Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

RPC over HTTP status code 64

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 General ] >> Exchange Publishing >> RPC over HTTP status code 64 Page: [1] 2   next >   >>
Login
Message << Older Topic   Newer Topic >>
RPC over HTTP status code 64 - 5.Apr.2006 2:29:53 PM   
mbassie

 

Posts: 36
Joined: 23.Mar.2005
Status: offline
Hi,

I'm running into problems publishing a single Exchange server using RPC over HTTP.

I followed the setup as described in procedure 8 in http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/exchage2003.mspx and on the internal network, RPC over HTTP works without problems. Outlook.exe /rpcdiag seems to be showing the right connections.

Outside the ISA firewall, 'Referral' appears to be successful (I receive a login box, for the Exchange server, the connection disappears afterwards), but the connection times out trying to make a 'Directory' connection. Using a network monitor, plenty of traffic appears to pass between the Exchange server and the External host. Using the ISA logging feature, I'm seeing a number of Failed Connection Attempts with status code 64 returning from the Exchange server.

The connection is setup as below:
 
                        +------+
                        | ISA  |
Client -> *.tamtam.nl --|Server|-- dft-isa-003.tamtam.nl -> exchange.tamtam.nl
                        |      |
                        +------+
 
The certificates use the names above (external is a wildcard, internal names are issued by our internal CA). I can access OWA and the RPC path from the ISA server without receiving warnings about the SSL certificate. On the internet, exchange.tamtam.nl resolves to the listener used for this publishing rule.

I can imagine one of two things might be happening:
1 - RPC over HTTP is unable to use a wildcard certificate
2 - The netbios name for the exchange server is dft-xch-002 (exchange.tamtam.nl is a CNAME). This name is unavailable to the outside world, but is the one used in normal Outlook profiles.

Any other suggestions for troubleshooting this?

-M

< Message edited by mbassie -- 5.Apr.2006 2:31:13 PM >
Post #: 1
RE: RPC over HTTP status code 64 - 6.Apr.2006 4:43:54 PM   
tshinder

 

Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi M,

What is the configuration of the Web Publishing Rule to publish the RPC/HTTP site?

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to mbassie)
Post #: 2
RE: RPC over HTTP status code 64 - 7.Apr.2006 12:34:04 AM   
Jason Jones

 

Posts: 2140
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
How is the msstd: parameter defined?

Is it configured for msstd:*.tamtam.nl?
 
JJ

_____________________________

Jason Jones (MVP)

Silversands Limited http://www.silversands.co.uk
My Blog: http://blog.msfirewall.org.uk/

Get our NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to tshinder)
Post #: 3
RE: RPC over HTTP status code 64 - 7.Apr.2006 2:32:34 PM   
mbassie

 

Posts: 36
Joined: 23.Mar.2005
Status: offline
Jason: I'm not (yet) using mutual authentication. Setting it to msstd:*.tamtam.nl didn't appear to do anything though.

Tom:

I'll walk through the tabs - that's easiest.







I am noticing that internally, on the same laptop, Directory connections appear to be TCP/IP connections, whereas Mail connections are HTTPS. I'm starting to think that may be the real problem here. Are these Directory sessions supposed to show up as TCP/IP conn's? Did I misconfigure something in the Exchange RPC-HTTP proxy?

-Martin

(in reply to Jason Jones)
Post #: 4
RE: RPC over HTTP status code 64 - 8.Apr.2006 12:33:00 AM   
Jason Jones

 

Posts: 2140
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
The listener should be using basic only and the "forward basic credentials" settings should be enabled under the users tab.

Try following the step-by-steps here: http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/firewall-exchange2003.mspx

JJ

< Message edited by Jason Jones -- 8.Apr.2006 12:34:23 AM >


_____________________________

Jason Jones (MVP)

Silversands Limited http://www.silversands.co.uk
My Blog: http://blog.msfirewall.org.uk/

Get our NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to mbassie)
Post #: 5
RE: RPC over HTTP status code 64 - 8.Apr.2006 4:17:57 PM   
tshinder

 

Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Jason,

And the listener and protocols should support only HTTPS, not HTTP.

Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to Jason Jones)
Post #: 6
RE: RPC over HTTP status code 64 - 10.Apr.2006 1:03:10 PM   
mbassie

 

Posts: 36
Joined: 23.Mar.2005
Status: offline
Added a separate listener for RPC over HTTP, set it to HTTPS, Basic auth, credentials forwarding. I get the login box for the HTTP connection to the exchange server, but the connection still times out. Mutual authentication stops me from authenticating successfully to the web listener.
 
What's odd is that I'm seeing success audits in the DC and Exchange server security event logs for the external machine used to test this setup.
 
 
One thing I can think of is that the Exchange server is only a member server in the domain, and the two GCs don't have the "NSPI interface protocol sequences" key - although I really don't want to add it unless it's absolutely necessary.
 
 
Is there any other logging I could enable for this?

 
-Martin

(in reply to tshinder)
Post #: 7
RE: RPC over HTTP status code 64 - 15.Apr.2006 8:10:51 PM   
tshinder

 

Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Martin,

Do you see any denied connections on the ISA firewall?

Do you see any allowed connections?

thanks!
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to mbassie)
Post #: 8
RE: RPC over HTTP status code 64 - 24.Apr.2006 5:26:58 PM   
mbassie

 

Posts: 36
Joined: 23.Mar.2005
Status: offline
quote:

ORIGINAL: tshinder

Hi Martin,

Do you see any denied connections on the ISA firewall?

