<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: howto://publish OWA through TMG</title> <atom:link href="http://retrohack.com/how-to-publish-owa-through-tmg/feed/" rel="self" type="application/rss+xml" /><link>http://retrohack.com/how-to-publish-owa-through-tmg/</link> <description>lest the tubes become overfull</description> <lastBuildDate>Tue, 15 May 2012 22:46:35 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=</generator> <item><title>By: Ian</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-3003</link> <dc:creator>Ian</dc:creator> <pubDate>Tue, 01 May 2012 04:28:27 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-3003</guid> <description>Hi Ed,Thanks for writing this tutorial, and spending so much time troubleshooting your reader&#039;s issues so long after you wrote the original article.  :)Cheers,Ian</description> <content:encoded><![CDATA[<p>Hi Ed,</p><p>Thanks for writing this tutorial, and spending so much time troubleshooting your reader&#8217;s issues so long after you wrote the original article. <img
src='http://retrohack.com/_retroh_wp_root/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p><p>Cheers,</p><p>Ian</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2972</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Thu, 29 Mar 2012 14:22:32 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2972</guid> <description>1. Is the TMG a domain member?
2. If not, how have you configured it to authenticate to AD? LDAP?
3. Is your local admin account on TMG using the same password as your domain admin?
4. Can you access OWA using the internal URL, using the browser on the TMG?
5. When you try to log on to OWA through the TMG, and it gives you the error you mention above, what error does it show in the TMG logs?</description> <content:encoded><![CDATA[<p>1. Is the TMG a domain member?<br
/> 2. If not, how have you configured it to authenticate to AD? LDAP?<br
/> 3. Is your local admin account on TMG using the same password as your domain admin?<br
/> 4. Can you access OWA using the internal URL, using the browser on the TMG?<br
/> 5. When you try to log on to OWA through the TMG, and it gives you the error you mention above, what error does it show in the TMG logs?</p> ]]></content:encoded> </item> <item><title>By: Tim</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2971</link> <dc:creator>Tim</dc:creator> <pubDate>Thu, 29 Mar 2012 01:38:21 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2971</guid> <description>Followed this, got OWA working. But I can&#039;t seem to login to OWA with any account besides the administrator account. Have created other users in the New user wizard on the Exchange server. The error I get is: &quot;You could not be logged on to Forefront TMG. Make sure that your domain name, user name, and password are correct, and then try again.&quot; Any ideas? Thanks!</description> <content:encoded><![CDATA[<p>Followed this, got OWA working. But I can&#8217;t seem to login to OWA with any account besides the administrator account. Have created other users in the New user wizard on the Exchange server. The error I get is: &#8220;You could not be logged on to Forefront TMG. Make sure that your domain name, user name, and password are correct, and then try again.&#8221; Any ideas? Thanks!</p> ]]></content:encoded> </item> <item><title>By: Jan</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2923</link> <dc:creator>Jan</dc:creator> <pubDate>Mon, 12 Mar 2012 10:19:40 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2923</guid> <description>Hi Ed,I&#039;ve found the flaw in my deny rule.
At the &quot;path&quot; section the internal path was /* and that should be /.
Now the deny and allow rule is working as expected</description> <content:encoded><![CDATA[<p>Hi Ed,</p><p>I&#8217;ve found the flaw in my deny rule.<br
/> At the &#8220;path&#8221; section the internal path was /* and that should be /.<br
/> Now the deny and allow rule is working as expected</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2918</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Fri, 09 Mar 2012 20:30:20 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2918</guid> <description>Ah, but my post is based on a two NIC server that is a domain member. I&#039;m not saying you cannot do it the way you have it, but I am saying that I don&#039;t do single NIC, and haven&#039;t done workgroup with LDAP since ISA 2006, so my guidance won&#039;t be as good as you might wish on this. And the ASA puts another variable into the mix. My first thought is that if the TMG is challenging you for auth, and then you keep getting the prompt but NOT an access denied or account lockout, your TMG is not making LDAP connections to your DCs.
1. Copy LDP.EXE to the TMG server and make sure you can connect to AD from the TMG using that app. LDAP binds usually require an account to authenticate with, so make sure you do that using whatever service account you have setup and not your own domain account.
2. I&#039;m hoping you setup LDAP to use SSL, so make sure you test with LDP using SSL. Your firewall will have to permit TCP 636 from the TMG to the DCs, and 3269 if you are hitting a GC.</description> <content:encoded><![CDATA[<p>Ah, but my post is based on a two NIC server that is a domain member. I&#8217;m not saying you cannot do it the way you have it, but I am saying that I don&#8217;t do single NIC, and haven&#8217;t done workgroup with LDAP since ISA 2006, so my guidance won&#8217;t be as good as you might wish on this. And the ASA puts another variable into the mix. My first thought is that if the TMG is challenging you for auth, and then you keep getting the prompt but NOT an access denied or account lockout, your TMG is not making LDAP connections to your DCs.<br
/> 1. Copy LDP.EXE to the TMG server and make sure you can connect to AD from the TMG using that app. LDAP binds usually require an account to authenticate with, so make sure you do that using whatever service account you have setup and not your own domain account.<br
/> 2. I&#8217;m hoping you setup LDAP to use SSL, so make sure you test with LDP using SSL. Your firewall will have to permit TCP 636 from the TMG to the DCs, and 3269 if you are hitting a GC.</p> ]]></content:encoded> </item> <item><title>By: Andrew</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2917</link> <dc:creator>Andrew</dc:creator> <pubDate>Fri, 09 Mar 2012 20:20:47 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2917</guid> <description>No, it is a standalone, single NIC in the DMZ with Edge sitting behind a Cisco ASA firewall.
I am attempting to authenticate via LDAP.
My web listeners and rules are set up using the schema set up in your posts.</description> <content:encoded><![CDATA[<p>No, it is a standalone, single NIC in the DMZ with Edge sitting behind a Cisco ASA firewall.<br
/> I am attempting to authenticate via LDAP.<br
/> My web listeners and rules are set up using the schema set up in your posts.</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2916</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Fri, 09 Mar 2012 20:00:59 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2916</guid> <description>Is your TMG a member of your domain?
How are you entering your username? username, domain\username, username@domain?</description> <content:encoded><![CDATA[<p>Is your TMG a member of your domain?<br
/> How are you entering your username? username, domain\username, username@domain?</p> ]]></content:encoded> </item> <item><title>By: Andrew</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2915</link> <dc:creator>Andrew</dc:creator> <pubDate>Fri, 09 Mar 2012 19:09:13 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2915</guid> <description>I keep getting the Login credentials pop up box but it will not accept the username or password.[PS] C:\Windows\system32&gt;Get-OutlookAnywhere &#124;flRunspaceId                      : 9d9211d3-8e96-4bc4-bd5b-a3a833b57b2b
ServerName                      : myexchange
SSLOffloading                   : False
ExternalHostname                : webmail.mydomain.com
ClientAuthenticationMethod      : Ntlm
IISAuthenticationMethods        : {Ntlm}
XropUrl                         :
MetabasePath                    : IIS://myexchange.mydomain.local/W3SVC/1/ROOT/Rpc
Path                            : C:\Windows\System32\RpcProxy
ExtendedProtectionTokenChecking : None
ExtendedProtectionFlags         : {}
ExtendedProtectionSPNList       : {}
Server                          : myexchange
AdminDisplayName                :
ExchangeVersion                 : 0.10 (14.0.100.0)
Name                            : Rpc (Default Web Site)
DistinguishedName               : CN=Rpc (Default Web Site),CN=HTTP,CN=Protocols,CN=myexchange,CN=Servers,CN=Exchange Adm
inistrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Mydomain,CN=Microsoft
Exchange,CN=Services,CN=Configuration,DC=mydomain,DC=local
Identity                        : myexchange\Rpc (Default Web Site)
Guid                            : c1b2a926-6baf-40e1-8982-5e3d85f4fdd7
ObjectCategory                  : mydomain.local/Configuration/Schema/ms-Exch-Rpc-Http-Virtual-Directory
ObjectClass                     : {top, msExchVirtualDirectory, msExchRpcHttpVirtualDirectory}
WhenChanged                     : 3/9/2012 11:02:36 AM
WhenCreated                     : 3/8/2012 2:50:00 PM
WhenChangedUTC                  : 3/9/2012 7:02:36 PM
WhenCreatedUTC                  : 3/8/2012 10:50:00 PM
OrganizationId                  :
OriginatingServer               : MyDC2.meritus.local
IsValid                         : True</description> <content:encoded><![CDATA[<p>I keep getting the Login credentials pop up box but it will not accept the username or password.</p><p>[PS] C:\Windows\system32&gt;Get-OutlookAnywhere |fl</p><p>RunspaceId                      : 9d9211d3-8e96-4bc4-bd5b-a3a833b57b2b<br
/> ServerName                      : myexchange<br
/> SSLOffloading                   : False<br
/> ExternalHostname                : webmail.mydomain.com<br
/> ClientAuthenticationMethod      : Ntlm<br
/> IISAuthenticationMethods        : {Ntlm}<br
/> XropUrl                         :<br
/> MetabasePath                    : IIS://myexchange.mydomain.local/W3SVC/1/ROOT/Rpc<br
/> Path                            : C:\Windows\System32\RpcProxy<br
/> ExtendedProtectionTokenChecking : None<br
/> ExtendedProtectionFlags         : {}<br
/> ExtendedProtectionSPNList       : {}<br
/> Server                          : myexchange<br
/> AdminDisplayName                :<br
/> ExchangeVersion                 : 0.10 (14.0.100.0)<br
/> Name                            : Rpc (Default Web Site)<br
/> DistinguishedName               : CN=Rpc (Default Web Site),CN=HTTP,CN=Protocols,CN=myexchange,CN=Servers,CN=Exchange Adm<br
/> inistrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Mydomain,CN=Microsoft<br
/> Exchange,CN=Services,CN=Configuration,DC=mydomain,DC=local<br
/> Identity                        : myexchange\Rpc (Default Web Site)<br
/> Guid                            : c1b2a926-6baf-40e1-8982-5e3d85f4fdd7<br
/> ObjectCategory                  : mydomain.local/Configuration/Schema/ms-Exch-Rpc-Http-Virtual-Directory<br
/> ObjectClass                     : {top, msExchVirtualDirectory, msExchRpcHttpVirtualDirectory}<br
/> WhenChanged                     : 3/9/2012 11:02:36 AM<br
/> WhenCreated                     : 3/8/2012 2:50:00 PM<br
/> WhenChangedUTC                  : 3/9/2012 7:02:36 PM<br
/> WhenCreatedUTC                  : 3/8/2012 10:50:00 PM<br
/> OrganizationId                  :<br
/> OriginatingServer               : MyDC2.meritus.local<br
/> IsValid                         : True</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2914</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Fri, 09 Mar 2012 18:57:35 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2914</guid> <description>Change your authentication method to NTLM and try again to connect to OA from an Outlook client on the internal network.&lt;blockquote&gt;set-outlookanywhere -identity &quot;myexchange\Rpc (Default Web Site)&quot; -clientauthenticationmethod ntlm [enter]</description> <content:encoded><![CDATA[<p>Change your authentication method to NTLM and try again to connect to OA from an Outlook client on the internal network.</p><blockquote><p>set-outlookanywhere -identity &#8220;myexchange\Rpc (Default Web Site)&#8221; -clientauthenticationmethod ntlm [enter]</p></blockquote> ]]></content:encoded> </item> <item><title>By: Andrew</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2913</link> <dc:creator>Andrew</dc:creator> <pubDate>Fri, 09 Mar 2012 18:56:44 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2913</guid> <description>When I set my deny rule to redirect traffic from webmail.mydomain.com to https://myexchange.mydomain.local/owa,, it redirects me without issue internally.</description> <content:encoded><![CDATA[<p>When I set my deny rule to redirect traffic from webmail.mydomain.com to <a
href="https://myexchange.mydomain.local/owa" rel="nofollow">https://myexchange.mydomain.local/owa</a>,, it redirects me without issue internally.</p> ]]></content:encoded> </item> <item><title>By: Andrew</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2912</link> <dc:creator>Andrew</dc:creator> <pubDate>Fri, 09 Mar 2012 18:41:27 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2912</guid> <description>[PS] C:\Windows\system32&gt;Get-OutlookAnywhere &#124;flRunspaceId                      : 9d9211d3-8e96-4bc4-bd5b-a3a833b57b2b
ServerName                      : MYEXCHANGE
SSLOffloading                   : False
ExternalHostname                : webmail.mydomain.com
ClientAuthenticationMethod      : Basic
IISAuthenticationMethods        : {Basic}
XropUrl                         :
MetabasePath                    : IIS://myexchange.mydomain.local/W3SVC/1/ROOT/Rpc
Path                            : C:\Windows\System32\RpcProxy
ExtendedProtectionTokenChecking : None
ExtendedProtectionFlags         : {}
ExtendedProtectionSPNList       : {}
Server                          : myexchange
AdminDisplayName                :
ExchangeVersion                 : 0.10 (14.0.100.0)
Name                            : Rpc (Default Web Site)
DistinguishedName               : CN=Rpc (Default Web Site),CN=HTTP,CN=Protocols,CN=MPSOLIVE,CN=Servers,CN=Exchange Adm
inistrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Meritus,CN=Microsoft
Exchange,CN=Services,CN=Configuration,DC=meritus,DC=local
Identity                        : myexchange\Rpc (Default Web Site)
Guid                            : c1b2a926-6baf-40e1-8982-5e3d85f4fdd7
ObjectCategory                  : mydomain.local/Configuration/Schema/ms-Exch-Rpc-Http-Virtual-Directory
ObjectClass                     : {top, msExchVirtualDirectory, msExchRpcHttpVirtualDirectory}
WhenChanged                     : 3/8/2012 2:50:15 PM
WhenCreated                     : 3/8/2012 2:50:00 PM
WhenChangedUTC                  : 3/8/2012 10:50:15 PM
WhenCreatedUTC                  : 3/8/2012 10:50:00 PM
OrganizationId                  :
OriginatingServer               : MyDC2.meritus.local
IsValid                         : True</description> <content:encoded><![CDATA[<p>[PS] C:\Windows\system32&gt;Get-OutlookAnywhere |fl</p><p>RunspaceId                      : 9d9211d3-8e96-4bc4-bd5b-a3a833b57b2b<br
/> ServerName                      : MYEXCHANGE<br
/> SSLOffloading                   : False<br
/> ExternalHostname                : webmail.mydomain.com<br
/> ClientAuthenticationMethod      : Basic<br
/> IISAuthenticationMethods        : {Basic}<br
/> XropUrl                         :<br
/> MetabasePath                    : IIS://myexchange.mydomain.local/W3SVC/1/ROOT/Rpc<br
/> Path                            : C:\Windows\System32\RpcProxy<br
/> ExtendedProtectionTokenChecking : None<br
/> ExtendedProtectionFlags         : {}<br
/> ExtendedProtectionSPNList       : {}<br
/> Server                          : myexchange<br
/> AdminDisplayName                :<br
/> ExchangeVersion                 : 0.10 (14.0.100.0)<br
/> Name                            : Rpc (Default Web Site)<br
/> DistinguishedName               : CN=Rpc (Default Web Site),CN=HTTP,CN=Protocols,CN=MPSOLIVE,CN=Servers,CN=Exchange Adm<br
/> inistrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Meritus,CN=Microsoft<br
/> Exchange,CN=Services,CN=Configuration,DC=meritus,DC=local<br
/> Identity                        : myexchange\Rpc (Default Web Site)<br
/> Guid                            : c1b2a926-6baf-40e1-8982-5e3d85f4fdd7<br
/> ObjectCategory                  : mydomain.local/Configuration/Schema/ms-Exch-Rpc-Http-Virtual-Directory<br
/> ObjectClass                     : {top, msExchVirtualDirectory, msExchRpcHttpVirtualDirectory}<br
/> WhenChanged                     : 3/8/2012 2:50:15 PM<br
/> WhenCreated                     : 3/8/2012 2:50:00 PM<br
/> WhenChangedUTC                  : 3/8/2012 10:50:15 PM<br
/> WhenCreatedUTC                  : 3/8/2012 10:50:00 PM<br
/> OrganizationId                  :<br
/> OriginatingServer               : MyDC2.meritus.local<br
/> IsValid                         : True</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2911</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Fri, 09 Mar 2012 18:32:03 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2911</guid> <description>What happens if you set the redirect in your deny rule to explicitly be the  https://URL:8443/owa that works directly?</description> <content:encoded><![CDATA[<p>What happens if you set the redirect in your deny rule to explicitly be the <a
href="https://URL:8443/owa" rel="nofollow">https://URL:8443/owa</a> that works directly?</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2910</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Fri, 09 Mar 2012 18:29:03 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2910</guid> <description>If OA doesn&#039;t work internally, forget about ever getting it to work through TMG until you get it working internally.
On your CAS server open an Exchange Management Shell, and reply with the contents of this command.&lt;blockquote&gt;get-outlookanywhere &#124; fl [enter]&lt;/blockquote&gt;Ed</description> <content:encoded><![CDATA[<p>If OA doesn&#8217;t work internally, forget about ever getting it to work through TMG until you get it working internally.<br
/> On your CAS server open an Exchange Management Shell, and reply with the contents of this command.</p><blockquote><p>get-outlookanywhere | fl [enter]</p></blockquote><p>Ed</p> ]]></content:encoded> </item> <item><title>By: Andrew</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2909</link> <dc:creator>Andrew</dc:creator> <pubDate>Fri, 09 Mar 2012 17:17:50 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2909</guid> <description>1.  ExRCA Outlook Anywhere Test Results
Testing RPC/HTTP connectivity.
The RPC/HTTP test failed.Testing HTTP Authentication Methods for URL https://webmail.mydomain.com/rpc/rpcproxy.dll.
The HTTP authentication test failed.
Additional Details
An HTTP 403 error was received because ISA Server denied the specified URL.2.  Denied Connection MyTMG2010 3/9/2012 9:11:34 AM
Log type: Web Proxy (Reverse)
Status: 12202 Forefront TMG denied the specified Uniform Resource Locator (URL).
Rule: Default rule
Source: Internal (192.168.42.190:55543)
Destination: Local Host (192.168.80.150:443)
Request: RPC_OUT_DATA http://webmail.mydomain.com/rpc/rpcproxy.dll?MyExchange.meritus.local:6004
Filter information: Req ID: 0ebc05ed; Compression: client=No, server=No, compress rate=0% decompress rate=0%
Protocol: https
User: anonymous
Additional information
Client agent: MSRPC
Object source: (No source information is available.)
Cache info: 0x8 (Request includes the AUTHORIZATION header.)
Processing time: 1 MIME type:3.  No, OA does not work internally or externally at the moment.  I can get it Outlook to connect internally if I manually configure the settings Exchange Proxy Settings</description> <content:encoded><![CDATA[<p>1.  ExRCA Outlook Anywhere Test Results<br
/> Testing RPC/HTTP connectivity.<br
/> The RPC/HTTP test failed.</p><p> Testing HTTP Authentication Methods for URL <a
href="https://webmail.mydomain.com/rpc/rpcproxy.dll" rel="nofollow">https://webmail.mydomain.com/rpc/rpcproxy.dll</a>.<br
/> The HTTP authentication test failed.</p><p> Additional Details<br
/> An HTTP 403 error was received because ISA Server denied the specified URL.</p><p>2.  Denied Connection MyTMG2010 3/9/2012 9:11:34 AM<br
/> Log type: Web Proxy (Reverse)<br
/> Status: 12202 Forefront TMG denied the specified Uniform Resource Locator (URL).<br
/> Rule: Default rule<br
/> Source: Internal (192.168.42.190:55543)<br
/> Destination: Local Host (192.168.80.150:443)<br
/> Request: RPC_OUT_DATA <a
href="http://webmail.mydomain.com/rpc/rpcproxy.dll?MyExchange.meritus.local:6004" rel="nofollow">http://webmail.mydomain.com/rpc/rpcproxy.dll?MyExchange.meritus.local:6004</a><br
/> Filter information: Req ID: 0ebc05ed; Compression: client=No, server=No, compress rate=0% decompress rate=0%<br
/> Protocol: https<br
/> User: anonymous<br
/> Additional information<br
/> Client agent: MSRPC<br
/> Object source: (No source information is available.)<br
/> Cache info: 0&#215;8 (Request includes the AUTHORIZATION header.)<br
/> Processing time: 1 MIME type:</p><p>3.  No, OA does not work internally or externally at the moment.  I can get it Outlook to connect internally if I manually configure the settings Exchange Proxy Settings</p> ]]></content:encoded> </item> <item><title>By: Jan</title><link>http://retrohack.com/how-to-publish-owa-through-tmg/comment-page-1/#comment-2908</link> <dc:creator>Jan</dc:creator> <pubDate>Fri, 09 Mar 2012 15:17:47 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtopublish-owa-through-tmg/#comment-2908</guid> <description>Hi Ed,Thanks for your response.I&#039;m fully aware of the problems with a none standard port. This situation is only temporary and only during the migration from Exch 2007 to Exch 2010. As in our environment there are many users that use mobile phone (active)sync and we do not want to interfere with that setup until we are ready to migrate those users to Exch 2010.
On the default port 443 the Exch 2007 OWA is still active.In TMG I see Allow connection, but looks like it is stuck in a loop between both the Publishing rules.
Initiated Connection TMG 3/9/2012 4:04:41 PM
Log type: Firewall service
Status: The operation completed successfully.
Source: External (81.243.62.97:56372)
Destination: Local Host (xx.xx.xx.xx:8443)
Protocol: HTTPS - 8443
Additional information
Number of bytes sent: 0 Number of bytes received: 0
Processing time: 0ms Original Client IP: 81.243.62.97Initiated Connection TMG 3/9/2012 4:04:41 PM
Log type: Firewall service
Status: The operation completed successfully.
Source: External (81.243.62.97:56373)
Destination: Local Host (xx.xx.xx.xx:8443)
Protocol: HTTPS - 8443
Additional information
Number of bytes sent: 0 Number of bytes received: 0
Processing time: 0ms Original Client IP: 81.243.62.97Denied Connection TMG 3/9/2012 4:04:41 PM
Log type: Firewall service
Status: A non-SYN packet was dropped because it was sent by a source that does not have an established connection with the Forefront TMG computer.
Rule: None - see Result Code
Source: External (81.243.62.97:56319)
Destination: Local Host (xx.xx.xx.xx:8443)
Protocol: HTTPS - 8443
Additional information
Number of bytes sent: 0 Number of bytes received: 0
Processing time: 0ms Original Client IP: 81.243.62.97Closed Connection TMG 3/9/2012 4:05:49 PM
Log type: Firewall service
Status: A connection was gracefully closed in an orderly shutdown process with a three-way FIN-initiated handshake.
Source: External (81.243.62.97:56373)
Destination: Local Host (xx.xx.xx.xx:8443)
Protocol: HTTPS - 8443
Additional information
Number of bytes sent: 92 Number of bytes received: 52
Processing time: 68000ms Original Client IP: 81.243.62.97</description> <content:encoded><![CDATA[<p>Hi Ed,</p><p>Thanks for your response.</p><p>I&#8217;m fully aware of the problems with a none standard port. This situation is only temporary and only during the migration from Exch 2007 to Exch 2010. As in our environment there are many users that use mobile phone (active)sync and we do not want to interfere with that setup until we are ready to migrate those users to Exch 2010.<br
/> On the default port 443 the Exch 2007 OWA is still active.</p><p>In TMG I see Allow connection, but looks like it is stuck in a loop between both the Publishing rules.</p><p>Initiated Connection TMG 3/9/2012 4:04:41 PM<br
/> Log type: Firewall service<br
/> Status: The operation completed successfully.<br
/> Source: External (81.243.62.97:56372)<br
/> Destination: Local Host (xx.xx.xx.xx:8443)<br
/> Protocol: HTTPS &#8211; 8443<br
/> Additional information<br
/> Number of bytes sent: 0 Number of bytes received: 0<br
/> Processing time: 0ms Original Client IP: 81.243.62.97</p><p>Initiated Connection TMG 3/9/2012 4:04:41 PM<br
/> Log type: Firewall service<br
/> Status: The operation completed successfully.<br
/> Source: External (81.243.62.97:56373)<br
/> Destination: Local Host (xx.xx.xx.xx:8443)<br
/> Protocol: HTTPS &#8211; 8443<br
/> Additional information<br
/> Number of bytes sent: 0 Number of bytes received: 0<br
/> Processing time: 0ms Original Client IP: 81.243.62.97</p><p>Denied Connection TMG 3/9/2012 4:04:41 PM<br
/> Log type: Firewall service<br
/> Status: A non-SYN packet was dropped because it was sent by a source that does not have an established connection with the Forefront TMG computer.<br
/> Rule: None &#8211; see Result Code<br
/> Source: External (81.243.62.97:56319)<br
/> Destination: Local Host (xx.xx.xx.xx:8443)<br
/> Protocol: HTTPS &#8211; 8443<br
/> Additional information<br
/> Number of bytes sent: 0 Number of bytes received: 0<br
/> Processing time: 0ms Original Client IP: 81.243.62.97</p><p>Closed Connection TMG 3/9/2012 4:05:49 PM<br
/> Log type: Firewall service<br
/> Status: A connection was gracefully closed in an orderly shutdown process with a three-way FIN-initiated handshake.<br
/> Source: External (81.243.62.97:56373)<br
/> Destination: Local Host (xx.xx.xx.xx:8443)<br
/> Protocol: HTTPS &#8211; 8443<br
/> Additional information<br
/> Number of bytes sent: 92 Number of bytes received: 52<br
/> Processing time: 68000ms Original Client IP: 81.243.62.97</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Served from: retrohack.com @ 2012-05-18 11:58:22 by W3 Total Cache -->
