![]() |
|
|
|||||||
| Petri.co.il is happy to award auglan the title of Most Valuable Member !!! |
| Register | Calendar |
Search |
Today's Posts |
Mark Forums Read |
| Notices |
|
|
Exchange 2010 Activesync using TMG not working wellthis thread has 10 replies and has been viewed 6799 times
|
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
|||||||||
|
|||||||||
|
hi
i have a new deployment that have some problems. the servers are : Exchange 2010 on server 2008 R2 the domain controllers are server 2003 STD the TMG is on server 2008 64bit the tmg is located in the DMZ an has 1 NIC. I've setup according to bunch of articles i found, and it's working fine only if I'm not forcing the use of SSL certificate. when i turn on the "require client certificate" the TMG log shows Allowed connection using my active sync rule, but the HTTP status code is "403 forbidden" i appreciate any help almost forgot, the certificate is issued from the CA on the domain controller. I've tested the connection internally using "exchange ActiveSync MD" tool, and it's working. thanks Yaniv Last edited by Yaniv Hoobian; 28th June 2010 at 15:29.. |
|
#2
|
|||||||||||
|
|||||||||||
|
tmg works better with two nics.. otherwise you're not necessarily getting the benefit of the firewall
__________________
Posting from a BB Playbook - please excuse my typing |
|
#3
|
|||||||||
|
|||||||||
|
i have two other firewalls outside the DMZ.
the only purposes of the TMG is to publish the exchange |
|
#4
|
|||||||||||
|
|||||||||||
|
a google search for tmg publish exchange one nic found this as one of the first responses
http://social.technet.microsoft.com/...0-5c8b96e9efe7
__________________
Posting from a BB Playbook - please excuse my typing |
|
#5
|
|||||||||
|
|||||||||
|
thanks, but i read it before.
it's something related to the way the TMG act when a certificate is used. |
|
#6
|
|||||||||||
|
|||||||||||
|
I'm re-reading your post.
"require client certificate" To me, it sound likes that option is requiring that the CLIENT Present a certificate to authenticate itself. The SSL Certificate for the Exchange websites should be bound to the HTTPS listener on the ISA server.
__________________
Posting from a BB Playbook - please excuse my typing |
|
#7
|
|||||||||
|
|||||||||
|
done that already.
i searched some more and i think the problem is bigger. i don't see the exchage virtual directorys in ADSIEDIT. i wanted to recreate the microsoft-server-activesync virtual directory, but it woulsn't let me reomove it, becuase the dc don't recognize it as existed. but when i wanted to create it, it says ut is already created. so i opened the ADSIEDIT based on what i've found here http://www.experts-exchange.com/Soft..._26185316.html if you can't read it here it is : "Navigate to the following: CN=Configuration, DC=dommainname, DC=com -> CN=Services -> CN=domainname -> CN=Administrative Groups -> CN=Exchange Administrative Group (FYDIBOHF23SPDLT) -> CN=Servers -> CN=Netbios name of the exchange server -> CN=Protocols -> CN=HTTP and under HTTP found only OWA" any ides? |
|
#8
|
|||||||||
|
|||||||||
|
An update
i changed the external ip address to port forward to the exchange server directly. and i came to the same result. so the problem is with the exchange or active directory and not the TMG Yaniv |
|
#9
|
|||||||||||
|
|||||||||||
|
ok, has it EVER worked as it is supposed to?
If so, what was changed recently. If it worked, and now doesn't, something changed. Vdirs don't just delete themselves. Have you tried reinstalling the CAS role ?
__________________
Posting from a BB Playbook - please excuse my typing |
|
#10
|
|||||||||
|
|||||||||
|
its a new sever. installed 3 months ago
now when the time come to use activesync i face this problems. today i mange to recreat the microsoft-server-activesync virtual directory. and now ADSIEDIT shows some records for the virtual directorys. but it's not like I'm familiarize with ( on exchange 2003 ) now under HTTP, i have only one folder for the OWA. ( CN=OWA (default web site)) and rows for each virtual directory, that looks like a text file. Yaniv |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Forefront Threat Management Gateway (TMG) 2010 now Available | Dumber | General Security | 7 | 14th May 2011 10:48 |
| Ex 2010 ActiveSync problem. | mmike | Exchange 2007 / 2010 / 2013 | 4 | 1st February 2010 00:39 |
| Exchange 2007 - Outlook Anywhere working, now ActiveSync is broken! | mvalpreda | Exchange 2007 / 2010 / 2013 | 1 | 4th August 2009 02:06 |
| Exchange 2003 / WM 6.1 SSL ActiveSync not working | Jamie | Exchange 2000 / 2003 | 8 | 14th July 2009 21:12 |
| ActiveSync working via http, but not https | greminn | Exchange 2000 / 2003 | 8 | 12th July 2008 23:57 |