Outlook access through a firewall

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Greetings,

We're currently trying to get Outlook working through a firewall, and
connected to Exchange 2000. I've read from multiple sources that this
requires locking down the high-numbered ports that the RPC Endpoint
Mapper hands out (via a registry edit), then opening up TCP port 135
and the high-numbered ports in the firewall.

We've done this, and for some reason it seems to not be working. We
set up an access rule and a translation rule in our PIX, identical to
the one that allows HTTP traffic to the Exchange server for OWA (except
for port 135 instead of 80). However, when telnetting to the outside
address specified in the translation rule on port 135, we get no
answer; the connection isn't refused, it just hangs while trying to
make the connection. Doing the same thing from inside the network
yields a familiar input prompt, indicating that the service is indeed
listening.

Since the access list and translation rule we set up are identical to
the (working) one allowing HTTP traffic through, we think that this
isn't a firewall issue. Is there any setting in Exchange that would
deny connections on port 135 to things, say, outside of the subnet? I
know you can configure access restrictions on the built-in
HTTP,IMAP,POP3 servers, but I find no similar setting that would
explain what we're seeing.

Any advice appreciated.

.



Relevant Pages

  • Re: AS4.2/WM5/OUTLOOK2K3 suddenly not syncing, please help
    ... there is a connection EXIST between the device because I ... connection on port 26675 but on the PPC the port number keeps ... Outlook, countless times of reinstalling Activesync, removing Windows ... Firewall set to NO). ...
    (microsoft.public.pocketpc.activesync)
  • RE: Exchange 2003
    ... This behavior seems plausible if there's a stateful firewall in the ... the case, then clearly, you won't get anything back from an nbtstat, ... does it allow it after there's a connection?". ... without exchange 2003 on it. ...
    (Pen-Test)
  • Re: Store and forward server
    ... address space but not the port. ... > But why not have Exchange pick up the mail from the head office (pull vs. ... > only an intermittent connection to a service provider. ... The roles of client and server then reverse, ...
    (microsoft.public.exchange.connectivity)
  • Re: 45 days STUCK LIKE CHUCK. DNS / Mx record cant recieve emails
    ... you've pretty much ruled out Exchange configuration. ... Exchange not listening on the Internet NIC. ... You can test the connection from within the LAN, ... I'm thinking that leaves the NAT device blocking port 25. ...
    (microsoft.public.windows.server.sbs)
  • RE: FTP Window of opportunity?
    ... target on the line when in reality it was just a firewall lying to them. ... The connection connects and then immediately ... Subject: FTP Window of opportunity? ... the FTP port shows up. ...
    (Pen-Test)