Re: ISA 2006 in DMZ for Activesync/OWA only Exchange 2003



Figured it out myself. Had to create another rule to allow LDAPS port 636
Inbound. For some reason the default protocol rule is for Outbound so that
would not work in my DMZ scenario.

When I enabled a rule for inbound to each of my DCs, pre-authentication
worked like a charm. Now I just need to add users to an AD group to allow
access.


"GA" <nospam@xxxxxxxxxxxx> wrote in message
news:ORQ2HXd1HHA.4712@xxxxxxxxxxxxxxxxxxxxxxx
Hi ISA experts! I am an ISA newbie building my first ISA server for Smart
Phone access to email for our sales reps.

Exchange OWA works internally. I am the Exchange Admin and am fairly
confident that Exchange is setup correctly although the FE/BE topology is
new to me as well.

My network guy wants ISA to live in the DMZ like this:

Public IP >> Edge switch (translates to private ip)>> ISA 2006 >> DMZ
Switch (translates another private ip to internal ip for FE server) >>
internal network (AD, Exchange FE/BE servers). I'm not sure if this is
even feasible.

I have done the certificate on FE and exported it then imported it on ISA,
published the rule using the wizard, single network config on ISA. The
only port we have open between DMZ and internal network is 443.

When I try to connect using a smart phone, I can get a username/password
prompt, but it fails to authenticate to ISA. What am I missing? I have
read on some websites that the smart phone needs the certificate installed
manually, but I don't buy that. It defeats the purpose of being able to
deploy a remote solution. Besides, I tried that and it still doesn't
work.



.



Relevant Pages

  • Re: Migration to exchange2007
    ... It had to do with an incorrect entry in the "Internal Network" list. ... Publishing Rule needs to be set so that it show all inbound communnication as "comming from the ISA". ... For a while 2007 and 2000 coexisted with the 2000 being the main server that handled all external communication. ... ISA was publishing the ip of exchange 2000 and everything worked fine. ...
    (microsoft.public.isaserver)
  • Re: ISA2004 EXCHANGE2003 SP2 SMTP
    ... communication from ISA to Exchange on internal network, ... Victor ... > Have you published the necessary exchange services in isa? ...
    (microsoft.public.isa)
  • Re: ISA and Exchange
    ... behind ISA and I cannot get to it from the outside. ... server rules set up with client address sets but it will not go. ... wonder if Exchange is grabbing the traffic before it hits ISA? ... > DMZ if ISA and Exchange are outside the internal network unless there is ...
    (microsoft.public.isaserver)
  • Re: ISA and Exchange
    ... Since we are using ISA 2004 already, all reading I am doing is in refrence ... to Exchange 2003 and ISA 2004. ... server itself from getting whacked. ... server on their internal network and then just allow HTTP / HTTPS through ...
    (microsoft.public.isa.enterprise)
  • Re: ActiveSync
    ... I've made sure all certs are exported from Exchange to ISA box. ... Before ISA reboot, when ActiveSync starts syncing, nothing gets logged in ... The security certificate on the server is not valid. ...
    (microsoft.public.isa.configuration)

Loading