• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

owa page not loading from vpn network

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Publishing] >> Exchange Publishing >> owa page not loading from vpn network Page: [1]
Login
Message << Older Topic   Newer Topic >>
owa page not loading from vpn network - 21.Apr.2009 10:50:13 AM   
smariaraj

 

Posts: 34
Joined: 4.Apr.2009
Status: offline
I have strange problem here, We are using windows 2003 / Exchange 2007/ ISA 2006 with latest patches.

We have total 4 exchange servers 0wa/owa2/owa3/owa4 for four data centers

We have published owa on isa 2006 and it is working fine from outside as well as internally within one data center owa4

It is also working fine from remote site which is different from Head office network/domain. It is connected thru l2tp vpn thru isa

My problem is that it is not working from other data center location which is part of one domain connected thru l2tp vpn thru isa. other data centers owa/owa2/owa3 are not able to access owa4 using owa4 address.But other data center and interconnection are working also owa4 is able to access other owa sites.
country server connected to owa4 network thru l2tp vpn and part of same domain are not able to access owa4. ISA log does not block anything, it is simply giving closed connection. Site is not part of domain but same l2tp vpn is working

Am i missing somthing , please help

SM
Post #: 1
RE: owa page not loading from vpn network - 21.Apr.2009 3:53:56 PM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
Do you see anything in alerts? Are there any alerts for network overlaps?

_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to smariaraj)
Post #: 2
RE: owa page not loading from vpn network - 22.Apr.2009 1:53:31 AM   
smariaraj

 

Posts: 34
Joined: 4.Apr.2009
Status: offline
Thanks for your response.

No we can not see any alerts regarding network overlaps.

It is working fine on following scenarios.

Ourdomain : Testdomain

1) Within internal network of owa4 : Domain Testdomain
2) Externally but outside testdomain network, it can be standalone machine or anyother domain network

It is not working from other network of owa3/owa2/owa. All have common domain testdomain

Smariaraj

(in reply to inderjeet)
Post #: 3
RE: owa page not loading from vpn network - 22.Apr.2009 9:26:31 AM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
Do you see the traffic from those machines hitting the ISA server? What comes in the Logs? Do you see that traffic getting denied?

_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to smariaraj)
Post #: 4
RE: owa page not loading from vpn network - 22.Apr.2009 11:27:16 AM   
smariaraj

 

Posts: 34
Joined: 4.Apr.2009
Status: offline
I can not see any denied connection on logs. I can see initiated connection entries and closed connection entries for the same client ips. So i am not able to figure out what is causing problem.

Thanks

(in reply to inderjeet)
Post #: 5
RE: owa page not loading from vpn network - 22.Apr.2009 11:33:04 AM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
We would need logs to analyze the traffic. Install Network Monitor 3.2 before running this tool on ISA server.

Run the below tool and then test the OWA from a client machine in OWA4 site. Then stop this tool.


ISA BPA can be downloaded and installed from the following location:
http://www.microsoft.com/downloads/details.aspx?FamilyID=d22ec2b9-4cd3-4bb6-91ec-0829e5f84063&DisplayLang=en

After installing this please run the ISA Data Packager from the Start, Programs, ISA Server, ISA Tools menu Select the 'Collect data from one of the following repro scenarios' radio button and select the 'Basic Repro and Static Configuration' option, select 'Next' and then 'Start Data Collection'.

When the ISA Data Packager has initialized the various data captures you will be asked to press the Spacebar to start capturing data. This is going to capture a number of data outputs from a repro of the issue (Network traces, ISA tracing output, ISA logs) so before running this and pressing the spacebar please get set-up to repro the issue.

When you are ready to repro the issue press the spacebar, repro the issue and then press the spacebar again to stop the captures. If you can try to keep this the time you are capturing quite short that will help our analysis of the data.
The BPA will also gather config data from the ISA server that will help us understand your set-up and will output all the data captures to a file on the desktop called isapackage.cab.

Send that to me at isaissues@yahoo.com

Also, send me the client IPs, server IPs and the time you Ran the ISABPA. If you are comfortable sending that Info...

< Message edited by inderjeet -- 22.Apr.2009 11:35:02 AM >


_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to smariaraj)
Post #: 6
RE: owa page not loading from vpn network - 23.Apr.2009 1:49:17 AM   
smariaraj

 

Posts: 34
Joined: 4.Apr.2009
Status: offline
Do you want me to install both network monitoring tool 3.2 and ISA BPA on ISA server. I'll send you the capture asap.

