This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos 9.1 WAF configuration for Exchange 2010 (and Outlook Anywhere)

Hello, 

is this KB still actual (after the 9.1 release) for Exchange 2010 and now for Outlook Anywhere?

How to configure your Webapplication Firewall for OWA and Active Sync support

Thank You.

Regards.
Stefano.


This thread was automatically locked due to age.
Parents
  • Is there anything related in either the Firewall or Intrusion Prevention log?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Is there anything related in either the Firewall or Intrusion Prevention log?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
  • Is there anything related in either the Firewall or Intrusion Prevention log?


    ips.log and packetfilter.log does not show any dropped or rejected packets incoming to the Outlook URL address.

    Entries in reverseproxy.log during test with 10.11.12.13 the Outlook URL addresse and 2.3.4.5 the test client show a mixture of http codes 200 and 401 all through the tests:

    2013:06:17-18:35:00 gw reverseproxy: srcip="2.3.4.5" localip="10.11.12.13" size="3550" user="-" host="2.3.4.5" method="POST" statuscode="200" reason="-" extra="-" time="5565701" url="/ews/Exchange.asmx" server="webmail.ourdomain.com" referer="-" cookie="exchangecookie=62be1...97b7" set-cookie="-"

    2013:06:17-18:35:02 gw reverseproxy: srcip="2.3.4.5" localip="10.11.12.13" size="0" user="-" host="2.3.4.5" method="POST" statuscode="401" reason="-" extra="-" time="3086" url="/ews/Exchange.asmx" server="webmail.ourdomain.com" referer="-" cookie="exchangecookie=62be...97b7" set-cookie="-"
  • This is the same as I get when trying to get iphones and phones working through waf.
  • This is the same as I get when trying to get iphones and phones working through waf.


    As I haven't heard any complaints yet from our iphone users about reading and writing mail and accessing the calendar, your problem seems to be a different one. Especially as iOS is using Active Sync and not EWS. Or do you see failed requests to /EWS from an iphone IP address?