Re: OWA 403 Forbidden, POP3,



Hi,

Thank you for your update.

Currently let's re-run CEICW wizard on SBS box, CEICW wizard helps us to
reconfigure Exchange, networking related settings on SBS box.

To do so:

1. On the Small Business Server 2003 computer, click "Start", and then
click "Server Management".

2. Expand "Standard Management", and then click "To Do List".

3. In the right pane, click "Connect to the Internet", and then click
"Next".

4. On the "Connection Type" page, click "Do not change connection type",
and then click "Next".

More info, please refer to following articles:

825763 How to configure Internet access in Windows Small Business Server
2003
http://support.microsoft.com/?id=825763

A step by step explanation of the CEICW:
http://www.sbs-rocks.com/sbs2k3/sbs2k3-n2.htm

If this issue persists please gather Metabase and IIS log for further
analysis

Collect the IIS metabase on Exchange Server and send to me:
v-chacez@xxxxxxxxxxxxx for further analysis:

1). On Exchange Server, install .NET Framework Version 1.1:
http://www.microsoft.com/downloads/details.aspx?FamilyID=262d25e3-f589-4842-
8157-034d1e7cf3a3&DisplayLang=en.
2). Install MBExplorer by installing IIS 6 Resource Kit Tools:
http://www.microsoft.com/downloads/details.aspx?FamilyId=56FC92EE-A71A-4C73-
B628-ADE629C89499&displaylang=en.
3). Once it is installed, access it from Start, Programs, IIS Resources,
Metabase Explorer.
4). In the left pane, right click ''LM'' (under your server computer name)
to choose ''Export to file'', and then save it as IIS.mbk.
5). Compress this mbk file and send it to me for analysis. Please let me
know the password if you set on this iis mbk file.

5. Please collect the IIS log on Exchange Server so that I can perform
further research:

1). On Exchange Serves, open IIS MMC, right click Default Web Site and then
click Properties.
2). Click Website tab and then check Enable logging.
3). Stop the Default Website and RENAME the existing IIS log files under
C:\WINDOWS\system32\LogFiles\W3SVC1.
4). Restart the Default Website and reproduce the problem, which will
generate new IIS log file with the exact error.
5). Wait for a while so that IIS Log can be synced. And then go to the
following folder on Exchange Server: C:\WINDOWS\system32\LogFiles\W3SVC1.
6). Send me the log files to my working email address
v-chacez@xxxxxxxxxxxxxx And please let me know the alias of the user who
encountered the issue.

Hope this helps, if anything unclear, please do not hesitate to let me know.


Best Regards,

Chace Zhang (MSFT)

Microsoft CSS Online Newsgroup Support

Get Secure! - www.microsoft.com/security

=====================================================
This newsgroup only focuses on SBS technical issues. If you have issues
regarding other Microsoft products, you'd better post in the corresponding
newsgroups so that they can be resolved in an efficient and timely manner.
You can locate the newsgroup here:
http://www.microsoft.com/communities/newsgroups/en-us/default.aspx

When opening a new thread via the web interface, we recommend you check the
"Notify me of replies" box to receive e-mail notifications when there are
any updates in your thread. When responding to posts via your newsreader,
please "Reply to Group" so that others may learn and benefit from your
issue.

Microsoft engineers can only focus on one issue per thread. Although we
provide other information for your reference, we recommend you post
different incidents in different threads to keep the thread clean. In doing
so, it will ensure your issues are resolved in a timely manner.

For urgent issues, you may want to contact Microsoft CSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

Any input or comments in this thread are highly appreciated.

=====================================================

This posting is provided "AS IS" with no warranties, and confers no rights.


--------------------
| From: "CJH" <cjh@xxxxxxxxxxxxxxxxxxxx>
| References: <e2jOQgEBHHA.4348@xxxxxxxxxxxxxxxxxxxx>
<FjYMb5JBHHA.1976@xxxxxxxxxxxxxxxxxxxxx>
<OruL46bCHHA.856@xxxxxxxxxxxxxxxxxxxx>
| Subject: Re: OWA 403 Forbidden, POP3,
| Date: Thu, 16 Nov 2006 15:04:39 -0600
| Lines: 191
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.2900.2869
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2962
| X-RFC2646: Format=Flowed; Response
| Message-ID: <OJeQhicCHHA.4844@xxxxxxxxxxxxxxxxxxxx>
| Newsgroups: microsoft.public.windows.server.sbs
| NNTP-Posting-Host: profiletechgroup.com 66.93.17.78
| Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP02.phx.gbl
| Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.windows.server.sbs:313311
| X-Tomcat-NG: microsoft.public.windows.server.sbs
|
| It does appear as if the TrendMicro stuff messed it up.
|
| Trend Micro has been removed, bht problems still persist.
|
| Is there a way to just re-install the IIS components to a set of Default
| Values? It was working before patches, and TrendMicro stuff was applied.
| The few other things I have installed in IIS are easy to redo. This
| incorrect type of install of Trend not in a virtual directory was
probably
| done in the late hours while things were being put back together.
|
|
| "CJH" <cjh@xxxxxxxxxxxxxxxxxxxx> wrote in message
| news:OruL46bCHHA.856@xxxxxxxxxxxxxxxxxxxxxxx
| >
| > "chace zhang" <v-chacez@xxxxxxxxxxxxx> wrote in message
| > news:FjYMb5JBHHA.1976@xxxxxxxxxxxxxxxxxxxxxxxx
| >> Hi,
| >>
| >> Thank you for posting here.
| >>
| >> From your post, I understand you after you rebuild SBS Server, you
| >> experienced a couple of problems. Please understand this newsgroup is
a
| >> one
| >> issue based service, to keep the thread clean, let's focus on OWA 403
| >> Forbidden issue, thanks for your understanding
| >>
| >> Based on my research, the symptom indicated that the web site only
allows
| >> restricted source IP. This is a normal behavior for a newly installed
SBS
| >> box. The SBS setup wizard implants IP restrictions on the default web
| >> site.
| >> We can run the CEICW to enable particular web services so that the
| >> restrictions on the virtual directory will be removed. Can I assume
that
| >> you have already run the CEICW on the SBS server? If not, please open
| >> Server Management console, navigate to 'To Do List'. Click 'Connect to
| >> the
| >> internet' in the right panel. In the web services configuration window,
| >> select the web functions which you want to use from the internet. When
| >> you
| >> select to allow "Outlook Web Access" when running CEICW, the component
| >> will
| >> modify the IIS connection permissions for the OWA-specific virtual
| >> directories to allow clients from any IP address to connect, while the
| >> rest
| >> of the site only allows local IP addresses to connect. Follow the
wizard
| >> to
| >> complete the configurations. After doing this, will the problem be
| >> resolved?
| >>
| >>
| >> 825763 How to configure Internet access in Windows Small Business
Server
| >> 2003
| >> http://support.microsoft.com/?id=825763
| >>
| >> A step by step explanation of the CEICW:
| >> http://www.sbs-rocks.com/sbs2k3/sbs2k3-n2.htm
| >>
| >>
| >>
| >> If the issue still persists after above steps. To verify is there an IP
| >> restriction configured on the website!
| >>
| >> 1. Click Start, point to Administrative Tools and click Internet
| >> Information Services (IIS) Manager.
| >>
| >> 2. Expand your server | Web Sites | Default Web Site, right-click
Default
| >> Web Site and click Properties.
| >>
| >> 3. On the Directory Security tab, click Edit in the "IP address and
| >> domain
| >> name restrictions" section.
| >>
| >> 4. What IP address access restrictions have been configured?
| > 192.168.0.100 (The server)
| > 127.0.1.0 (Loopback)
| >
| >>
| >> 5. Also check this setting for the Exchweb and the Exchange virtual
| >> directory.
| >
| > (No restrictions)
| >
| >>
| >>
| >> You don't need port 80 inbound open.Port 80 is still the most attacked
| >> port
| >> on the internet.
| >>
| >> Please use HTTPS instead of HTTP to access OWA and forward port 443
from
| >> the router to your external nic.
| >
| > Use HTTPS only
| >
| >
| >>
| >>
| >>
| >> 1. Make sure you have Exchange SP1 installed
| >
| > Done......
| >
| >>
| >> 2. Clear the IIS server files. To do so, follow these steps:
| >
| > Done.....
| >
| >>
| >> a. Go to your "%SystemRoot%\IIS Temporary Compressed Files"
| >> (C:\WINDOWS\IIS
| >> Temporary Compressed Files or C:\WINNT\IIS Temporary Compressed Files)
| >> directory.
| >
| > Done .....
| >
| >>
| >> b. Select all of the content in this directory and delete it.
| >>
| >> 3. Click Start->Run, type "iisreset" (without the quotes) and click OK
to
| >> restart the IIS services.
| >
| > Done....
| >
| >>
| >> At the client side:
| >>
| >> a. Open IE, and go to Tools -> Internet Options.
| >>
| >> b. Select Delete Files, check "Delete all offline files" and click OK
to
| >> confirm that you want to delete the content. Then check if the issue
| >> disappears.
| >>
| >> This issue may also be caused by URLSCAN installed on IIS if it is not
| >> configured per the Exchange 2003 OWA template. For more information,
see:
| >
| > URL Scan is not installed.
| >
| >
| >
|
|
|
| --------------------
| | From: "CJH" <cjh@xxxxxxxxxxxxxxxxxxxx>
| | Subject: OWA 403 Forbidden, POP3,
| | Date: Thu, 9 Nov 2006 15:50:41 -0600
| | Lines: 27
| | X-Priority: 3
| | X-MSMail-Priority: Normal
| | X-Newsreader: Microsoft Outlook Express 6.00.2900.2869
| | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2962
| | X-RFC2646: Format=Flowed; Original
| | Message-ID: <e2jOQgEBHHA.4348@xxxxxxxxxxxxxxxxxxxx>
| | Newsgroups: microsoft.public.windows.server.sbs
| | NNTP-Posting-Host: profiletechgroup.com 66.93.17.78
| | Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP04.phx.gbl
| | Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.windows.server.sbs:311500
| | X-Tomcat-NG: microsoft.public.windows.server.sbs
| |
| | Had to rebuild server over the weekend due to a Crash, and a backup that
| | would not recognize hardware.
| |
| | Was able to retrieve all user data, and E-mail (I assume).
| |
| | Server is basically up and running, but a couple of critical services
are
| | giving fits.
| |
| | 1. https:/www/company.com/remote (RWW Works, Can get to
| desktops/servers
| | 2. * OWA Get to Login screen, and then Error 403 Forbidden <===
| Need
| | this one
| | 3. * POP3 Connectot, Unable to connect on 110
| | 4 * IMAP4 Connection Unable to connect on 143
| | 5 * Active Sync to a Treo phone connects just fine, error when
| download
| | of data starts
| | 6 Outlook Desktop works just fine
| | 7. Shared directories etc OK.
| | 8. CompanyWeb does work OK (Only used Intranet)
| | 9 All Automatic Services running.
| |
| | OWA Originally worked as expected. Between patches, updates, Install of
| | Trend Micro SMB something has gone astray, and I am at a loss where to
| look
| | any more.
| |
| | Looking for input.
| |
| |
| |
|
|
|

.



Relevant Pages

  • RE: Error on page in RMonitoring report
    ... IIS settings? ... Do you have any issue when you visit SBS backup node in the Server ... since you still receive the monitoring report of ...
    (microsoft.public.windows.server.sbs)
  • Re: So why SBS?
    ... Public folders will be in the next version.. ... The sad part of most of us is that we haven't even tried or practiced a backup/restore and we freak out over a 'single" SBS box when we haven't even tried to restore it from a harddrive. ... Exchange seems to mix its words and titles, the global/generic use of POP and SMTP for just about every Exchange function is dumb, MailEnable understands post office protocol and simple mail transfer protocol in a "meaningfull" way. ... The standard profiles in Server are quite effective assuming you add new users to the correct account in the first place and your note running more than 1 file server. ...
    (microsoft.public.windows.server.sbs)
  • Re: Easy to use second 2000 Server for Exchange?
    ... Existing Exchange 2000 server - therefore have the CALs - so no new ones are ... Frank McCallister SBS MVP ...
    (microsoft.public.windows.server.sbs)
  • Re: So why SBS?
    ... Public folders will be in the next version.. ... If SBS isn't for you...that's fine. ... Mailenable is an example of a freeware or pay for extra's, mail server. ... It is infinitly simpler to configure than Exchange once installed. ...
    (microsoft.public.windows.server.sbs)
  • Re: Email for second domain
    ... The Microsoft Exchange MTA Stacks service is normally disabled on Exchange 2003 Servers on SBS 2003. ... You can safely ignore the MTA warning messages on the SBS 2003 server. ...
    (microsoft.public.windows.server.sbs)

Loading