Also one more thing i noticed. From owa/owa2/owa3 sites we are not able to load owa4 from the client computers, however we are able to load owa4 from isa server of owa/owa2/owa3 sites. The only difference is DNS. ISA server is using public DNS and Client computer is using internal DNS.

smariaraj

(in reply to inderjeet)
Post #: 7
RE: owa page not loading from vpn network - 23.Apr.2009 8:44:45 AM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
Yes, install both

If i understood correctly then your Datacenters are interconnected using L2TP Site-to-site VPN using ISA. If that's the scenario then the users should be able to access the resources usign their internal DNS names. Considering, your DNS Infrastruture is setup properly.

Do you want users to open OWA using the public name or the private name? How are your clients configured?

If they are configured as SecureNAT (gateway as their respective ISA's IP) then your local DNS should resolve names for them. Your local DNS should be able to forward requests to the ISP DNS. If your using FWC or Web proxy clients (IE set to direct requests to ISA) then you will need ISA to resolve it.

Since your ISA is able to resolve the OWA4 address being on public network, Try configuring your test client machine at OWA/OWA2/OWA3 sites as web proxy client

Moreover, send me the logs if that doesn't work


_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to smariaraj)
Post #: 8
RE: owa page not loading from vpn network - 25.Apr.2009 7:26:46 AM   
smariaraj

 

Posts: 34
Joined: 4.Apr.2009
Status: offline
Yes you are right. It is connected thru l2tp vpn. We are able to load using internal server name. It is working fine. however we have configured outlook anywhere with owa4.test.com

We have situation where one data center visitor visiting other data center, so he needs to use owa4 with public name. we have current workaround to use internal name, but outlook anywhere may not work with owa4.

Yes we are using ISA server  as gateway. With/without DNS forwarder we still face the issue, we are able to resolve the dns name to local from the client and to public from ISA server.

How do i use owa/owa2 /owa3 as webproxy client, I am not clear with this point

smariaraj

(in reply to inderjeet)
Post #: 9
RE: owa page not loading from vpn network - 26.Apr.2009 1:30:54 AM   
smariaraj

 

Posts: 34
Joined: 4.Apr.2009
Status: offline
Also one more observation.

Eg. Khobar owa4 is connected Bahrain country server. Bahrain users are connecting to owa4 from khobar thru l2tp vpn. all conections are working except owa4 webpage. It is working with active sync, Outlook anywhere.but owa4 webpage is not loading. It is giving DNS error

Khobar ISA log is showing denied connection with blank rule for https . I saw your posting on curstom http filter. can you elaporate this point please

smariaraj

(in reply to inderjeet)
Post #: 10
RE: owa page not loading from vpn network - 27.Apr.2009 8:46:36 AM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
Ah, i dint realize that you posted the same entry under different catagory as well. I said custom HTTP because there you were not clera if your were accessing the OWA4 webpage internally or externally.... It is seen a bug in ISA when you have a web proxy filer enabled on HTTP then you aren't able to open HTTP/HTTPs webpages over Site-to-Site VPN. For making it work the recommended best practice is to remove the web proxy filter by making a new protocol... If that question is in reference to the same issue then forget it, it's not applicable to your problem, because you are accessing it public not over Site-to Site VPN

Did you generate the logs which i mentioned? Are you able to open OWA4 from internet, i mean not sitting in any other data center but somewhere outside like your home or cafe? When sitting in other Datacenters what IP are you able to resolve the OWA4 website?

_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to smariaraj)
Post #: 11
RE: owa page not loading from vpn network - 28.Apr.2009 7:30:02 AM   
smariaraj

 

Posts: 34
Joined: 4.Apr.2009
Status: offline
Yes owa4 is  working from outside. eg home or internet cafe.

OWA4 Working environment

Inside abcgroup.local(domain) network

L2tp VPN connected to other site network .Eg. domain - sakfs.local

Externally using any internet connection

active sync is working with owa4 on any setup

outlookanywhere is also working

OWA4 not working environement

l2tp VPN connected to other country /data center to same domain as abcgroup.local
Note : i'll generate the log today or tmrw and send it , i was waiting for Group IT manage approval,

(in reply to inderjeet)
Post #: 12
RE: owa page not loading from vpn network - 28.Apr.2009 7:44:21 AM   
smariaraj

 

Posts: 34
Joined: 4.Apr.2009
Status: offline
From other data center client we are able to resolve internal ip of owa4 which is isa server. and from isa server it is resolving to external ip of owa4 or  isa server

smariaraj

(in reply to inderjeet)
Post #: 13
RE: owa page not loading from vpn network - 28.Apr.2009 9:31:54 AM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
quote:

From other data center client we are able to resolve internal ip of owa4 which is isa server. and from isa server it is resolving to external ip of owa4 or  isa server


Sorry but i couldn't understand this. Can you be more specific? What IPs do you get for OWA/OWA2/OWA3 from OWA4 site when you try to resolve?

_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to smariaraj)
Post #: 14
RE: owa page not loading from vpn network - 28.Apr.2009 10:22:26 AM   
smariaraj

 

Posts: 34
Joined: 4.Apr.2009
Status: offline
When we try from client machine it  resolves to local ip of  respecitve isa server, when we try from isa server it resolves to public ip of isa server. as ISA external uses ISP dns.

Eg. owa4

ISA ext - 212.10.170.39 - same public ip is registered from owa4
ISA int : 192.161.32.127           

smariaraj

(in reply to inderjeet)
Post #: 15
RE: owa page not loading from vpn network - 28.Apr.2009 10:48:27 AM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
Have you published the OWA4 for internally as well through ISA? Should the users go to OWA4 internally?

OWA should be internally resolved to the OWA4 server and not to the internal IP of the ISA Server if you are not using the ISA publishing internally....



_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to smariaraj)
Post #: 16
RE: owa page not loading from vpn network - 30.Apr.2009 6:41:37 AM   
smariaraj

 

Posts: 34
Joined: 4.Apr.2009
Status: offline
Our internal DNS is resolving to internal ip of ISA for OWA4, but public dns is resolving to external ip of owa4.

Also exchange listener is configured  for both external and internal.


(in reply to inderjeet)
Post #: 17
RE: owa page not loading from vpn network - 30.Apr.2009 9:54:48 AM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
I can try helping you if i can get Logs

1. Install Network Monitor on the client machine from where you are testing it
2. Install Network Monitor on the concerned ISA Server
3. Install the below ISABPA tool on the ISA
4. Run netmon on client and ISABPA samultaneously when doing the test

ISA BPA can be downloaded and installed from the following location:
http://www.microsoft.com/downloads/details.aspx?FamilyID=d22ec2b9-4cd3-4bb6-91ec-0829e5f84063&DisplayLang=en

After installing this please run the ISA Data Packager from the Start, Programs, ISA Server, ISA Tools menuSelect the ‘Collect data from one of the following repro scenarios’ radio button and select the ‘Basic Repro and Static Configuration’ option, select ‘Next’ and then ‘Start Data Collection’.

When the ISA Data Packager has initialized the various data captures you will be asked to press the Spacebar to start capturing data. This is going to capture a number of data outputs from a repro of the issue (Network traces, ISA tracing output, ISA logs) so before running this and pressing the spacebar please get set-up to repro the issue.

When you are ready to repro the issue press the spacebar, repro the issue and then press the spacebar again to stop the captures. If you can try to keep this the time you are capturing quite short that will help our analysis of the data.

The BPA will also gather config data from the ISA server that will help us understand your set-up and will output all the data captures to a file on the desktop called isapackage.cab.

Send the isapackage.cab file to isaissues@yahoo.com if it's more than 5MB then upload it on megashare.com or rapidshare.com and send me the link



_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to smariaraj)
Post #: 18
RE: owa page not loading from vpn network - 11.May2009 1:55:19 AM   
smariaraj

 

Posts: 34
Joined: 4.Apr.2009
Status: offline
Sorry , i was on holidays.

Actually i am not allowed to install any software on ISA as i need to take too many approval from my corporate due to security reasons, however i can install software on my client machine.

Is there anything we can do with the help of client tool, or if you want i can send isa log file. Does it help?


(in reply to inderjeet)
Post #: 19
RE: owa page not loading from vpn network - 11.May2009 12:28:49 PM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
Install network monitor on client machine and do the test. Then save the logs as .CAP file and send it to me..

_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to smariaraj)
Post #: 20

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Publishing] >> Exchange Publishing >> owa page not loading from vpn network Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts