<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Exchange Server Pro &#187; OWA</title>
	<atom:link href="http://exchangeserverpro.com/tag/owa/feed" rel="self" type="application/rss+xml" />
	<link>http://exchangeserverpro.com</link>
	<description>Microsoft Exchange Server News - Tips - Tutorials</description>
	<lastBuildDate>Wed, 23 May 2012 11:55:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available</title>
		<link>http://exchangeserverpro.com/owa-error-mailbox-trying-access-not-currently-available</link>
		<comments>http://exchangeserverpro.com/owa-error-mailbox-trying-access-not-currently-available#comments</comments>
		<pubDate>Wed, 07 Sep 2011 12:07:25 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[Solutions]]></category>
		<category><![CDATA[Co-Existence]]></category>
		<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[Migration]]></category>
		<category><![CDATA[OWA]]></category>

		<guid isPermaLink="false">http://exchangeserverpro.com/?p=4020</guid>
		<description><![CDATA[Exchange 2007 Outlook Web Access users may receive an error when connecting to OWA after Exchange 2010 is installed.]]></description>
			<content:encoded><![CDATA[<p>During the co-existence phase of an <a href="http://exchangeserverpro.com/exchange-2007-2010-migration-guide">Exchange 2007 to 2010 migration</a>, when you have cut over your <a href="http://exchangeserverpro.com/publish-outlook-web-app-isa-server-2006">ISA Server publishing rules for Outlook Web App</a> to point to the <a href="http://exchangeserverpro.com">Exchange 2010</a> Client Access server, you may encounter the following error for some OWA users.</p>
<blockquote><p>The mailbox you&#8217;re trying to access isn&#8217;t currently available. If the problem continues, contact your helpdesk.</p></blockquote>
<p>Depending on your Exchange environment you may find that this is only occurring for some users and not all of them. In particular you may find that Exchange 2007 mailbox users in remote AD sites are receiving the error, but Exchange 2007 mailbox users in the internet-facing AD site are not.</p>
<p>This can occur because of how the <a title="Exchange 2010 FAQ: What are the Exchange Server 2010 Server Roles?" href="http://exchangeserverpro.com/exchange-2010-server-roles">Client Access servers</a> handle OWA traffic differently, depending on which AD site the mailbox user is in.</p>
<p>For the internet-facing AD site the scenarios are simply as follows.</p>
<p><strong>Exchange 2010 Mailbox user:</strong></p>
<ol>
<li>Connects to published name for Outlook Web App</li>
<li>The internet-facing Exchange 2010 CAS connects to the mailbox server in that site on behalf of the user</li>
</ol>
<p><strong>Exchange 2007 Mailbox user:</strong></p>
<ol>
<li>Connects to the published name for Outlook Web App</li>
<li>The internet-facing Exchange 2010 CAS redirects them to the legacy namespace, which is published to the internet-facing Exchange 2007 CAS</li>
<li>The Exchange 2007 CAS connects to the mailbox server in that site on behalf of the user</li>
</ol>
<p><img class="aligncenter size-large wp-image-4021" title="exchange-2007-2010-migration-redirection-1" src="http://exchangeserverpro.com/wp-content/uploads/2011/09/exchange-2007-2010-migration-redirection-1-600x284.jpg" alt="" width="600" height="284" /><br />
For mailbox users in remote AD sites the situation is slightly different.</p>
<p><strong>Exchange 2010 Mailbox user:</strong></p>
<ol>
<li>Connects to published name for Outlook Web App</li>
<li>The internet-facing CAS proxies the connection to an Exchange 2010 CAS in the remote AD site</li>
<li>The Exchange 2010 CAS in the remote AD site connects to the mailbox server in that site on behalf of the user</li>
</ol>
<p><strong>Exchange 2007 Mailbox user:</strong></p>
<ol>
<li>Connects to the published name for Outlook Web App</li>
<li>The internet-facing CAS proxies the connection to an Exchange 2007 CAS in the remote AD site</li>
<li>The Exchange 2007 CAS in the remote AD site connects to the mailbox server in that site on behalf of the user</li>
</ol>
<p><img class="aligncenter size-large wp-image-4022" title="exchange-2007-2010-migration-redirection-2" src="http://exchangeserverpro.com/wp-content/uploads/2011/09/exchange-2007-2010-migration-redirection-2-600x180.jpg" alt="" width="600" height="180" /></p>
<p>For this to work correctly there are a few configuration requirements.</p>
<ul>
<li>The OWA virtual directories on the Client Access servers in the remote AD site must have <a href="http://exchangeserverpro.com/exchange-server-2010-outlook-web-app-authentication-settings">Integrated Windows authentication</a> enabled</li>
<li>The OWA virtual directories on the Client Access servers in the remote AD site must not have an external URL configured (it should be blank)</li>
<li>The internet-facing Exchange 2010 CAS needs a copy of the OWA resources files from any down-version Client Access servers it will be proxying to</li>
</ul>
<p>Often people get the first two correct and leave out the third one. However without meeting that third requirement you will receive the error shown at the start of this article. On the internet-facing Exchange 2010 CAS you&#8217;ll also see an event ID 46 logged in the Application Event Log, with details similar to the following:</p>
<blockquote><p>Log Name: Application<br />
Source: MSExchange OWA<br />
Date: 9/6/2011 11:42:35 PM<br />
Event ID: 46<br />
Task Category: Proxy<br />
Level: Error<br />
Keywords: Classic<br />
User: N/A<br />
Computer: HO-EX2010-CAHT1.exchangeserverpro.net<br />
Description:<br />
Client Access server &#8220;https://mail.exchangeserverpro.net/owa&#8221;, running Exchange version &#8220;14.1.323.3&#8243;, is proxying Outlook Web App traffic to Client Access server &#8220;br-ex2007-caht.exchangeserverpro.net&#8221;, which runs Exchange version &#8220;8.3.83.4&#8243;. To ensure reliable interoperability, the proxying Client Access server needs to be running a newer version of Exchange than the Client Access server it is proxying to. If the proxying Client Access server is running a newer version of Exchange than the Client Access server it is proxying to, the proxying Client Access server needs to have an Outlook Web App resource folder (for example, &#8220;&lt;Exchange Server installation path&gt;)\ClientAccess\owa\8.0.498.0&#8243; that contains all the same versioned resource files as the Client Access server it is proxying to. If you will be running Outlook Web App proxying with mismatched server versions, you can manually copy this resource folder to the proxying Client Access server. After you copy this resource folder to the proxying Client Access server, you need to restart IIS before proxying will work.</p></blockquote>
<p>To resolve this issue you simply follow the instructions in the error. Copy the OWA resource files from a down-version Client Access server over to the Exchange 2010 CAS, and then restart IIS on the Exchange 2010 CAS.</p>
<p><img class="aligncenter size-large wp-image-4023" title="cas-proxy-owa-resource" src="http://exchangeserverpro.com/wp-content/uploads/2011/09/cas-proxy-owa-resource-600x396.jpg" alt="" width="600" height="396" /></p>
<p>You&#8217;ll find the folder name matching the server version (eg 8.3.83.4 above) in the location where Exchange is installed, for example <strong>C:\Program Files\Microsoft\Exchange Server\ClientAccess\OWA</strong>.</p>
<p>After copying the files run IISReset from a command prompt.</p>
<pre>[PS] C:\Windows\system32&gt;iisreset

Attempting stop...
Internet services successfully stopped
Attempting start...
Internet services successfully restarted</pre>
<p>Outlook Web App should now work successfully for all users regardless of which site their mailbox is located.</p>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/exchange-2010-online-mailbox-moves" title="Exchange 2010 FAQ: How to Minimise Downtime During Mailbox Migration from Exchange 2007">Exchange 2010 FAQ: How to Minimise Downtime During Mailbox Migration from Exchange 2007</a></li><li><a href="http://exchangeserverpro.com/exchange-server-2007-2010-migration-guide" title="The Exchange Server 2007 to 2010 Migration Guide is Available Now">The Exchange Server 2007 to 2010 Migration Guide is Available Now</a></li><li><a href="http://exchangeserverpro.com/exchange-2003-2010-coexistence" title="Configuring Co-Existence for Exchange 2003 and Exchange 2010">Configuring Co-Existence for Exchange 2003 and Exchange 2010</a></li><li><a href="http://exchangeserverpro.com/exchange-2010-direct-migration-2003-2010-or-2007" title="Exchange 2010 FAQ: Is Direct Exchange Migration from 2003 to 2010 Possible Without Upgrading to 2007?">Exchange 2010 FAQ: Is Direct Exchange Migration from 2003 to 2010 Possible Without Upgrading to 2007?</a></li><li><a href="http://exchangeserverpro.com/exchange-2007-exchange-2010-hub-transport-servers" title="Exchange 2010 FAQ: Can I Replace Exchange 2007 Hub Transport Servers with Exchange 2010?">Exchange 2010 FAQ: Can I Replace Exchange 2007 Hub Transport Servers with Exchange 2010?</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/owa-error-mailbox-trying-access-not-currently-available">OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available</a> is © 2011 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/owa-error-mailbox-trying-access-not-currently-available/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>500 Internal Server Error for Exchange 2007 Outlook Web Access</title>
		<link>http://exchangeserverpro.com/500-internal-server-error-exchange-2007-outlook-web-access</link>
		<comments>http://exchangeserverpro.com/500-internal-server-error-exchange-2007-outlook-web-access#comments</comments>
		<pubDate>Fri, 05 Aug 2011 11:36:52 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[Solutions]]></category>
		<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[OWA]]></category>

		<guid isPermaLink="false">http://exchangeserverpro.com/?p=3890</guid>
		<description><![CDATA[Exchange users may encounter a 500 Internal Error when access Outlook Web Access.]]></description>
			<content:encoded><![CDATA[<p>In an Exchange Server 2007 environment you may encounter the following error when users attempt to access Outlook Web Access.</p>
<blockquote><p>500 &#8211; Internal server error.</p>
<p>There is a problem with the resource you are looking for, and it cannot be displayed.</p></blockquote>
<p><img class="aligncenter size-full wp-image-3891" title="exchange-2007-owa-500-error-01" src="http://exchangeserverpro.com/wp-content/uploads/2011/08/exchange-2007-owa-500-error-01.png" alt="" width="590" height="110" /></p>
<p>The error occurs when user access OWA via the <strong>/exchange</strong> path but not the <strong>/owa</strong>. For example:</p>
<ul>
<li>https://mail.company.net/owa (gets no error)</li>
<li>https://mail.company.net/exchange (gets the 500 internal error)</li>
</ul>
<p>This can occur when the Exchange 2007 Mailbox server is missing the Web-ISAPI-Ext feature. You can check this by logging on to the server and running this command:</p>
<pre>C:\&gt;servermanagercmd -q | findstr "Web-ISAPI-Ext"
            [ ] ISAPI Extensions  [Web-ISAPI-Ext]</pre>
<p>If there is no check mark next to the feature then it will need to be installed by running the following command:</p>
<pre>C:\&gt;servermanagercmd -i web-isapi-ext
..

Start Installation...

[Installation] Succeeded: .
[Installation] Succeeded: [Web Server (IIS)] Application Development.
[Installation] Succeeded: [Web Server (IIS)] ISAPI Extensions.

Success: Installation succeeded.</pre>
<p>When you check the status of the feature it will now show as installed.</p>
<pre>C:\&gt;servermanagercmd -q | findstr "Web-ISAPI-Ext"
            [X] ISAPI Extensions  [Web-ISAPI-Ext]</pre>
<p>That should resolve the &#8220;500 internal error&#8221; when accessing OWA via the /exchange path.</p>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/exchange-2007-owa-stops-working-with-reason0-error" title="Exchange 2007 OWA stops working with &ldquo;reason=0&rdquo; error">Exchange 2007 OWA stops working with &ldquo;reason=0&rdquo; error</a></li><li><a href="http://exchangeserverpro.com/owa-error-mailbox-trying-access-not-currently-available" title="OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available">OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available</a></li><li><a href="http://exchangeserverpro.com/exchange-remote-connectivity-analyzer-updated" title="Exchange Remote Connectivity Analyzer Updated">Exchange Remote Connectivity Analyzer Updated</a></li><li><a href="http://exchangeserverpro.com/publish-exchange-server-2007-owa-using-isa-server-2006" title="Publish Exchange Server 2007 OWA Using ISA Server 2006">Publish Exchange Server 2007 OWA Using ISA Server 2006</a></li><li><a href="http://exchangeserverpro.com/migrate-ssl-certificates-from-exchange-server-2003-to-exchange-server-2007" title="Migrate SSL Certificates from Exchange Server 2003 to Exchange Server 2007">Migrate SSL Certificates from Exchange Server 2003 to Exchange Server 2007</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/500-internal-server-error-exchange-2007-outlook-web-access">500 Internal Server Error for Exchange 2007 Outlook Web Access</a> is © 2011 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/500-internal-server-error-exchange-2007-outlook-web-access/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exchange Server 2010 Error: Outlook Web App Didn&#8217;t Initialize</title>
		<link>http://exchangeserverpro.com/exchange-server-2010-error-outlook-web-app-initialize</link>
		<comments>http://exchangeserverpro.com/exchange-server-2010-error-outlook-web-app-initialize#comments</comments>
		<pubDate>Thu, 12 May 2011 13:27:33 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[Solutions]]></category>
		<category><![CDATA[Client Access]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[OWA]]></category>

		<guid isPermaLink="false">http://exchangeserverpro.com/?p=3437</guid>
		<description><![CDATA[When connecting to OWA for Exchange Server 2010 users may report an error that Outlook Web App didn't initialize.]]></description>
			<content:encoded><![CDATA[<p>When connecting to Outlook Web App (OWA) for Exchange Server 2010 users may report the following error in their web browser.</p>
<blockquote><p>Outlook Web App didn&#8217;t initialize. If the problem continues, please contact your helpdesk.<br />
Couldn&#8217;t find a base theme (folder name=base)</p></blockquote>
<p>This can be caused by missing OWA theme files in <strong>\ClientAccess\Owa\14.1.287.0\themes</strong> sub-folder of the Exchange 2010 installation path.  By default this is <strong>C:\Program Files\Microsoft\Exchange Server\V14\ClientAccess\Owa\14.1.287.0\themes.</strong></p>
<p><strong><img class="aligncenter size-full wp-image-3438" title="exchange-2010-owa-theme-empty" src="http://exchangeserverpro.com/wp-content/uploads/2011/05/exchange-2010-owa-theme-empty.png" alt="" width="600" height="173" /><br />
</strong></p>
<p>To resolve the error you can perform a restore of the files to the <a title="Exchange 2010 FAQ: What are the Exchange Server 2010 Server Roles?" href="http://exchangeserverpro.com/exchange-2010-server-roles">Client Access server</a> from a previous <a title="Exchange Server 2010 Client Access Server Backup and Recovery" href="http://exchangeserverpro.com/exchange-server-2010-client-access-server-backup-and-recovery">backup</a>.</p>
<p>If that is not available to you then you can also restore the files by re-running Exchange Server 2010 SP1 setup in upgrade mode.</p>
<pre>C:\Admin\Exchange2010SP1&gt;setup /m:upgrade

