way in to allow the traffic that needs to go to the server to get there.
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 12

Accepted Solution

by:
David Paris Vicente earned 1500 total points
ID: 39765798
Can you confirm that the to tab& Public Name tab on the policy settings on your ISA 2006 box  has the correct names?

 When you are publishing OWA 2010 you can still use SAN Certificate on the Exchange OWA side. However the FQDN name that appears on the To Tab on the ISA Server 2006 OWA Publishing rule needs to match with the first name on the SAN Certificate.
0
 

Author Comment

by:Yeloball
ID: 39765879
As an example. What I have listed on my "TO" tab is mail.my.domain.com, then when I look at my listner tab properties window, my certificate is listed as mail.mydomain.com.

Does that look correct?
0
 
LVL 16

Expert Comment

by:Dirk Mare
ID: 39766093
I would start with testing with

https://testconnectivity.microsoft.com

It will tell you exactly what needs to be changed or it will give you recommendations..

DirkMare
0
 
LVL 1

Expert Comment

by:soniczoom5
ID: 39768087
have you looked at the ISA logs yet? I would enable logging and set a filter to listen for the external IP you are testing from; that way you can at least see if the traffic is hitting the ISA server; if it is hitting it, then move to the IIS logs within Exchange to see if the traffic is reach the Exchange server
0

Featured Post

Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

In a Cross Forest, the steps to migrate users are quite complicated and even in the official articles of Technet there is no clear recommendation on which approach to take .. From an experience, I mention and simplify which way to go and how to use …
How to Import Outlook PST file to Exchange Server Mailbox without Powershell and Exchange Admin Center. Use SysTools Exchange Import Tool to Move PST file in Exchange 2016 / 13 / 10/ 07 Server Mailbox including Contacts, Calendar, Task and journal d…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

590 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question