• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

403 forbieen (12202) after logon OWA

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 General ] >> Exchange Publishing >> 403 forbieen (12202) after logon OWA Page: [1]
Login
Message << Older Topic   Newer Topic >>
403 forbieen (12202) after logon OWA - 14.May2009 9:52:03 AM   
yesname

 

Posts: 11
Joined: 14.May2009
Status: offline
My scenario: ISA Server and Exchange Server. Two certificates generated with our CA. Both generated with public FQDN Common Name mail.isasucks.com. One for Internal OWA Access and one for External OWA Access. From internal OWA works because of the split DNS, but from external I get a 403 forbidden error (12202) after OWA logon screen.
Form based authentication is disabled on Exchange Server.

ISA Monitoring shows first:

Log type: Web Proxy (Reverse)
Status: 12210 An Internet Server API (ISAPI) filter has finished handling the request. Contact your system administrator.
Rule:
Source: ( 10.10.0.10:0)
Destination: ( 10.10.0.10:443)
Request: POST http://mail.isasucks.com/CookieAuth.dll?Logon
Filter information: Req ID: 086b2bc2
Protocol: https
User: anonymous

then second:

Log type: Web Proxy (Reverse)
Status: 12202 The ISA Server denied the specified Uniform Resource Locator (URL).
Rule: Default rule
Source: Branch Office ( 10.10.30.100:0)
Destination: ( 10.10.10.100:443)
Request: GET http://mail.isasucks.com/
Filter information: Req ID: 086b2bc4
Protocol: https
User: isasucks.local\kambu

ISABPA show this error both certification (Internal and External):

The name of the certificate attached to the External OWA Access Web publishing rule does not match the public name. The certificate was issued to mail.isasucks.com, and the set of public names is Not Found.

I have googled all net, tried all step-by-step guide and "solution" but none helped. Please give me a real solution. Thank You!

< Message edited by yesname -- 14.May2009 11:22:58 AM >
Post #: 1
RE: 403 forbieen (12202) after logon OWA - 14.May2009 10:06:05 AM   
SteveMoffat

 

Posts: 1130
Joined: 29.Jun.2001
From: Hamilton, Bermuda
Status: offline
webmail.crewprint.hu is not http://mail.isasucks.com/

They have to be the same ....ie if the cert is for http://mail.isasucks.com/  then so must the external fqdn

_____________________________

Thanks
Steve

ISA 2006 Book! - http://tinyurl.com/2gpoo8
TMG Bible - http://tinyurl.com/ykv85hr
www.isaserver.bm

The built in ISA help is likely the most comprehensive help built into an application anywhere. USE it!!! Search it!!! RTFM

(in reply to yesname)
Post #: 2
RE: 403 forbieen (12202) after logon OWA - 14.May2009 11:19:02 AM   
yesname

 

Posts: 11
Joined: 14.May2009
Status: offline
Sorry, I forgot to rewrite it to mail.isasucks.com. :)
Of course they are same. Please rewrite your reply too. Tnx! :)

(in reply to SteveMoffat)
Post #: 3
RE: 403 forbieen (12202) after logon OWA - 14.May2009 11:50:19 AM   
SteveMoffat

 

Posts: 1130
Joined: 29.Jun.2001
From: Hamilton, Bermuda
Status: offline
Then why does ISABPA return the error.

"The name of the certificate attached to the External OWA Access Web publishing rule does not match the public name. The certificate was issued to mail.isasucks.com, and the set of public names is Not Found. "

_____________________________

Thanks
Steve

ISA 2006 Book! - http://tinyurl.com/2gpoo8
TMG Bible - http://tinyurl.com/ykv85hr
www.isaserver.bm

The built in ISA help is likely the most comprehensive help built into an application anywhere. USE it!!! Search it!!! RTFM

(in reply to yesname)
Post #: 4
RE: 403 forbieen (12202) after logon OWA - 14.May2009 12:17:52 PM   
yesname

 

Posts: 11
Joined: 14.May2009
Status: offline
That is what I would like to know...

Both certificate (internal and external) issued to mail.isasucks.com and CNs are the same. Public (external) FQDN the same. On the Public Name tab of Web publishing rule the name is the same again.
And it does not work. I tried to issue new certifications, reconfiguring rules and all things. Tried so much step-by-step guide and everytime I get this error.

(in reply to SteveMoffat)
Post #: 5
RE: 403 forbieen (12202) after logon OWA - 14.May2009 1:06:37 PM   
SteveMoffat

 

Posts: 1130
Joined: 29.Jun.2001
From: Hamilton, Bermuda
Status: offline
But your external fqdn is webmail.crewprint.hu.....not http://mail.isasucks.com/

So the cert should be in the common name of webmail.crewprint.hu

On both ISA & exchange

_____________________________

Thanks
Steve

ISA 2006 Book! - http://tinyurl.com/2gpoo8
TMG Bible - http://tinyurl.com/ykv85hr
www.isaserver.bm

The built in ISA help is likely the most comprehensive help built into an application anywhere. USE it!!! Search it!!! RTFM

(in reply to yesname)
Post #: 6
RE: 403 forbieen (12202) after logon OWA - 14.May2009 2:17:06 PM   
yesname

 

Posts: 11
Joined: 14.May2009
Status: offline
Please read again my post No. 3 and please forgot that FQDN. As i said I forgot to rewrite that FQDN to mail.isasucks.com <- not the real. Please edit your comments and delete that domain. Thanks!

(in reply to SteveMoffat)
Post #: 7
RE: 403 forbieen (12202) after logon OWA - 14.May2009 3:52:49 PM   
SteveMoffat

 

Posts: 1130
Joined: 29.Jun.2001
From: Hamilton, Bermuda
Status: offline
http://mail.isasucks.com does not exist.

_____________________________

Thanks
Steve

ISA 2006 Book! - http://tinyurl.com/2gpoo8
TMG Bible - http://tinyurl.com/ykv85hr
www.isaserver.bm

The built in ISA help is likely the most comprehensive help built into an application anywhere. USE it!!! Search it!!! RTFM

(in reply to yesname)
Post #: 8
RE: 403 forbieen (12202) after logon OWA - 14.May2009 4:13:51 PM   
yesname

 

Posts: 11
Joined: 14.May2009
Status: offline
Yes I know, as I said this is not real. Now I found the source of my problem. Mybe the link translation or something.
Internal network I can access with mail.isasucks.com, but from external works only with mail.isasucks.com/exchange!
Why?

(in reply to SteveMoffat)
Post #: 9
RE: 403 forbieen (12202) after logon OWA - 14.May2009 5:01:45 PM   
yesname

 

Posts: 11
Joined: 14.May2009
Status: offline
Found the solution. Because it is worked with only the https://mail.isasucks.com from internal network I did not try the https://mail.isasucks.com/exchange from external network.
Now I tried it and it worked. I forgot to set the path to /* only and set the link translation to work with https://mail.isasucks.com from external networks. Now changed mail.isasucks.com to mail.ISuck.com :)

< Message edited by yesname -- 15.May2009 1:58:47 AM >

(in reply to yesname)
Post #: 10
RE: 403 forbieen (12202) after logon OWA - 14.May2009 5:18:31 PM   
SteveMoffat

 

Posts: 1130
Joined: 29.Jun.2001
From: Hamilton, Bermuda
Status: offline
Your pub rule shouldn't be */

_____________________________

Thanks
Steve

ISA 2006 Book! - http://tinyurl.com/2gpoo8
TMG Bible - http://tinyurl.com/ykv85hr
www.isaserver.bm

The built in ISA help is likely the most comprehensive help built into an application anywhere. USE it!!! Search it!!! RTFM

(in reply to yesname)
Post #: 11
RE: 403 forbieen (12202) after logon OWA - 15.May2009 2:01:44 AM   
yesname

 

Posts: 11
Joined: 14.May2009
Status: offline
I have removed all path and set only one: /* to /exchange/*, and set link translation: http://mail.isasucks.com to https://mail.isasucks.com/exchange. With these settings it works fine from both internal and external.

(in reply to SteveMoffat)
Post #: 12

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 General ] >> Exchange Publishing >> 403 forbieen (12202) after logon OWA Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts