Petri IT Knowledgebase Forums
 

Petri.co.il forums Home Forums Start Page Forums Frequently Asked Questions FAQ Member List Members List
Go Back   Petri IT Knowledgebase Forums > Messaging Software > Exchange 2007 / 2010 / 2013
Petri.co.il is happy to award auglan the title of Most Valuable Member !!!
Register Calendar Calendar Search Petri IT Knowledgebase Forums Search Todays Posts Today's Posts Mark Forums Read

Notices

Exchange 2010 Activesync using TMG not working well

Exchange 2010 Activesync using TMG not working well

this thread has 10 replies and has been viewed 6799 times

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 28th June 2010, 15:17
Yaniv Hoobian Yaniv Hoobian is offline
Junior Member
It's not a coincidence
 
 Join Date: Nov 2006
  6 month star 12 month star
 Location: Haifa, ISRAEL
 Posts: 109
 Reputation: Yaniv Hoobian is on a distinguished road (10)
Default Exchange 2010 Activesync using TMG not working well

hi

i have a new deployment that have some problems.

the servers are :

Exchange 2010 on server 2008 R2
the domain controllers are server 2003 STD
the TMG is on server 2008 64bit

the tmg is located in the DMZ an has 1 NIC.
I've setup according to bunch of articles i found, and it's working fine only if I'm not forcing the use of SSL certificate.

when i turn on the "require client certificate" the TMG log shows Allowed connection using my active sync rule, but the HTTP status code is "403 forbidden"

i appreciate any help

almost forgot, the certificate is issued from the CA on the domain controller.
I've tested the connection internally using "exchange ActiveSync MD" tool, and it's working.

thanks
Yaniv

Last edited by Yaniv Hoobian; 28th June 2010 at 15:29..
  #2  
Old 28th June 2010, 16:44
tehcamel's Avatar
tehcamel tehcamel is offline
Moderator
 
 Join Date: Mar 2009
  6 month star 12 month star
 Location: Melbourne
 Posts: 5,033
  Send a message via Skype™ to tehcamel
 Reputation: tehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to all (557)
Default Re: Exchange 2010 Activesync using TMG not working well

tmg works better with two nics.. otherwise you're not necessarily getting the benefit of the firewall
__________________

IT Support for businesses. Australian IT Support
Adept Small Business IT
Passionate about IT Support

Please do show your appreciation to those who assist you by leaving Rep Point
Posting from a BB Playbook - please excuse my typing
  #3  
Old 28th June 2010, 16:55
Yaniv Hoobian Yaniv Hoobian is offline
Junior Member
It's not a coincidence
 
 Join Date: Nov 2006
  6 month star 12 month star
 Location: Haifa, ISRAEL
 Posts: 109
 Reputation: Yaniv Hoobian is on a distinguished road (10)
Default Re: Exchange 2010 Activesync using TMG not working well

i have two other firewalls outside the DMZ.

the only purposes of the TMG is to publish the exchange
  #4  
Old 28th June 2010, 18:47
tehcamel's Avatar
tehcamel tehcamel is offline
Moderator
 
 Join Date: Mar 2009
  6 month star 12 month star
 Location: Melbourne
 Posts: 5,033
  Send a message via Skype™ to tehcamel
 Reputation: tehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to all (557)
Default Re: Exchange 2010 Activesync using TMG not working well

a google search for tmg publish exchange one nic found this as one of the first responses


http://social.technet.microsoft.com/...0-5c8b96e9efe7
__________________

IT Support for businesses. Australian IT Support
Adept Small Business IT
Passionate about IT Support

Please do show your appreciation to those who assist you by leaving Rep Point
Posting from a BB Playbook - please excuse my typing
  #5  
Old 28th June 2010, 21:25
Yaniv Hoobian Yaniv Hoobian is offline
Junior Member
It's not a coincidence
 
 Join Date: Nov 2006
  6 month star 12 month star
 Location: Haifa, ISRAEL
 Posts: 109
 Reputation: Yaniv Hoobian is on a distinguished road (10)
Default Re: Exchange 2010 Activesync using TMG not working well

thanks, but i read it before.
it's something related to the way the TMG act when a certificate is used.
  #6  
Old 28th June 2010, 22:25
tehcamel's Avatar
tehcamel tehcamel is offline
Moderator
 
 Join Date: Mar 2009
  6 month star 12 month star
 Location: Melbourne
 Posts: 5,033
  Send a message via Skype™ to tehcamel
 Reputation: tehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to all (557)
Default Re: Exchange 2010 Activesync using TMG not working well

I'm re-reading your post.

"require client certificate"

To me, it sound likes that option is requiring that the CLIENT Present a certificate to authenticate itself.

The SSL Certificate for the Exchange websites should be bound to the HTTPS listener on the ISA server.
__________________

IT Support for businesses. Australian IT Support
Adept Small Business IT
Passionate about IT Support

Please do show your appreciation to those who assist you by leaving Rep Point
Posting from a BB Playbook - please excuse my typing
  #7  
Old 28th June 2010, 23:35
Yaniv Hoobian Yaniv Hoobian is offline
Junior Member
It's not a coincidence
 
 Join Date: Nov 2006
  6 month star 12 month star
 Location: Haifa, ISRAEL
 Posts: 109
 Reputation: Yaniv Hoobian is on a distinguished road (10)
Default Re: Exchange 2010 Activesync using TMG not working well

done that already.

i searched some more and i think the problem is bigger.
i don't see the exchage virtual directorys in ADSIEDIT.

i wanted to recreate the microsoft-server-activesync virtual directory, but it woulsn't let me reomove it, becuase the dc don't recognize it as existed.
but when i wanted to create it, it says ut is already created.
so i opened the ADSIEDIT based on what i've found here http://www.experts-exchange.com/Soft..._26185316.html

if you can't read it here it is :

"Navigate to the following: CN=Configuration, DC=dommainname, DC=com -> CN=Services -> CN=domainname -> CN=Administrative Groups -> CN=Exchange Administrative Group (FYDIBOHF23SPDLT) -> CN=Servers -> CN=Netbios name of the exchange server -> CN=Protocols -> CN=HTTP
and under HTTP found only OWA"



any ides?
  #8  
Old 29th June 2010, 11:31
Yaniv Hoobian Yaniv Hoobian is offline
Junior Member
It's not a coincidence
 
 Join Date: Nov 2006
  6 month star 12 month star
 Location: Haifa, ISRAEL
 Posts: 109
 Reputation: Yaniv Hoobian is on a distinguished road (10)
Default Re: Exchange 2010 Activesync using TMG not working well

An update

i changed the external ip address to port forward to the exchange server directly.
and i came to the same result.

so the problem is with the exchange or active directory and not the TMG


Yaniv
  #9  
Old 29th June 2010, 13:35
tehcamel's Avatar
tehcamel tehcamel is offline
Moderator
 
 Join Date: Mar 2009
  6 month star 12 month star
 Location: Melbourne
 Posts: 5,033
  Send a message via Skype™ to tehcamel
 Reputation: tehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to alltehcamel is a name known to all (557)
Default Re: Exchange 2010 Activesync using TMG not working well

ok, has it EVER worked as it is supposed to?

If so, what was changed recently. If it worked, and now doesn't, something changed. Vdirs don't just delete themselves.

Have you tried reinstalling the CAS role ?
__________________

IT Support for businesses. Australian IT Support
Adept Small Business IT
Passionate about IT Support

Please do show your appreciation to those who assist you by leaving Rep Point
Posting from a BB Playbook - please excuse my typing
  #10  
Old 29th June 2010, 14:59
Yaniv Hoobian Yaniv Hoobian is offline
Junior Member
It's not a coincidence
 
 Join Date: Nov 2006
  6 month star 12 month star
 Location: Haifa, ISRAEL
 Posts: 109
 Reputation: Yaniv Hoobian is on a distinguished road (10)
Default Re: Exchange 2010 Activesync using TMG not working well

its a new sever. installed 3 months ago

now when the time come to use activesync i face this problems.

today i mange to recreat the microsoft-server-activesync virtual directory.
and now ADSIEDIT shows some records for the virtual directorys.
but it's not like I'm familiarize with ( on exchange 2003 )

now under HTTP, i have only one folder for the OWA.
( CN=OWA (default web site))


and rows for each virtual directory, that looks like a text file.


Yaniv
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Forefront Threat Management Gateway (TMG) 2010 now Available Dumber General Security 7 14th May 2011 10:48
Ex 2010 ActiveSync problem. mmike Exchange 2007 / 2010 / 2013 4 1st February 2010 00:39
Exchange 2007 - Outlook Anywhere working, now ActiveSync is broken! mvalpreda Exchange 2007 / 2010 / 2013 1 4th August 2009 02:06
Exchange 2003 / WM 6.1 SSL ActiveSync not working Jamie Exchange 2000 / 2003 8 14th July 2009 21:12
ActiveSync working via http, but not https greminn Exchange 2000 / 2003 8 12th July 2008 23:57


All times are GMT +3. The time now is 09:38.

Steel Blue 3.5.4 vBulletin Style ©2006 vBEnhanced
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
 

Valid XHTML 1.0!   Valid CSS!

Copyright 2005 Daniel Petri