This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Microsoft Teams Calendar through WAF

Hello,

I used to have the Exchange WebServices exposed to the internet over DNAT. Because of the recent Exchange exploits, we decided to start using the WAF again and to use the 2FA possibilities of the UTM.

It all works fine except the reason we used DNAT and not WAF in the first place: the Teams Calendar. It randomly comes and goes with users when connected through the WAF, which cripples their usage of Teams. My impression is that Microsoft queries the (on-premises) /ews very often and that Sophos blocks this because it is suspicious behaviour. I'm experimenting with the Firewall profile Exception List (eg. skip "Request limits"), but I'm not entirely sure what I am doing.

The current configuration is taken from https://support.sophos.com/support/s/article/KB-000038003?language=en_US, but it's not a good sign that it starts with "Sophos does not officially support Microsoft Exchange 2016 with WAF." I don't want to change firewall from several customers just because of a Teams issue. 



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thanks for reaching out to the Community! 

    Could you please replicate the issue and provide the reverseproxy logs from your firewall? 

    WAF log files

    You can view the WAF log files from the following locations:

    • Live Log View - go to Logging & Reporting > View Log Files > Today's Log Files > Web Application Firewall > Live Log
    • Shell Access - go to tail -f /var/log/reverseproxy.log

    Thanks,

  • I posted a part of the log file, but the forum decided it was spam and removed it ...

    --------------------

    J. Janssens

    Sophos Certified Architect
    Sophos Certified Engineer
    Sophos Certified Sales Consultant
    Gold Partner

Reply Children