RE: OWA Bridging mode,

  • From: "Thomas W Shinder" <tshinder@xxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Mon, 26 Sep 2005 07:41:52 -0500

Hi Ruba,
 
The Exchange Server definitely should not be running the Firewall
client.
 
Thomas W Shinder, M.D.
Site: www.isaserver.org <http://www.isaserver.org/> 
Blog: http://spaces.msn.com/members/drisa/
Book: http://tinyurl.com/3xqb7 <http://tinyurl.com/3xqb7> 
MVP -- ISA Firewalls

 


________________________________

        From: Ruba Al Omari [mailto:romari@xxxxxxxxxxxxxxxxx] 
        Sent: Monday, September 26, 2005 3:35 AM
        To: [ISAserver.org Discussion List]
        Subject: [isalist] OWA Bridging mode,
        
        
        http://www.ISAserver.org
        

        Dear list,

         

        Am trying to publish an exchange 2003 behind and ISA2004 in
bridging mode, after the FBA login screen I receive a File not found
error with the below in the log file.

        If I add a web chaining rule that retrieve requests for the
internal exchange directly, the publishing rule works fine.

        Is it ok to leave this web chaining rule in place or is it
actually over writing the publishing rule and working on its own? Or
else should I add an access rule between the ISA and the internal
exchange?

        The exchange has a firewall client for the ISA, and  it has the
ISA as its default gateway, and the ISA can ping the OWA internal IP
from the ISA correctly.

         

        Original Client IP            Client Agent      Authenticated
Client       Service  Server Name      Referring Server Destination Host
Name    Transport           MIME Type        Object Source   Source
Proxy    Destination Proxy          Bidirectional      Client Host Name
Filter Information            Network Interface           Raw IP Header
Raw Payload     Source Port       Processing Time            Bytes Sent
Bytes Received  Result Code      HTTP Status Code         Cache
Information          Error Information            Log Record Type
Log Time           Destination IP    Destination Port Protocol
Action   Rule      Client IP            Client Username
Source Network Destination Network       HTTP Method    URL

        213.230.9.21                                         ISA       -
TCP      -
-                                                13479   0          0
0          0x0                   0x0       0x0       Firewall 9/26/2005
11:00:35 AM       10.116.60.10     443       HTTPS  Initiated Connection
213.230.9.21                 External            Local Host            -
-

        213.230.9.18                                         ISA       -
TCP      -
-                                                58157   4000     1412
3278     0x80074e20                   0x0       0x0       Firewall
9/26/2005 11:00:35 AM      10.116.60.10     443       HTTPS  Closed
Connection                     213.230.9.18                 External
Local Host         -           -

        0.0.0.0  Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1;
.NET CLR 1.1.4322)      Yes      Reverse Proxy   ISA
webmail.daralhekma.edu.sa        TCP                  Upstream
-           -                       -                       -
-            -           0          22954   2155     617
10060   0x8       0x40     Web Proxy Filter            9/26/2005
11:00:58 AM       212.71.32.84     443       https     Failed Connection
Attempt          OWA    213.230.9.21     DAH\romari       External
GET      http://webmail.daralhekma.edu.sa/exchange

        213.230.9.18                                         ISA       -
TCP      -
-                                                46459   0          0
0          0xc0040017 FWX_E_TCP_NOT_SYN_PACKET_DROPPED
0x0       0x0       Firewall 9/26/2005 11:01:13 AM  10.116.60.10     443
HTTPS  Denied Connection                     213.230.9.18
External            Local Host         -           -

         

         

        Thanks,

        r.

        ------------------------------------------------------
        List Archives:
http://www.webelists.com/cgi/lyris.pl?enter=isalist
        ISA Server Newsletter:
http://www.isaserver.org/pages/newsletter.asp
        ISA Server FAQ:
http://www.isaserver.org/pages/larticle.asp?type=FAQ
        ------------------------------------------------------
        Visit TechGenix.com for more information about our other sites:
        http://www.techgenix.com
        ------------------------------------------------------
        You are currently subscribed to this ISAserver.org Discussion
List as: tshinder@xxxxxxxxxxxxxxxxxx
        To unsubscribe visit
http://www.webelists.com/cgi/lyris.pl?enter=isalist
        Report abuse to listadmin@xxxxxxxxxxxxx 

Other related posts: