Customers might be unable to connect with us via the Sophos Malaysia Support Hotline number. Our teams are actively working on a fix. In the interim, we request customers to use the backup hotline number - +65 3157 5922 (Singapore) or raise a support request at https://support.sophos.com/.

Help us enhance your Sophos Community experience. Share your thoughts in our Sophos Community survey.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Exchange server with 'Windows Extended Protection' behind WAF

Hey, I was wondering if anyone who has their Exchange server(s) behind a Sophos UTM WAF (to publish OWA, Autodiscover and Outlook Anywhere) has activated 'Windows Extended Protection' yet and if there were any problems or not.

Info:
techcommunity.microsoft.com/.../3593862
microsoft.github.io/.../



This thread was automatically locked due to age.
Parents
  • We activated the Extended Protection yesterday on all Exchange servers and since then, Outlook Anywhere stopped working.

    Everything from inside the company works fine, also Smartphones are able to sync mails but Outlook from external connections is not working. So we are doing a rollback.

    For a short test we disabled the Webserver Protection and did a 80 and 443 NAT to the Exchange Server and it worked. After enabling the Webserver Protection it Outlook Anywhere stopped working again.

    At the Exchange Server Eventlog we see:

    An account failed to log on.
    
    Subject:
    Security ID: NULL SID
    Account Name: -
    Account Domain: -
    Logon ID: 0x0
    
    Logon Type: 3
    
    Account For Which Logon Failed:
    Security ID: NULL SID
    Account Name: name.name@company.de (edited)
    Account Domain:
    
    Failure Information:
    Failure Reason: An Error occured during Logon.
    Status: 0xC000035B
    Sub Status: 0x0
    
    Process Information:
    Caller Process ID: 0x0
    Caller Process Name: -
    
    Network Information:
    Workstation Name: edited
    Source Network Address: edited
    Source Port: 34080
    
    Detailed Authentication Information:
    Logon Process:
    Authentication Package: NTLM
    Transited Services: -
    Package Name (NTLM only): -
    Key Length: 0

    So we disabled the Extended Protection and everything works through the Webserver Protection again.

    Is anyone able to use the Extended Protection together with Exchange Webserver Protection through UTM?

  • Same Problem here(UTM). After Update Exchange and enabling EP anything works fine except Outlook from external connections. We disable the extended Protection and open  a ticket to solve the Problem. Seems like the XG works.

Reply Children