Posts: 433
Joined: 18.Jul.2005
From: USA
Status: offline
quote:
some reason my access is getting denied. How should I trouble shoot? I am using
I did a test for LDAP communication between ISA and DC and it worked. So, I dont think there is communnication errror but when I try to create a OWA users group and add users to that group from AD using LDAP it gives me error Specified user not found.
when I try to hit https://owa.bhavin.us/exchange in the error logs it say trying to connect from Ext to Localhost HTTPS denied.
Posts: 433
Joined: 18.Jul.2005
From: USA
Status: offline
Tom, I have my production server on domain but I would like to try LDAP in my LAB Network.
What else can I check to find out what 's wrong? I tried LDP.exe from ISA to DC and it worked fine. I was able to make connection. I also have LDAP port open from local host to DC.
Posts: 433
Joined: 18.Jul.2005
From: USA
Status: offline
Now I am able to make ldap work and I added groups from AD to allow OWA to group of users ,but when I try to loginto OWA it fails. In the log I can see external host is trying to connect to localhost instead of exchange server. http://www.bhavin.us/doc1.htm
Posts: 433
Joined: 18.Jul.2005
From: USA
Status: offline
Hi Tom, Finally I got it working. I restarted from scratch and I think I missed to copy cert to Trusted CA and did not disable FBA authentication on Exchage server.
Now the only problem is how do I configure ISA so that user dont have to enter domain name?
Only Basic authentication works without a domain name, and in that case, you need to configure the default domain on the Web listener and the Exchange Server.
Posts: 433
Joined: 18.Jul.2005
From: USA
Status: offline
I have configured default domain on exchange server and I configured default domain on web listner Under Authentication/ Advance / Default name and it is working. Thanks
other question is when I try to launch OWA using https://owa.bhavin.us it takes me to ISA Server OWA page, When I try https://owa.bhavin.us/exchange it takes me to MS Office outlook OWA page. what it the reason,if I have to customize the OWA page I have to work on two different pages.
< Message edited by bhavin78 -- 17.Jun.2008 9:30:17 AM >
Posts: 433
Joined: 18.Jul.2005
From: USA
Status: offline
According to your article, I need to remove Authenticated Users from OWA Redirect Policy but I get error when I try to do that (Weblistner selected for this rule requires authentication). I did not remove Authenticated Users but, I added All users and now it's working fine for both below URL.
Posts: 433
Joined: 18.Jul.2005
From: USA
Status: offline
How do I, Create a split DNS entry on your internal DNS server to map owa.bhavin.us to the internal interface of the ISA Firewall? Do I have to create Forward lookup zone name bhavin.us and create entry which points to internal NIC of ISA?
Posts: 433
Joined: 18.Jul.2005
From: USA
Status: offline
quote:
ORIGINAL: tshinder
Very good.
You'll need to do two things to support the internal users.
1. Create a split DNS entry on your internal DNS server to map owa.bhavin.us to the internal interface of the ISA Firewall
2. Configure the Web Listener on the rule to listen on the Internal interface IP address
HTH, Tom
I have three weblistner (one for OWA, Website and Sharepoint). Each weblistner has uniqure Exp IP. Only only have one IP configured for Internal NIC, now how can I make this work? only one listner can user my internal IP, what is the work around?