Vous êtes sur la page 1sur 8

3/23/2015

HowtopublishOWA/ActiveSync/OutlookAnywhere(Exchange2010)withMicrosoftForefrontTMGExchangewww.windowsnoob.com

www.windowsnoob.com servernoob Exchange

HowtopublishOWA/ActiveSync/OutlookAnywhere(Exchange2010)with
MicrosoftForefrontTMG
StartedbyAndersson,Jan16201107:24AM

Posted16January201107:24AM

Andersson

Published:20100301(ontestlabs.se/blog)
Updated:20100727
Version:1.1

Installation

ThiswillbeacompletewalkthroughtosetupupcertificatebasedonaCAserveronaDC.
Myenvironmentlookslikethis
1xWindows2003(DC/DNS/CA)
1xForefrontTMG
1xExchange2010CAS/HUB/MBX
EverythingisrunningasvirtualmachinesinVMwareWorkstation.
MyTMGserverisinstalledwithWindows2008R2x64with2Nics(E1000),runningwithaninternalNicsetup
IP:172.16.2.18
Subnet:255.255.255.0
DNS:172.16.2.11(pointingtotheDC)

http://www.windowsnoob.com/forums/index.php?/topic/3124howtopublishowaactivesyncoutlookanywhereexchange2010withmicrosoftforefronttmg/

1/8

3/23/2015

HowtopublishOWA/ActiveSync/OutlookAnywhere(Exchange2010)withMicrosoftForefrontTMGExchangewww.windowsnoob.com

(http://www.windowsnoob.com/forums/uploads/monthly_01_2011/post82160540404001295162860.png)
TheexternalNicissetupwith
IP:192.168.0.1
Subnet:255.255.255.0
DNS:ExternalIP
DefaultGateway:Pointingtomyexternalgateway
OntheTMGserverinthehostsfileIhaveediteditwithnotepadandpointedouttheCASserver
172.16.2.12owa.target.se

Justtogetthenameresolutionworkingfinewiththeruleandcertificate.
FirstthingtodoistoimportthecertificatethatisgeneratedfromtheCASserverinmycaseit'saCAserverontheDC
thatgeneratedthiscertificate.Bestpracticeistobuythecertificatefroma3rdpartthatistrustedrootinmostdevices
(godaddy.com,digicert.com,comodo.com,verisign.cometc).
Thecertificateimportiseasy,startammcconsoleandaddcertificatesforthelocalcomputer.
GotoPersonalandrightclick,chooseimportandpointatthefile.Whenit'sdoneitshouldlooklikebelow.

http://www.windowsnoob.com/forums/index.php?/topic/3124howtopublishowaactivesyncoutlookanywhereexchange2010withmicrosoftforefronttmg/

2/8

3/23/2015

HowtopublishOWA/ActiveSync/OutlookAnywhere(Exchange2010)withMicrosoftForefrontTMGExchangewww.windowsnoob.com

(http://www.windowsnoob.com/forums/uploads/monthly_01_2011/post82160582979001295162861.png)
NextstepistocreatetheWeblistener,itwillbedoneinTMGConsoleunderFirewallPolicy,chooseToolboxand
rightclickWebListenerstocreateanewweblistener.
Giveitafriendlyname,Icalledit"SSLListener",setituptorequireSSL,selectthesourceswhereitshouldlistento
trafficfrom.InmycaseIlistenonExternalandInternal,alsoselectaspecificIPaddressontheExternalandInternal
interface.Nextscreenselect'AssignacertificateforeachIPaddressandpointouttheimportedcertificate.
TheauthenticationsettingthatwillbeusediscalledHTMLFormAuthentication,makesurethatWindows(Active
Directory)isselected.
IntheSSO(SingleSignOn)typeinthe.domain.localifyouwanttousethefunction.
(OrelseyouwillneedtologontwotimesforusingtheOWA.)
Whenthecreatingiscompleteditshouldlooklikebelow.
Don'tforgettoapplythechanges.

(http://www.windowsnoob.com/forums/uploads/monthly_01_2011/post82160776795001295162862.png)

http://www.windowsnoob.com/forums/index.php?/topic/3124howtopublishowaactivesyncoutlookanywhereexchange2010withmicrosoftforefronttmg/

3/8

3/23/2015

HowtopublishOWA/ActiveSync/OutlookAnywhere(Exchange2010)withMicrosoftForefrontTMGExchangewww.windowsnoob.com
OWA
NextstepistocreatethepublishingruleitwillbedoneundertheTaskstabcalled'PublishExchangeWebClient
Access'.
Awizardwillstart,setupafriendlynamelikeOWA(Basic)andselecttheappropriateExchangeversion,inmycaseit's
Exchange2010.

(http://www.windowsnoob.com/forums/uploads/monthly_01_2011/post82160886786001295162863.png)
Selecttheoption'publishessingleserver'andrequireSSL.
Inthesettingregardinginternalsitename,giveittheexternalsitename(owa.target.se)andselecttheoptionbelow
andbrowsefortheCASserver.
Inthepublicname,giveityourexternalsitename(owa.target.se).
Nextthingittoselectthenewlycreatedweblistener,forauthenticationdelegationsettingsselectBasic
AuthenticationandfinallyAllAuthenticatedUsers.

OWARedirect

AniceonetocompletethepublishingoftheOWAistocreatea'PublishWebSites'ruleandsetittodeny,publishitas
asingleserverandrequireSSL.
Pointouttheinternalsitenametobetheexternalsitename(owa.target.se)andbrowsefortheCASserver.Inthe
pathselectionjusttype/aswillindicatethewholesite.
Forthepublicname,typeintheexternalsitename(inmycaseowa.target.se)towork.
Selecttheweblistenerandtheauthenticationmethodshouldbesetto'Nodelegation,andclientcannotauthenticate
directly'.RemovetheAllAuthenticatedUsersandreplaceitwithAllUsers.
Openuptheruleafteritiscreated,gototheActiontabandselecttheoption'RedirectHTTPrequeststothisweb
page'andtypein'https://owa.target.se/owa'.(https://owa.target.se/owa%27.)
ThisruleiscreatedsotheendusercanreachtheOWAwithouttypingin/owaintheaddressbar.
Nowthisiscompletedandshouldlooklikebelow.

http://www.windowsnoob.com/forums/index.php?/topic/3124howtopublishowaactivesyncoutlookanywhereexchange2010withmicrosoftforefronttmg/

4/8

3/23/2015

HowtopublishOWA/ActiveSync/OutlookAnywhere(Exchange2010)withMicrosoftForefrontTMGExchangewww.windowsnoob.com

(http://www.windowsnoob.com/forums/uploads/monthly_01_2011/post82160979385001295162864.png)

OutlookAnywhere
NexttodoistopublishOutlookAnywhere,itwillbedonethruthesamewizard.
SelecttheappropriateExchangeversionandthefunctionyouwanttopublish,inthiscaseit'stheOutlookAnywhere
(earliercalledRPCoverHTTP(s)

PublishingusingBasicAuthentication
JustlikethepublishingruleabovethisisasingleserverpublishingruleanditrequiresSSL.
Andpointouttheinternalsitenamelikebefore,itshouldbetheexternalsitename(owa.target.se)andbrowseforthe
CASserver.
Thepublicnameshouldbetheexternalsitename(owa.target.se).
Thenselecttheweblistenerthathasbeencreatedearlier.
Basicauthenticationisusedastheauthenticationmethod.
VerifythatthecorrectauthenticationmethodisselectedinExchangeManagementConsole(EMC),ifusingBasicit
shouldlooklikethis.

http://www.windowsnoob.com/forums/index.php?/topic/3124howtopublishowaactivesyncoutlookanywhereexchange2010withmicrosoftforefronttmg/

5/8

3/23/2015

HowtopublishOWA/ActiveSync/OutlookAnywhere(Exchange2010)withMicrosoftForefrontTMGExchangewww.windowsnoob.com

(http://www.windowsnoob.com/forums/uploads/monthly_01_2011/post82160758668001295162866.png)
Also,verifytherulesinTMGbyselectingtheruleandpress"TestRule"
Itshouldthenlooklikebelow,ifyouhaveanyissuesitwillgiveyoutheinfoincleartextlikeauthenticationmethodsis
notcorrectlyconfigured,likeamismatch.

(http://www.windowsnoob.com/forums/uploads/monthly_01_2011/post82160759356001295162867.png)
TimeforverificationsothepublishingruleworksforBasicAuthbyusingOutlookAnywherefunctionandtypingin
address:owa.target.sethatpointstoTMG.
Itseemstoworkfine

http://www.windowsnoob.com/forums/index.php?/topic/3124howtopublishowaactivesyncoutlookanywhereexchange2010withmicrosoftforefronttmg/

6/8

3/23/2015

HowtopublishOWA/ActiveSync/OutlookAnywhere(Exchange2010)withMicrosoftForefrontTMGExchangewww.windowsnoob.com

(http://www.windowsnoob.com/forums/uploads/monthly_01_2011/post82160612826001295162868.png)

ActiveSync

Thisisalmostthesameasabove,besidesActiveSyncwilluseBasicastheAuthenticationmethod.
SothenexttodoistopublishtheActiveSyncfunction,itwillbedonethruthesamewizard.
SelecttheappropriateExchangeversionandthefunctionyouwanttopublish,inthiscaseit'stheActiveSyncfunction.
JustlikethepublishingruleabovethisisasingleserverpublishingruleanditrequiresSSL.
Andpointouttheinternalsitenamelikebefore,itshouldbetheexternalsitename(webmail.testlabs.se)andbrowse
fortheCASserver.
Thepublicnameshouldbetheexternalsitename(webmail.testlabs.se).
Thenselecttheweblistenerthathasbeencreatedearlier.
Basicisusedastheauthenticationmethod.

Sometimesintestingpurposesyouneedtoturnofspoofdetection,orelseitwillnotwork.
Ihavehadthatproblem,ifyouneedtoturnitoff,checkthislink

http://www.windowsnoob.com/forums/index.php?/topic/3124howtopublishowaactivesyncoutlookanywhereexchange2010withmicrosoftforefronttmg/

7/8

3/23/2015

HowtopublishOWA/ActiveSync/OutlookAnywhere(Exchange2010)withMicrosoftForefrontTMGExchangewww.windowsnoob.com
http://support.microsoft.com/kb/838114(http://support.microsoft.com/kb/838114)
Copyandpastefromthelinkabove
ClickStart,clickRun,typeregedit,andthenclickOK.
Locateandthenclickthefollowingregistrysubkey:
HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/FwEng/Parameters

IftheParameterssubkeyisnotdisplayed,followthesestepstocreatethissubkey:
ClicktheFwEngsubkey.
OntheEditmenu,pointtoNew,andthenclickKey.
Tonamethekey,typeParameters,andthenpressENTER.
RightclickParameters,pointtoNew,andthenclickDWORDValue.
Tonamethevalue,typeDisableSpoofDetection,andthenpressENTER.
RightclickDisableSpoofDetection,andthenclickModify.
IntheValuedatabox,type1,andthenclickOK.

BacktoExchange

www.windowsnoob.com servernoob Exchange

http://www.windowsnoob.com/forums/index.php?/topic/3124howtopublishowaactivesyncoutlookanywhereexchange2010withmicrosoftforefronttmg/

8/8

Vous aimerez peut-être aussi