Do you see any allowed connections?

thanks!
Tom

Hi,

Meant to get back to this earlier :).

I'm seeing allowed established connections, after which I receive a HTTP status code 64 as a response. I imagine that's somewhat of a problem :D.
The ISA server isn't denying any RPC/HTTP traffic, so the rule -appears- to be setup properly.

-Martin

(in reply to tshinder)
Post #: 9
RE: RPC over HTTP status code 64 - 25.Apr.2006 11:55:56 PM   
tshinder

 

Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Martin,

Have you run the ISA firewall BPA on this machine yet? I might find some problems with your Web publshing rules.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to mbassie)
Post #: 10
RE: RPC over HTTP status code 64 - 3.May2006 2:20:43 PM   
mbassie

 

Posts: 36
Joined: 23.Mar.2005
Status: offline
Re-ran the BPA (you never know, something might pop up :).
 
I get 4 warnings, and 1 'best practices' item
 
Best Practices:
- OWA listening on HTTP port (this is done because it lets me automatically redirect connections to the HTTPS port, instead of simply refusing). It's not the same interface as I reserved for RPC over HTTP.
 
Warnings:
- Connection limit exceeded (this is an expected error for me)
- IP spoofing alert (not expected, but these do occasionally pop up)
- Unsupported compression type in HTTP response (not expected, but not harmful)
- DNS search order is blank (this is the external interface. The machine runs a DNS master for split DNS, but it must use the internal interface to resolve names)
 
 
-Martin
 

(in reply to tshinder)
Post #: 11
RE: RPC over HTTP status code 64 - 4.May2006 8:22:24 PM   
tshinder

 

Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Martin,

Is the ISA firewall resolving the name on the To tab to the actual IP address of the RPC proxy?

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to mbassie)
Post #: 12
RE: RPC over HTTP status code 64 - 5.May2006 9:58:11 AM   
mbassie

 

Posts: 36
Joined: 23.Mar.2005
Status: offline
quote:

ORIGINAL: tshinder

Hi Martin,

Is the ISA firewall resolving the name on the To tab to the actual IP address of the RPC proxy?

Thanks!
Tom

Aye.. It gets the right IP address for the RPC proxy, which runs on our Exchange server. What confuses me is that it returns 'The specified network name is no longer available.'. The machine's netbios name is different from the servicename, though, and I know Exchange is still very fond of using netbios. I just can't really afford to not use service names.

I'm stumped :). Maybe I should rethink the setup.

(in reply to tshinder)
Post #: 13
RE: RPC over HTTP status code 64 - 7.May2006 6:35:58 PM   
tshinder

 

Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Martin,

You didn't show your Users tab. Are you forwarding basic credentials?

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to mbassie)
Post #: 14
RE: RPC over HTTP status code 64 - 8.May2006 3:55:41 PM   
mbassie

 

Posts: 36
Joined: 23.Mar.2005
Status: offline
Hi Tom,


Forwarding basic credentials, also have only basic authentication on the HTTPS listener (no HTTP). From what I can tell, this setup should work. Would it help if I used a completely different name from the Exchange server on the outside?

-Martin

(in reply to tshinder)
Post #: 15
RE: RPC over HTTP status code 64 - 8.May2006 10:38:25 PM   
tshinder

 

Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Martin,

You shouldn't need to change the name of the Exchange Server, not even in the client configuration. If the client is configured to use the correct FQDN to create the RPC proxy, that's all that's required.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to mbassie)
Post #: 16
RE: RPC over HTTP status code 64 - 7.Aug.2006 3:45:47 PM   
kjacobsen

 

Posts: 3
Joined: 22.Jul.2006
Status: offline
I have basically the same setup, it was working until i tried to swap the certificates for the listener (just bought one). Anway, now i get a HTTP error code 64 for the rpc proxy. Weird thing is OWA works.

(in reply to mbassie)
Post #: 17
RE: RPC over HTTP status code 64 - 9.Aug.2006 3:35:34 PM   
tshinder

 

Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi K,

Sounds like a name resolution issue.

Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to kjacobsen)
Post #: 18
RE: RPC over HTTP status code 64 - 1.Sep.2006 6:42:47 AM   
aaronparker

 

Posts: 22
Joined: 31.Jan.2005
From: Australia
Status: offline
I've been troubleshooting this issue myself and have found that connecting to the RPC proxy over HTTP (http://rpc.company.com/rpc/rpcproxy.dll) produces Error Code 64. However, in my case, connecting to the RPC proxy over HTTPS (https://rpc.company.com/rpc/rpcproxy.dll), the web site is not found.

This looks to me that the server is not sending the host header, because the ISA Server can resolve the hostname correctly. Any other machine on the network can connect to the RPC proxy correctly (https://rpc.company.com/rpc/rpcproxy.dll).

_____________________________

http://stealthpuppy.com

(in reply to tshinder)
Post #: 19
RE: RPC over HTTP status code 64 - 1.Sep.2006 1:15:54 PM   
tshinder

 

Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Aaron,

You are using SSL to SSL bridging, aren't you? If not, then implement it NOW.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to aaronparker)
Post #: 20

Page:   [1] 2   next >   >> << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 General ] >> Exchange Publishing >> RPC over HTTP status code 64 Page: [1] 2   next >   >>
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts