You need to configure an exception for OWA notifications, see page 24 of the Exchange WAF Guide. The guide is for UTM 9.3 but it still applies to UTM 9.5.
Ewadie Hi,
Yes thats exactly what i have set for the /owa/ev.owa* to skip anti virus and all other categories and never change HTML. Even tried skiping all but to no avail i still get the same error. Snap shot from the WAF Log;
2017:11:09-12:54:29 ####-01-1 httpd: id="0299" srcip="1.1.1.1" localip="1.2.3.166" size="324" user="myname" host="4.6.8.1" method="GET" statuscode="200" reason="-" extra="-" exceptions="SkipAntiVirus, SkipURLHardening, SkipThreatsFilter" time="60179264" url="/owa/ev.owa" server="mail.public.org.uk" port="443" query="?UA=0&oeh=1&ns=PendingRequest&ev=PendingNotificationRequest&canary=cJR2vyzoe0O1nqG9cC_auUK9W7fwLNUInuYH2k4o0ecrXBU8E3U03ysqTNa0zEUBAaY4gaovoKs.n=j9sh58gx" referer="mail.public.org.uk/.../" cookie="MstrPgLd1=1; MstrPgLd2=1; ROUTEID.44b938094b2193ed55ad99a84171a1db=.node1; OutlookSession=b73d9eb6654b40a68c7878f023a6283f; UserContext=cJR2vyzoe0O1nqG9cC_auUK9W7fwLNUInuYH2k4o0ecrXBU8E3U03ysqTNa0zEUBAaY4gaovoKs.; tzid=GMT Standard Time; owacsdc=1" set-cookie="fkslfljmzsn_cookie=451eb49903c867adfc0831f5d85fd00c1cfecb27;path=/;httponly;secure" uid="WgRPyQoIPwQAAHA-G3IAAAAk"
Confirmed it works via straight NAT, its the only thing that is failing with OWA very frustrating.
Regards
Hi,
Was doing some further testing last night, i can get it working but only by completely disabling Anti Virus and All the common threat Filters, i tried every combination off and on between the two protection modules, we cannot leave it like that as we are then completely wide open to attached other than URL hardening.
I had noticed another URL that we were only Skipping URL Hardening that wasn't Skipping Antivirus and tried adding that to the OWA notifications Skip AV scanning
exceptions="SkipURLHardening" time="85942" url="/owa/14.3.352.0/
Skip AV with - /owa/14.3.352.0/*
You can then see it skipping the AV but still didn't work. I have a Case open with Sophos support just waiting for them to come back to me, will update this case when i have a conclusion.
Regards