<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Exchange OWA Access through Web Application Firewall</title><link>https://community.sophos.com/utm-firewall/f/web-server-security/114628/exchange-owa-access-through-web-application-firewall</link><description>So I am trying to configure Exchange OWA web access through the Webserver protection area on our UTM 9. I&amp;#39;ve followed the guide here: https://community.sophos.com/kb/en-us/131787 
 However I am still unable to login with a test user to our Exchange server</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Exchange OWA Access through Web Application Firewall</title><link>https://community.sophos.com/thread/412108?ContentTypeID=1</link><pubDate>Thu, 15 Aug 2019 09:57:34 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:862e6034-c915-43a2-808f-ddce210e7304</guid><dc:creator>Jammy</dc:creator><description>&lt;p&gt;[quote user=&amp;quot;Jnurse&amp;quot;]&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div class="quote-header"&gt;&amp;nbsp;&lt;/div&gt;
&lt;blockquote class="quote"&gt;
&lt;div class="quote-user"&gt;Evianne&lt;/div&gt;
&lt;div class="quote-content"&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div class="quote-header"&gt;&amp;nbsp;&lt;/div&gt;
&lt;blockquote class="quote"&gt;
&lt;div class="quote-user"&gt;Jnurse&lt;/div&gt;
&lt;div class="quote-content"&gt;
&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Tried this and no luck. Here are the logs for when I tried;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;div class="quote-footer"&gt;&amp;nbsp;&lt;/div&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Next step would be to disable Reverse Authentication.&lt;/p&gt;
&lt;p&gt;This helps you to make sure, that you can authenticate with Basic Auth over the WAF at your Exchange.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&amp;nbsp;&lt;/div&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;div class="quote-footer"&gt;&amp;nbsp;&lt;/div&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If I remove the authentication profile from all the virtual webservers then I am able to get to OWA and authenticate successfully so something is going wrong with the authentication pass-through I assume....&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;James&lt;/p&gt;
&lt;div style="clear:both;"&gt;&amp;nbsp;&lt;/div&gt;
&lt;p&gt;[/quote]&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Although I can&amp;#39;t seem to use the Outlook mobile app as I get &amp;#39;Login error&amp;#39; and the following appears in the log;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://community.sophos.com/cfs-file/__key/communityserver-discussions-components-files/57/Web-application-firewall3.txt"&gt;community.sophos.com/.../Web-application-firewall3.txt&lt;/a&gt;&lt;/p&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Exchange OWA Access through Web Application Firewall</title><link>https://community.sophos.com/thread/412104?ContentTypeID=1</link><pubDate>Thu, 15 Aug 2019 09:19:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:198aa900-77e4-485a-8d99-aec7cdc77b2b</guid><dc:creator>Jammy</dc:creator><description>&lt;p&gt;[quote user=&amp;quot;Evianne&amp;quot;]&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div class="quote-header"&gt;&amp;nbsp;&lt;/div&gt;
&lt;blockquote class="quote"&gt;
&lt;div class="quote-user"&gt;Jnurse&lt;/div&gt;
&lt;div class="quote-content"&gt;
&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Tried this and no luck. Here are the logs for when I tried;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;div class="quote-footer"&gt;&amp;nbsp;&lt;/div&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Next step would be to disable Reverse Authentication.&lt;/p&gt;
&lt;p&gt;This helps you to make sure, that you can authenticate with Basic Auth over the WAF at your Exchange.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&amp;nbsp;&lt;/div&gt;
&lt;p&gt;[/quote]&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If I remove the authentication profile from all the virtual webservers then I am able to get to OWA and authenticate successfully so something is going wrong with the authentication pass-through I assume....&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;James&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Exchange OWA Access through Web Application Firewall</title><link>https://community.sophos.com/thread/412103?ContentTypeID=1</link><pubDate>Thu, 15 Aug 2019 09:13:23 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7e03635e-00fa-4706-861e-e4b28845cfc6</guid><dc:creator>Evianne</dc:creator><description>&lt;p&gt;[quote user=&amp;quot;Jnurse&amp;quot;]&lt;/p&gt;
&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Tried this and no luck. Here are the logs for when I tried;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;[/quote]&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Next step would be to disable Reverse Authentication.&lt;/p&gt;
&lt;p&gt;This helps you to make sure, that you can authenticate with Basic Auth over the WAF at your Exchange.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Exchange OWA Access through Web Application Firewall</title><link>https://community.sophos.com/thread/412099?ContentTypeID=1</link><pubDate>Thu, 15 Aug 2019 08:51:42 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8b0142b9-d872-4029-a0fe-c40663446963</guid><dc:creator>Jammy</dc:creator><description>&lt;p&gt;[quote user=&amp;quot;Evianne&amp;quot;]&lt;/p&gt;
&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;you got a lot of errors like &amp;#39; [client 52.125.138.122:40866] Client is listed on DNSRBL black.rbl.ctipd.astaro.local&amp;#39; in your logs.&lt;br /&gt;&lt;br /&gt;Make an exception for this IP (or your network) for &amp;#39;Block clients with bad reputation&amp;#39; and test again.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Best,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Sabine&lt;/p&gt;
&lt;div style="clear:both;"&gt;&amp;nbsp;&lt;/div&gt;
&lt;p&gt;[/quote]&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Tried this and no luck. Here are the logs for when I tried;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://community.sophos.com/cfs-file/__key/communityserver-discussions-components-files/57/Web-application-firewall2.txt"&gt;community.sophos.com/.../Web-application-firewall2.txt&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Exchange OWA Access through Web Application Firewall</title><link>https://community.sophos.com/thread/412092?ContentTypeID=1</link><pubDate>Thu, 15 Aug 2019 07:12:02 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e36c78a9-e827-4431-aba7-e1584c144537</guid><dc:creator>Evianne</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;you got a lot of errors like &amp;#39; [client 52.125.138.122:40866] Client is listed on DNSRBL black.rbl.ctipd.astaro.local&amp;#39; in your logs.&lt;br /&gt;&lt;br /&gt;Make an exception for this IP (or your network) for &amp;#39;Block clients with bad reputation&amp;#39; and test again.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Best,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Sabine&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Exchange OWA Access through Web Application Firewall</title><link>https://community.sophos.com/thread/412046?ContentTypeID=1</link><pubDate>Wed, 14 Aug 2019 19:25:51 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b47c29e9-5893-40bb-a51e-a006284bab08</guid><dc:creator>Jammy</dc:creator><description>&lt;p&gt;[quote user=&amp;quot;Alexander Busch&amp;quot;]But this KB never said do authentication via UTM.&lt;/p&gt;
&lt;p&gt;I think that is the problem. Try to do the authentication on Exchange/IIS. This should help.&lt;/p&gt;
&lt;p&gt;Best regards &lt;/p&gt;
&lt;p&gt;Alex &lt;/p&gt;
&lt;p&gt;[/quote]&lt;/p&gt;
&lt;p&gt;It said optional was to use &amp;#39;basic&amp;#39; or &amp;#39;form&amp;#39; pass through. If I turn authentication off for the webserver then I get access denied message and no option to authenticate with owa &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Exchange OWA Access through Web Application Firewall</title><link>https://community.sophos.com/thread/412045?ContentTypeID=1</link><pubDate>Wed, 14 Aug 2019 19:06:30 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1a897dd1-34c2-4822-a8a6-3257ee3c5658</guid><dc:creator>Alexander Busch</dc:creator><description>&lt;p&gt;But this KB never said do authentication via UTM.&lt;/p&gt;
&lt;p&gt;I think that is the problem. Try to do the authentication on Exchange/IIS. This should help.&lt;/p&gt;
&lt;p&gt;Best regards &lt;/p&gt;
&lt;p&gt;Alex &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>