<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>WAF on v9.3 for Exchange 2013 on single server/IP/FQDN/certificate?</title><link>https://community.sophos.com/utm-firewall/f/web-server-security/50352/waf-on-v9-3-for-exchange-2013-on-single-server-ip-fqdn-certificate</link><description>Hello all,  Is it at all possible to set up WAF on v9.3 for Exchange 2013 OWA, Outlook Anywhere and ActiveSync on the same URL, on one server, a single IP address, and with the same certificate (with only one server name in it)?  I have tried to follow</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: WAF on v9.3 for Exchange 2013 on single server/IP/FQDN/certificate?</title><link>https://community.sophos.com/thread/185301?ContentTypeID=1</link><pubDate>Sun, 29 Mar 2015 01:47:27 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e19578ad-e6ca-46e4-a40e-2f855427573e</guid><dc:creator>MrOlrich</dc:creator><description>Ok,&amp;nbsp;my&amp;nbsp;set&amp;nbsp;up&amp;nbsp;and&amp;nbsp;settings&amp;nbsp;are&amp;nbsp;as&amp;nbsp;follows:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Preparations&lt;/b&gt;&lt;br /&gt;Registered&amp;nbsp;two&amp;nbsp;certificates&amp;nbsp;for&amp;nbsp;free&amp;nbsp;at&amp;nbsp;startssl.com;&amp;nbsp;mail.domain.com&amp;nbsp;and&amp;nbsp;autodiscover.domain.com.&lt;br /&gt;Created&amp;nbsp;public&amp;nbsp;DNS&amp;nbsp;A&amp;nbsp;and&amp;nbsp;MX&amp;nbsp;records&amp;nbsp;pointing&amp;nbsp;to&amp;nbsp;my&amp;nbsp;single&amp;nbsp;public&amp;nbsp;IP.&lt;br /&gt;Created&amp;nbsp;the&amp;nbsp;host&amp;nbsp;&amp;quot;labserver.internal.domain.com&amp;quot;,&amp;nbsp;with&amp;nbsp;IP&amp;nbsp;and&amp;nbsp;DNS&amp;nbsp;hostname&amp;nbsp;specified.&lt;br /&gt;No&amp;nbsp;firewall&amp;nbsp;rules&amp;nbsp;or&amp;nbsp;NAT&amp;nbsp;set&amp;nbsp;up.&amp;nbsp;Traffic&amp;nbsp;is&amp;nbsp;forwarded&amp;nbsp;when&amp;nbsp;everything&amp;nbsp;below&amp;nbsp;is&amp;nbsp;enabled.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Virtual&amp;nbsp;webserver&amp;nbsp;&amp;quot;Exchange&amp;nbsp;Autodiscover&amp;quot;&lt;/b&gt;&lt;br /&gt;Interface:&amp;nbsp;External&amp;nbsp;(Address)&lt;br /&gt;Type:&amp;nbsp;Encrypted&amp;nbsp;(HTTPA)&amp;nbsp;&amp;amp;&amp;nbsp;Redirect&lt;br /&gt;Port:&amp;nbsp;443&lt;br /&gt;Certificate:&amp;nbsp;autodiscover.domain.com&lt;br /&gt;Domain:&amp;nbsp;autodiscover.domain.com&lt;br /&gt;Real&amp;nbsp;webserver:&amp;nbsp;Exchange&lt;br /&gt;Firewall&amp;nbsp;profile:&amp;nbsp;Exchange&amp;nbsp;Autodiscover&lt;br /&gt;Rewrite&amp;nbsp;HTML:&amp;nbsp;checked&lt;br /&gt;Rewrite&amp;nbsp;cookies:&amp;nbsp;checked&lt;br /&gt;Pass&amp;nbsp;Host&amp;nbsp;Header:&amp;nbsp;checked&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Virtual&amp;nbsp;webserver&amp;nbsp;&amp;quot;Exchange&amp;nbsp;OWA+OA+AS&amp;quot;&lt;/b&gt;&lt;br /&gt;Interface:&amp;nbsp;External&amp;nbsp;(Address)&lt;br /&gt;Type:&amp;nbsp;Encrypted&amp;nbsp;(HTTPA)&amp;nbsp;&amp;amp;&amp;nbsp;Redirect&lt;br /&gt;Port:&amp;nbsp;443&lt;br /&gt;Certificate:&amp;nbsp;mail.domain.com&lt;br /&gt;Domain:&amp;nbsp;mail.domain.com&lt;br /&gt;Real&amp;nbsp;webserver:&amp;nbsp;Exchange&lt;br /&gt;Firewall&amp;nbsp;profile:&amp;nbsp;Exchange&amp;nbsp;OWA+OA+AS&lt;br /&gt;Rewrite&amp;nbsp;HTML:&amp;nbsp;checked&lt;br /&gt;Rewrite&amp;nbsp;cookies:&amp;nbsp;checked&lt;br /&gt;Pass&amp;nbsp;Host&amp;nbsp;Header:&amp;nbsp;checked&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Real&amp;nbsp;webserver&amp;nbsp;&amp;quot;Exchange&amp;quot;&lt;/b&gt;&lt;br /&gt;Name:&amp;nbsp;Exchange&lt;br /&gt;Host:&amp;nbsp;labserver.internal.domain.com&lt;br /&gt;Type:&amp;nbsp;Encrypted&amp;nbsp;(HTTPS)&lt;br /&gt;Port:&amp;nbsp;443&lt;br /&gt;HTTP&amp;nbsp;keepalive:&amp;nbsp;300&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Firewall&amp;nbsp;profile&amp;nbsp;&amp;quot;Exchange&amp;nbsp;Autodiscover&amp;quot;&lt;/b&gt;&lt;br /&gt;Mode:&amp;nbsp;Reject&lt;br /&gt;Static&amp;nbsp;URL&amp;nbsp;Hardening:&amp;nbsp;/autodiscover&amp;nbsp;and&amp;nbsp;/Autodiscover&lt;br /&gt;Form&amp;nbsp;Hardening:&amp;nbsp;checked.&lt;br /&gt;Block&amp;nbsp;clients&amp;nbsp;with&amp;nbsp;bad&amp;nbsp;reputation:&amp;nbsp;checked.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Firewall&amp;nbsp;profile&amp;nbsp;&amp;quot;Exchange&amp;nbsp;OWA+OA+AS&amp;quot;&lt;/b&gt;&lt;br /&gt;Mode:&amp;nbsp;Reject&lt;br /&gt;Static&amp;nbsp;URL&amp;nbsp;Hardening:&amp;nbsp;/owa,&amp;nbsp;/OWA,&amp;nbsp;/ecp,&amp;nbsp;/ECP,&amp;nbsp;/rpc,&amp;nbsp;/RPC,&amp;nbsp;/oab,&amp;nbsp;/OAB,&amp;nbsp;/microsoft-server-activesync,&amp;nbsp;/Microsoft-Server-ActiveSync&lt;br /&gt;Antivirus:&amp;nbsp;Dual&amp;nbsp;scan,&amp;nbsp;uploads&amp;nbsp;and&amp;nbsp;downloads.&lt;br /&gt;Block&amp;nbsp;unscannable&amp;nbsp;content:&amp;nbsp;checked.&lt;br /&gt;Block&amp;nbsp;clients&amp;nbsp;with&amp;nbsp;bad&amp;nbsp;reputation:&amp;nbsp;checked.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Exception&amp;nbsp;&amp;quot;Exchange&amp;nbsp;Autodiscover&amp;quot;&lt;/b&gt;&lt;br /&gt;Static&amp;nbsp;URL&amp;nbsp;Hardening:&amp;nbsp;skipped&amp;nbsp;(checked)&lt;br /&gt;XSS&amp;nbsp;Attacks:&amp;nbsp;skipped&amp;nbsp;(checked)&lt;br /&gt;Virtual&amp;nbsp;webserver:&amp;nbsp;Exchange&amp;nbsp;Autodiscover&lt;br /&gt;Web&amp;nbsp;requests&amp;nbsp;matching&amp;nbsp;this&amp;nbsp;path:&amp;nbsp;/autodiscover/*,&amp;nbsp;/Autodiscover/*&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Exception&amp;nbsp;&amp;quot;Exchange&amp;nbsp;OWA+OA+AS&amp;quot;&lt;/b&gt;&lt;br /&gt;Static&amp;nbsp;URL&amp;nbsp;Hardening:&amp;nbsp;skipped&amp;nbsp;(checked)&lt;br /&gt;Virtual&amp;nbsp;webserver:&amp;nbsp;Exchange&amp;nbsp;OWA+OA+AS&lt;br /&gt;Web&amp;nbsp;requests&amp;nbsp;matching&amp;nbsp;this&amp;nbsp;path:&lt;br /&gt;/owa/*,&amp;nbsp;/OWA/*,&amp;nbsp;/ecp/*,&amp;nbsp;/ECP/*,&amp;nbsp;/rpc/*,&amp;nbsp;/RCP/*,&amp;nbsp;/oab/*,&amp;nbsp;/OAB/*,&amp;nbsp;/microsoft-server-activesync*,&amp;nbsp;/Microsoft-Server-ActiveSync*&lt;br /&gt;&lt;br /&gt;Default&amp;nbsp;site&amp;nbsp;path&amp;nbsp;routes&amp;nbsp;are&amp;nbsp;unmodified.&lt;br /&gt;Secrets&amp;nbsp;under&amp;nbsp;the&amp;nbsp;Advanced&amp;nbsp;tab&amp;nbsp;are&amp;nbsp;unmodified.&lt;br /&gt;Reverse&amp;nbsp;authentication:&amp;nbsp;Nothing&amp;nbsp;configured.&lt;br /&gt;&lt;br /&gt;Setting&amp;nbsp;up&amp;nbsp;Outlook&amp;nbsp;2013&amp;nbsp;both&amp;nbsp;on&amp;nbsp;the&amp;nbsp;LAN&amp;nbsp;and&amp;nbsp;outside&amp;nbsp;through&amp;nbsp;Autodiscover&amp;nbsp;works&amp;nbsp;flawlessly,&amp;nbsp;as&amp;nbsp;does&amp;nbsp;a&amp;nbsp;corporate&amp;nbsp;account&amp;nbsp;on&amp;nbsp;a&amp;nbsp;Cyanogenmod&amp;nbsp;Android&amp;nbsp;mobile.&lt;br /&gt;&lt;br /&gt;Please&amp;nbsp;note&amp;nbsp;that&amp;nbsp;I&amp;nbsp;have&amp;nbsp;no&amp;nbsp;idea&amp;nbsp;if&amp;nbsp;these&amp;nbsp;settings&amp;nbsp;are&amp;nbsp;the&amp;nbsp;optimal&amp;nbsp;ones&amp;nbsp;for&amp;nbsp;either&amp;nbsp;security&amp;nbsp;or&amp;nbsp;performance,&amp;nbsp;all&amp;nbsp;I&amp;nbsp;know&amp;nbsp;is&amp;nbsp;that&amp;nbsp;they&amp;nbsp;seem&amp;nbsp;to&amp;nbsp;work&amp;nbsp;fine.&amp;nbsp;Perhaps&amp;nbsp;someone&amp;nbsp;can&amp;nbsp;provide&amp;nbsp;input&amp;nbsp;and&amp;nbsp;comments&amp;nbsp;on&amp;nbsp;that?&lt;br /&gt;&lt;br /&gt;Also&amp;nbsp;note&amp;nbsp;that&amp;nbsp;several&amp;nbsp;howtos&amp;nbsp;here&amp;nbsp;and&amp;nbsp;there&amp;nbsp;mention&amp;nbsp;both&amp;nbsp;&amp;quot;Microsoft-Server-ActiveSync&amp;quot;&amp;nbsp;and&amp;nbsp;&amp;quot;Exchange-Server-ActiveSync&amp;quot;,&amp;nbsp;but&amp;nbsp;apparently&amp;nbsp;&amp;quot;Microsoft-Server-ActiveSync&amp;quot;&amp;nbsp;ones&amp;nbsp;are&amp;nbsp;correct&amp;nbsp;(both&amp;nbsp;capitalisations).&lt;br /&gt;&lt;br /&gt;And&amp;nbsp;to&amp;nbsp;answer&amp;nbsp;your&amp;nbsp;question,&amp;nbsp;Bob:&amp;nbsp;I&amp;nbsp;created&amp;nbsp;two&amp;nbsp;virtual&amp;nbsp;servers,&amp;nbsp;A&amp;nbsp;records&amp;nbsp;and&amp;nbsp;certificates&amp;nbsp;because&amp;nbsp;every&amp;nbsp;guide&amp;nbsp;and&amp;nbsp;howto&amp;nbsp;afaik&amp;nbsp;state&amp;nbsp;that&amp;nbsp;AutoDiscover&amp;nbsp;needs&amp;nbsp;a&amp;nbsp;separate&amp;nbsp;one.&amp;nbsp;Sounds&amp;nbsp;legit,&amp;nbsp;so&amp;nbsp;I&amp;nbsp;simply&amp;nbsp;haven&amp;#39;t&amp;nbsp;tested&amp;nbsp;with&amp;nbsp;just&amp;nbsp;a&amp;nbsp;single&amp;nbsp;virtual&amp;nbsp;server&amp;nbsp;setup.&amp;nbsp;But&amp;nbsp;since&amp;nbsp;the&amp;nbsp;the&amp;nbsp;firewall&amp;nbsp;profiles&amp;nbsp;and&amp;nbsp;exceptions&amp;nbsp;in&amp;nbsp;my&amp;nbsp;setup&amp;nbsp;are&amp;nbsp;not&amp;nbsp;tuned&amp;nbsp;for&amp;nbsp;neither&amp;nbsp;security&amp;nbsp;or&amp;nbsp;performance&amp;nbsp;and&amp;nbsp;therefore&amp;nbsp;are&amp;nbsp;pretty&amp;nbsp;similar,&amp;nbsp;I&amp;nbsp;suppose&amp;nbsp;it&amp;#39;s&amp;nbsp;possible&amp;nbsp;to&amp;nbsp;set&amp;nbsp;up&amp;nbsp;and&amp;nbsp;get&amp;nbsp;it&amp;nbsp;to&amp;nbsp;work&amp;nbsp;with&amp;nbsp;just&amp;nbsp;a&amp;nbsp;single&amp;nbsp;server,&amp;nbsp;though.&lt;br /&gt;&lt;br /&gt;Thanks.&lt;br /&gt;MrOlrich&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF on v9.3 for Exchange 2013 on single server/IP/FQDN/certificate?</title><link>https://community.sophos.com/thread/185300?ContentTypeID=1</link><pubDate>Sat, 28 Mar 2015 16:47:12 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:92d671c6-61de-4de7-ba0c-f393d2f3a112</guid><dc:creator>BAlfson</dc:creator><description>Yes,&amp;nbsp;Please&amp;nbsp;do&amp;nbsp;post&amp;nbsp;your&amp;nbsp;settings.&amp;nbsp;&amp;nbsp;Did&amp;nbsp;you&amp;nbsp;create&amp;nbsp;two&amp;nbsp;Virtual&amp;nbsp;Servers&amp;nbsp;because&amp;nbsp;you&amp;nbsp;had&amp;nbsp;a&amp;nbsp;cert&amp;nbsp;that&amp;nbsp;you&amp;nbsp;could&amp;nbsp;use,&amp;nbsp;or&amp;nbsp;were&amp;nbsp;you&amp;nbsp;unable&amp;nbsp;to&amp;nbsp;get&amp;nbsp;it&amp;nbsp;to&amp;nbsp;work&amp;nbsp;with&amp;nbsp;a&amp;nbsp;single&amp;nbsp;one?&lt;br /&gt;&lt;br /&gt;Cheers&amp;nbsp;-&amp;nbsp;Bob&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF on v9.3 for Exchange 2013 on single server/IP/FQDN/certificate?</title><link>https://community.sophos.com/thread/185299?ContentTypeID=1</link><pubDate>Sat, 28 Mar 2015 11:37:32 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:083dafe5-661a-4fc9-a0a2-4e5806717da5</guid><dc:creator>MrOlrich</dc:creator><description>Hi,&amp;nbsp;and&amp;nbsp;thanks,&amp;nbsp;Bob.&lt;br /&gt;&lt;br /&gt;Just&amp;nbsp;to&amp;nbsp;clarify:&amp;nbsp;When&amp;nbsp;I&amp;nbsp;said&amp;nbsp;I&amp;nbsp;followed&amp;nbsp;Sophos&amp;#39;&amp;nbsp;&amp;quot;official&amp;nbsp;9.2&amp;nbsp;pdf&amp;nbsp;guide&amp;quot;,&amp;nbsp;I&amp;nbsp;meant&amp;nbsp;the&amp;nbsp;one&amp;nbsp;at&amp;nbsp;&lt;a href="http://sophserv.sophos.com/repo_kb/120454/file/Exchange%20WAF%20How%20to%209%202.pdf"&gt;http://sophserv.sophos.com/repo_kb/120454/file/Exchange%20WAF%20How%20to%209%202.pdf&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Anyway,&amp;nbsp;I&amp;nbsp;took&amp;nbsp;your&amp;nbsp;suggestion&amp;nbsp;and&amp;nbsp;got&amp;nbsp;it&amp;nbsp;to&amp;nbsp;work&amp;nbsp;with&amp;nbsp;two&amp;nbsp;virtual&amp;nbsp;servers,&amp;nbsp;one&amp;nbsp;for&amp;nbsp;Autodiscover&amp;nbsp;and&amp;nbsp;one&amp;nbsp;for&amp;nbsp;OWA+OA+AS.&amp;nbsp;(I&amp;nbsp;had&amp;nbsp;a&amp;nbsp;certificate&amp;nbsp;and&amp;nbsp;DNS&amp;nbsp;record&amp;nbsp;for&amp;nbsp;autodiscover.domain.com&amp;nbsp;pointing&amp;nbsp;to&amp;nbsp;the&amp;nbsp;same&amp;nbsp;server,&amp;nbsp;so&amp;nbsp;that&amp;#39;s&amp;nbsp;why&amp;nbsp;I&amp;nbsp;did&amp;nbsp;a&amp;nbsp;two-server&amp;nbsp;solution.)&amp;nbsp;I&amp;nbsp;even&amp;nbsp;got&amp;nbsp;Autodiscover&amp;nbsp;to&amp;nbsp;work,&amp;nbsp;externally&amp;nbsp;tested&amp;nbsp;both&amp;nbsp;Outlook&amp;nbsp;2013&amp;nbsp;and&amp;nbsp;an&amp;nbsp;Android&amp;nbsp;client,&amp;nbsp;and&amp;nbsp;both&amp;nbsp;smacked&amp;nbsp;right&amp;nbsp;in&amp;nbsp;place.&lt;br /&gt;&lt;br /&gt;Thank&amp;nbsp;you&amp;nbsp;for&amp;nbsp;your&amp;nbsp;hint,&amp;nbsp;really&amp;nbsp;appreciated.&amp;nbsp;Just&amp;nbsp;wishing&amp;nbsp;Sophos&amp;nbsp;would&amp;nbsp;keep&amp;nbsp;their&amp;nbsp;how-tos&amp;nbsp;up&amp;nbsp;to&amp;nbsp;date&amp;nbsp;with&amp;nbsp;the&amp;nbsp;UTM&amp;nbsp;versions.&lt;br /&gt;&lt;br /&gt;If&amp;nbsp;anyone&amp;nbsp;wants,&amp;nbsp;I&amp;nbsp;can&amp;nbsp;post&amp;nbsp;my&amp;nbsp;settings&amp;nbsp;here.&amp;nbsp;Just&amp;nbsp;let&amp;nbsp;me&amp;nbsp;know.&lt;br /&gt;&lt;br /&gt;Happy&amp;nbsp;weekend&amp;nbsp;and&amp;nbsp;things.&lt;br /&gt;MrOlrich&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF on v9.3 for Exchange 2013 on single server/IP/FQDN/certificate?</title><link>https://community.sophos.com/thread/185298?ContentTypeID=1</link><pubDate>Fri, 27 Mar 2015 16:44:10 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:9af54c11-6d4b-445d-a648-82cb6ec3b667</guid><dc:creator>BAlfson</dc:creator><description>If&amp;nbsp;you&amp;nbsp;have&amp;nbsp;only&amp;nbsp;a&amp;nbsp;single&amp;nbsp;server,&amp;nbsp;you&amp;nbsp;don&amp;#39;t&amp;nbsp;need&amp;nbsp;to&amp;nbsp;add&amp;nbsp;a&amp;nbsp;site-path&amp;nbsp;route.&amp;nbsp;&amp;nbsp;It&amp;nbsp;sounds&amp;nbsp;like&amp;nbsp;all&amp;nbsp;you&amp;nbsp;need&amp;nbsp;is&amp;nbsp;different&amp;nbsp;Exceptions&amp;nbsp;for&amp;nbsp;OWA,&amp;nbsp;Outlook&amp;nbsp;Anywhere&amp;nbsp;and&amp;nbsp;ActiveSync&amp;nbsp;after&amp;nbsp;having&amp;nbsp;configured&amp;nbsp;a&amp;nbsp;single&amp;nbsp;Filter&amp;nbsp;and&amp;nbsp;Virtual&amp;nbsp;Server.&amp;nbsp;&amp;nbsp;Instead&amp;nbsp;of&amp;nbsp;that&amp;nbsp;extract,&amp;nbsp;refer&amp;nbsp;to&amp;nbsp;the&amp;nbsp;complete&amp;nbsp;document&amp;nbsp;on&amp;nbsp;the&amp;nbsp;KnowledgeBase:&amp;nbsp;&lt;a href="https://sophserv.sophos.com/repo_kb/120454/file/Configuring%20UTM%20firewall%20for%20Exchange.pdf"&gt;How&amp;nbsp;to&amp;nbsp;configure&amp;nbsp;the&amp;nbsp;UTM&amp;nbsp;firewall&amp;nbsp;for&amp;nbsp;Microsoft&amp;nbsp;Exchange&amp;nbsp;connectivity&lt;/a&gt;.&amp;nbsp;&amp;nbsp;Any&amp;nbsp;luck&amp;nbsp;with&amp;nbsp;that?&lt;br /&gt;&lt;br /&gt;Cheers&amp;nbsp;-&amp;nbsp;Bob&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>