Welcome to Microsoft Exchange Server 2010 Unattended Setup

Preparing Exchange Setup

    Copying Setup Files                           COMPLETED

The following server roles will be upgraded
Languages
Hub Transport Role
Client Access Role
Management Tools

Performing Microsoft Exchange Server Prerequisite Check

    Configuring Prerequisites                                 COMPLETED
    Language Pack Checks                                      COMPLETED
    Hub Transport Role Checks                                 COMPLETED
    Client Access Role Checks                                 COMPLETED

Configuring Microsoft Exchange Server

    Language Files                                            COMPLETED
    Restoring Services                                        COMPLETED
    Languages                                                 COMPLETED
    Hub Transport Server Role                                 COMPLETED
    Client Access Server Role                                 COMPLETED
    Exchange Management Tools                                 COMPLETED
    Finalizing Setup                                          COMPLETED

The Microsoft Exchange Server setup operation completed successfully.</pre>
<p>You should now see the restored files in the correct location, and OWA will begin working again.</p>
<p><img class="aligncenter size-full wp-image-3439" title="exchange-2010-owa-theme-restored" src="http://exchangeserverpro.com/wp-content/uploads/2011/05/exchange-2010-owa-theme-restored.png" alt="" width="600" height="274" /></p>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/exchange-server-2010-outlook-web-app-authentication-settings" title="Exchange Server 2010 Outlook Web App Authentication Settings">Exchange Server 2010 Outlook Web App Authentication Settings</a></li><li><a href="http://exchangeserverpro.com/exchange-server-2010-cas-array" title="Getting Started with Exchange Server 2010 Client Access Server Arrays">Getting Started with Exchange Server 2010 Client Access Server Arrays</a></li><li><a href="http://exchangeserverpro.com/iis-6-wmi-compatibility-component-required-exchange-2010-sp2-upgrade" title="Error Message &#8220;The &#8216;IIS 6 WMI Compatibility&#8217; component is required&#8221; During Exchange 2010 SP2 Upgrade">Error Message &#8220;The &#8216;IIS 6 WMI Compatibility&#8217; component is required&#8221; During Exchange 2010 SP2 Upgrade</a></li><li><a href="http://exchangeserverpro.com/exchange-2010-online-mailbox-moves" title="Exchange 2010 FAQ: How to Minimise Downtime During Mailbox Migration from Exchange 2007">Exchange 2010 FAQ: How to Minimise Downtime During Mailbox Migration from Exchange 2007</a></li><li><a href="http://exchangeserverpro.com/owa-error-mailbox-trying-access-not-currently-available" title="OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available">OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/exchange-server-2010-error-outlook-web-app-initialize">Exchange Server 2010 Error: Outlook Web App Didn&#8217;t Initialize</a> is © 2011 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/exchange-server-2010-error-outlook-web-app-initialize/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>How to Publish Outlook Web App with ISA Server 2006</title>
		<link>http://exchangeserverpro.com/publish-outlook-web-app-isa-server-2006</link>
		<comments>http://exchangeserverpro.com/publish-outlook-web-app-isa-server-2006#comments</comments>
		<pubDate>Sun, 03 Apr 2011 13:11:17 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[ISA 2006]]></category>
		<category><![CDATA[OWA]]></category>

		<guid isPermaLink="false">http://exchangeserverpro.com/?p=3202</guid>
		<description><![CDATA[This tutorial demonstrates the step by step process for how to publish Exchange Server 2010 Outlook Web App (OWA) using ISA Server 2006.]]></description>
			<content:encoded><![CDATA[<p>One way to make Exchange Server 2010 Outlook Web App (OWA) available for remote users is to publish it using ISA Server 2006.  There are several parts of this solution that make it work.</p>
<ul>
<li>A public DNS name for Outlook Web App (in this example mail.exchangeserverpro.net is used)</li>
<li>An ISA Server 2006 (with Service Pack 1) firewall configured with an external interface and IP address corresponding to the above DNS record</li>
<li>An <a href="http://exchangeserverpro.com/exchange-2010-ssl-certificates">SSL certificate for Exchange Server 2010</a></li>
<li>Exchange 2010 <a title="Exchange 2010 FAQ: What are the Exchange Server 2010 Server Roles?" href="http://exchangeserverpro.com/exchange-2010-server-roles">Client Access and Mailbox servers</a> deployed in the organization</li>
</ul>
<p>This diagram provides an overview of how Outlook Web App is published using ISA Server 2006.  The remote user makes a connection over HTTPS (SSL) to the ISA firewall, which then reverse proxies the traffic over SSL to the Client Access server.  The Client Access server is then responsible for proxying the requests for the user&#8217;s mailbox to the appropriate Mailbox server using RPC connections.</p>
<p><img class="aligncenter size-full wp-image-3203" title="exchange-2010-publish-owa-isa-2006" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006.png" alt="" width="600" height="217" /></p>
<h2>Configuring the Exchange 2010 Client Access Server</h2>
<p>In this example the <strong>/OWA</strong> virtual directory on the Client Access server is configured for both Basic and Integrated authentication.  This combination allows internal, domain-joined computers to seamlessly log on to Outlook Web App while also permitting the ISA server to use Basic delegation to authenticate the remote user.</p>
<p><img class="aligncenter size-full wp-image-3204" title="exchange-2010-owa-authentication" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-owa-authentication.png" alt="" width="444" height="164" /></p>
<p>For more details see this article on <a href="http://exchangeserverpro.com/exchange-server-2010-outlook-web-app-authentication-settings">how to configure Outlook Web App authentication</a>.</p>
<p>The Client Access server <strong>/OWA</strong> virtual directory has also been configured with the external URL to match the public DNS name.</p>
<p><img class="aligncenter size-full wp-image-3205" title="exchange-2010-owa-external-url" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-owa-external-url.png" alt="" width="444" height="351" /></p>
<p>The Client Access server also needs to be <a href="http://exchangeserverpro.com/configure-an-ssl-certificate-for-exchange-server-2010">configured with an SSL certificate</a>.  Preferably this SSL certificate is from a <a href="http://exchangeserverpro.com/exchange-server-2010-and-the-benefits-of-commercial-ssl-certificates">public certificate authority</a> but it can also be a <a href="http://exchangeserverpro.com/how-to-issue-a-san-certificate-to-exchange-server-2010-from-a-private-certificate-authority">private CA</a>, as long as it is one that the ISA server trusts so that ISA considers the certificate to be valid.  You can of course import root certificates to make just about any certificate trusted by ISA but it is less effort and a better overall solution to use a public CA.</p>
<h2>Configuring the ISA Server SSL Certificate</h2>
<p>The ISA server needs to be configured with an SSL certificate to accept the secure remote access connections.  Although you can issue the server with its own certificate for this purpose you could also export the SSL certificate from the Client Access server and import it to the ISA server, provided that the license terms your issuing CA allow for that.  <a href="http://www.digicert.com/unified-communications-ssl-tls.htm">Digicert</a> is an example of a CA that allows certificates to be installed on multiple servers.</p>
<p>For more details see this article on <a href="http://exchangeserverpro.com/export-an-exchange-server-2010-certificate-to-exchange-2003">exporting an SSL certificate from Exchange 2010</a> (note that it refers to importing it for Exchange 2003 but the steps are the same for importing to an ISA Server 2006 firewall running on Windows Server 2003).</p>
<h2>Configuring the ISA Server Publishing Rule for Outlook Web App</h2>
<p>In the ISA Server Management console right-click the <strong>Firewall Policy</strong> and choose <strong>New -&gt; Exchange Web Client Access Publishing Rule</strong>.</p>
<p><img class="aligncenter size-full wp-image-3206" title="exchange-2010-publish-owa-isa-2006-rule-01" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-01.png" alt="" width="512" height="261" /></p>
<p>Give the new rule a name and click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3207" title="exchange-2010-publish-owa-isa-2006-rule-02" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-02.png" alt="" width="376" height="105" /></p>
<p>Set the Exchange version to <strong>Exchange Server 2007</strong> (yes this is correct for Exchange 2010 publishing) and tick the box for <strong>Outlook Web Access</strong>, then click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3208" title="exchange-2010-publish-owa-isa-2006-rule-03" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-03.png" alt="" width="461" height="133" /></p>
<p>In this case a single server is being published. Click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3209" title="exchange-2010-publish-owa-isa-2006-rule-04" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-04.png" alt="" width="432" height="103" /></p>
<p>Enter the internal site name for OWA (in this case mail.exchangeserverpro.net), and optionally enter a computer name or IP address for ISA to connect to if the internal site name does not resolve in the internal DNS zone.  Click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3210" title="exchange-2010-publish-owa-isa-2006-rule-06" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-06.png" alt="" width="503" height="467" /></p>
<p>Configure the public names that this rule should accept connections for and click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3220" title="exchange-2010-publish-owa-isa-2006-rule-07-b" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-07-b.png" alt="" width="469" height="122" /></p>
<p>&nbsp;</p>
<p>Now we need to configure a web listener to accept the remote user connections.  Click on the <strong>New</strong> button.</p>
<p><img class="aligncenter size-full wp-image-3212" title="exchange-2010-publish-owa-isa-2006-rule-08" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-08.png" alt="" width="503" height="267" /></p>
<p>Give the new web listener a name and click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3213" title="exchange-2010-publish-owa-isa-2006-rule-09" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-09.png" alt="" width="364" height="106" /></p>
<p>Leave the default choice to require SSL and click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3214" title="exchange-2010-publish-owa-isa-2006-rule-10" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-10.png" alt="" width="455" height="99" /></p>
<p>Select the External interface for the web listener to listen on.  If your External interface has multiple IP addresses you can configure the web listener to listen on all, some, or just one of those IP addresses.  Click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3215" title="exchange-2010-publish-owa-isa-2006-rule-11" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-11.png" alt="" width="457" height="211" /></p>
<p>Click on the <strong>Select Certificates</strong> button.</p>
<p><img class="aligncenter size-full wp-image-3216" title="exchange-2010-publish-owa-isa-2006-rule-12" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-12.png" alt="" width="468" height="127" /></p>
<p>A list of valid certificates will appear, which should include the one you imported to the server earlier.  Choose that certificate and click the <strong>Select</strong> button, then click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3217" title="exchange-2010-publish-owa-isa-2006-rule-13" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-13.png" alt="" width="587" height="117" /></p>
<p>Leave the authentication set to <strong>HTML Form Authentication</strong> and <strong>Windows (Active Directory)</strong>.  Note this assumes your ISA server is joined to the domain, otherwise you can configure LDAP authentication.  Click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3218" title="exchange-2010-publish-owa-isa-2006-rule-14" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-14.png" alt="" width="488" height="303" /></p>
<p>Single Sign-On is useful but optional.  Click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3219" title="exchange-2010-publish-owa-isa-2006-rule-15" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-15.png" alt="" width="460" height="171" /></p>
<p>Click <strong>Finish</strong> to complete the new web listener wizard.  If there are no warnings or errors displayed click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3221" title="exchange-2010-publish-owa-isa-2006-rule-16" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-16.png" alt="" width="464" height="184" /></p>
<p>Leave the authentication delegation set to Basic Authentication and click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3222" title="exchange-2010-publish-owa-isa-2006-rule-17" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-17.png" alt="" width="462" height="176" /></p>
<p>Leave the users set to All Authenticated Users and click <strong>Next</strong> to continue.</p>
<p><img class="aligncenter size-full wp-image-3223" title="exchange-2010-publish-owa-isa-2006-rule-18" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-18.png" alt="" width="469" height="129" /></p>
<p>Before you click Finish to create the new rule first click on the <strong>Test Rule</strong> button to validate the settings you chose.</p>
<p><img class="aligncenter size-full wp-image-3224" title="exchange-2010-publish-owa-isa-2006-rule-19" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-19.png" alt="" width="503" height="467" /></p>
<p>If the tests are all successful click on <strong>Close</strong> and then <strong>Finish</strong> to create the rule.</p>
<p><img class="aligncenter size-full wp-image-3225" title="exchange-2010-publish-owa-isa-2006-rule-20" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-20.png" alt="" width="368" height="116" /></p>
<p>Before applying the changes to the Firewall Policy double-click the new rule to open its properties.  Select the <strong>Paths</strong> tab and then click <strong>Add</strong>.</p>
<p><img class="aligncenter size-full wp-image-3226" title="exchange-2010-publish-owa-isa-2006-rule-21" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-21.png" alt="" width="404" height="253" /></p>
<p>Add the Exchange Control Panel virtual directory path of <strong>/ecp/*</strong> and then click <strong>OK</strong> and <strong>OK</strong> again.</p>
<p><img class="aligncenter size-full wp-image-3227" title="exchange-2010-publish-owa-isa-2006-rule-22" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-22.png" alt="" width="374" height="279" /></p>
<p>Now click <strong>Apply</strong> to commit the changes to the Firewall Policy.</p>
<p><img class="aligncenter size-full wp-image-3228" title="exchange-2010-publish-owa-isa-2006-rule-23" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-rule-23.png" alt="" width="490" height="104" /></p>
<h2>Testing the ISA Server 2006 Publishing Rule for Outlook Web App</h2>
<p>Now that the rule has been configured we can test it from outside of the firewall using a web browser.  When the remote user first connects to the Outlook Web App URL they will see the Exchange 2007 style log on form that ISA 2006 renders.</p>
<p><img class="aligncenter size-full wp-image-3230" title="exchange-2010-publish-owa-isa-2006-logon" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-logon.png" alt="" width="410" height="322" /></p>
<p>However after logging in the Exchange Server 2010 Outlook Web App interface will be available to the remote user.</p>
<p><img class="aligncenter size-full wp-image-3231" title="exchange-2010-publish-owa-isa-2006-logon-2" src="http://exchangeserverpro.com/wp-content/uploads/2011/04/exchange-2010-publish-owa-isa-2006-logon-2.png" alt="" width="590" height="209" /></p>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/owa-error-mailbox-trying-access-not-currently-available" title="OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available">OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available</a></li><li><a href="http://exchangeserverpro.com/exchange-server-2010-error-outlook-web-app-initialize" title="Exchange Server 2010 Error: Outlook Web App Didn&#8217;t Initialize">Exchange Server 2010 Error: Outlook Web App Didn&#8217;t Initialize</a></li><li><a href="http://exchangeserverpro.com/exchange-2010-edge-transport-server-configuring-edgesync" title="Exchange 2010 Edge Transport Server: Configuring EdgeSync">Exchange 2010 Edge Transport Server: Configuring EdgeSync</a></li><li><a href="http://exchangeserverpro.com/publishing-exchange-2010-pop3-isa-server-2006" title="Publishing Exchange 2010 POP3 with ISA Server 2006">Publishing Exchange 2010 POP3 with ISA Server 2006</a></li><li><a href="http://exchangeserverpro.com/exchange-2010-owa-legacy-url-redirection-http-500-error" title="Exchange 2010 OWA Legacy URL Redirection HTTP 500 Error">Exchange 2010 OWA Legacy URL Redirection HTTP 500 Error</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/publish-outlook-web-app-isa-server-2006">How to Publish Outlook Web App with ISA Server 2006</a> is © 2011 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/publish-outlook-web-app-isa-server-2006/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Exchange 2010 OWA Legacy URL Redirection HTTP 500 Error</title>
		<link>http://exchangeserverpro.com/exchange-2010-owa-legacy-url-redirection-http-500-error</link>
		<comments>http://exchangeserverpro.com/exchange-2010-owa-legacy-url-redirection-http-500-error#comments</comments>
		<pubDate>Wed, 05 Jan 2011 13:40:10 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[Solutions]]></category>
		<category><![CDATA[Exchange 2003]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[Legacy URL]]></category>
		<category><![CDATA[Migration]]></category>
		<category><![CDATA[OWA]]></category>
		<category><![CDATA[Transition]]></category>

		<guid isPermaLink="false">http://exchangeserverpro.com/?p=2606</guid>
		<description><![CDATA[During the co-existence period of a transition from Exchange Server 2003 to Exchange Server 2010 you may encounter an issue with the legacy Outlook Web Access URL redirection.]]></description>
			<content:encoded><![CDATA[<p>During the co-existence period of a transition from Exchange Server 2003 to Exchange Server 2010 you may encounter an issue with the legacy Outlook Web Access URL redirection.</p>
<p>When users connect to the Exchange 2010 Client Access server for OWA login they receive a second login prompt for the legacy URL.</p>
<div id="attachment_2607" class="wp-caption aligncenter" style="width: 439px"><img class="size-full wp-image-2607" title="Authentication prompt when accessing OWA legacy URL" src="http://exchangeserverpro.com/wp-content/uploads/2011/01/exchange-2010-legacy-url-authentication-prompt.png" alt="Authentication prompt when accessing OWA legacy URL" width="429" height="243" /><p class="wp-caption-text">Authentication prompt when accessing OWA legacy URL</p></div>
<p>No matter which credentials are entered into this authentication dialog box the login is not successful, and a HTTP 500 error is displayed.</p>
<div id="attachment_2608" class="wp-caption aligncenter" style="width: 510px"><img class="size-full wp-image-2608" title="HTTP 500 error accessing OWA legacy URL" src="http://exchangeserverpro.com/wp-content/uploads/2011/01/exchange-2010-legacy-url-http-500-error.png" alt="HTTP 500 error accessing OWA legacy URL" width="500" height="321" /><p class="wp-caption-text">HTTP 500 error accessing OWA legacy URL</p></div>
<p>The solution is to enable forms-based authentication on the Exchange 2003 front-end server.  This is located in the <strong>Properties</strong> of the <strong>Exchange Virtual Server</strong>.</p>
<div id="attachment_2609" class="wp-caption aligncenter" style="width: 582px"><img class="size-full wp-image-2609" title="Open the Properties of the Exchange Virtual Server" src="http://exchangeserverpro.com/wp-content/uploads/2011/01/exchange-2003-enable-forms-based-authentication-01.png" alt="Open the Properties of the Exchange Virtual Server" width="572" height="493" /><p class="wp-caption-text">Open the Properties of the Exchange Virtual Server</p></div>
<p>In the <strong>Settings</strong> tab enable forms-based authentication and click <strong>OK</strong> to apply the change.</p>
<div id="attachment_2610" class="wp-caption aligncenter" style="width: 414px"><img class="size-full wp-image-2610" title="Enabling Forms-Based Authentication for Exchange 2003" src="http://exchangeserverpro.com/wp-content/uploads/2011/01/exchange-2003-enable-forms-based-authentication-02.png" alt="Enabling Forms-Based Authentication for Exchange 2003" width="404" height="204" /><p class="wp-caption-text">Enabling Forms-Based Authentication for Exchange 2003</p></div>
<p>Exchange will warn you that SSL must be configured and IIS restarted if you are not offloading SSL elsewhere, or have not already configured it in IIS.  Click <strong>OK </strong>to close the warning (and obviously if you have not already got SSL offloaded or configured then you should go ahead and do that).</p>
<div id="attachment_2611" class="wp-caption aligncenter" style="width: 610px"><img class="size-full wp-image-2611" title="Exchange 2003 warning about SSL configuration for forms-based authentication" src="http://exchangeserverpro.com/wp-content/uploads/2011/01/exchange-2003-enable-forms-based-authentication-03.png" alt="Exchange 2003 warning about SSL configuration for forms-based authentication" width="600" height="103" /><p class="wp-caption-text">Exchange 2003 warning about SSL configuration for forms-based authentication</p></div>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/exchange-2010-fix-alias-script" title="Fixing Mail-Enabled Object Aliases for Exchange Server 2010 Migration">Fixing Mail-Enabled Object Aliases for Exchange Server 2010 Migration</a></li><li><a href="http://exchangeserverpro.com/owa-error-mailbox-trying-access-not-currently-available" title="OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available">OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available</a></li><li><a href="http://exchangeserverpro.com/exchange-2003-2010-coexistence" title="Configuring Co-Existence for Exchange 2003 and Exchange 2010">Configuring Co-Existence for Exchange 2003 and Exchange 2010</a></li><li><a href="http://exchangeserverpro.com/free-sample-chapter-exchange-server-2003-2010-migration-guide" title="Free Sample Chapter from the Exchange Server 2003 to 2010 Migration Guide">Free Sample Chapter from the Exchange Server 2003 to 2010 Migration Guide</a></li><li><a href="http://exchangeserverpro.com/exchange-2010-direct-migration-2003-2010-or-2007" title="Exchange 2010 FAQ: Is Direct Exchange Migration from 2003 to 2010 Possible Without Upgrading to 2007?">Exchange 2010 FAQ: Is Direct Exchange Migration from 2003 to 2010 Possible Without Upgrading to 2007?</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/exchange-2010-owa-legacy-url-redirection-http-500-error">Exchange 2010 OWA Legacy URL Redirection HTTP 500 Error</a> is © 2011 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/exchange-2010-owa-legacy-url-redirection-http-500-error/feed</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Exchange Server 2010 Outlook Web App Authentication Settings</title>
		<link>http://exchangeserverpro.com/exchange-server-2010-outlook-web-app-authentication-settings</link>
		<comments>http://exchangeserverpro.com/exchange-server-2010-outlook-web-app-authentication-settings#comments</comments>
		<pubDate>Sun, 19 Sep 2010 13:12:09 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[Client Access]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[OWA]]></category>

		<guid isPermaLink="false">http://exchangeserverpro.com/?p=2086</guid>
		<description><![CDATA[Outlook Web App is hosted on the Client Access Server role for Exchange Server 2010 and integrated with IIS 7.  The OWA virtual directory can be secured using different authentication settings depending on the network environment.]]></description>
			<content:encoded><![CDATA[<p>Outlook Web App (OWA) is the webmail interface for Exchange Server 2010.  Most of you will already be familiar with the acronym OWA from previous versions of Exchange Server where webmail was named Outlook Web <em>Access</em>.</p>
<p>Outlook Web App is hosted on the Client Access Server role for Exchange Server 2010 and integrated with IIS 7.  The OWA URL is typically something like this:</p>
<blockquote><p>https://webmail.mycompany.com/owa</p></blockquote>
<p>To connect to Outlook Web App users must authenticate first.  The OWA virtual directory can be secured using different authentication settings depending on the network environment.</p>
<h2>Exchange Server 2010 Outlook Web App Authentication Types</h2>
<p>There are four authentication methods available for Exchange Server 2010 OWA.  They are:</p>
<p><strong>Integrated Authentication</strong> &#8211; this allows domain users who are logged on to domain computers to automatically logon to Outlook Web App.  This is useful for internal Outlook Web App access as it simplifies the logon process for domain users (they don&#8217;t need to logon once to the computer and then a second time for OWA).  However Integrated Authentication is not suitable for remote access by people using non-domain member computers, or people who are connecting via proxy servers.</p>
<p><strong>Basic Authentication</strong> &#8211; this uses the HTTP protocol to send the logon credentials to the server.  Because the credentials are sent &#8220;in the clear&#8221; the use of SSL is highly recommended for securing them.  Also, because Basic Authentication credentials can be cached in web browsers it is recommended to use an additional authentication factor (eg a one-time password from a token) to prevent unauthorized access from public kiosk computers using the cached credentials.</p>
<div id="attachment_2090" class="wp-caption aligncenter" style="width: 439px"><img class="size-full wp-image-2090" title="exchange-2010-owa-basic-authentication" src="http://exchangeserverpro.com/wp-content/uploads/2010/09/exchange-2010-owa-basic-authentication.png" alt="" width="429" height="243" /><p class="wp-caption-text">Logon dialog box for Outlook Web App using Basic Authentication </p></div>
<p><strong>Digest Authentication</strong> &#8211; this method solves the problem with Basic Authentication where credentials are sent &#8220;in the clear&#8221; by sending a hashed password instead.  Digest Authentication also works through a proxy server unlike Integrated Authentication.  However Digest Authentication does have some other configuration requirements, such as the use of reversible encryption for password storage in Active Directory.  These may make it an undesirable option for many organiztions.</p>
<p><strong>Forms-Based Authentication</strong> &#8211; this method uses a sign-in webpage on the server to collect logon credentials.  as with Basic Authentication the use of SSL with Forms-Based Authentication is highly recommended to protect the user credentials.</p>
<div id="attachment_2092" class="wp-caption aligncenter" style="width: 450px"><img class="size-full wp-image-2092" title="exchange-2010-owa-forms-based-authentication" src="http://exchangeserverpro.com/wp-content/uploads/2010/09/exchange-2010-owa-forms-based-authentication.png" alt="" width="440" height="326" /><p class="wp-caption-text">The Exchange Server 2010 OWA Logon Page</p></div>
<p>Forms-Based Authentication has three additional configuration options for how the user credentials are submitted.</p>
<ul>
<li><strong>Domain\Username</strong> &#8211; users enter their credentials in the format Domain\Username, using either the NETBIOS or FQDN for the domain name.</li>
<li><strong>User Principal Name (UPN)</strong> &#8211; if this option is chosen only users who have a UPN specified that matches their email address will be able to logon to Outlook Web App.</li>
<pre>[PS] C:\&gt;Get-Mailbox "alan reid" | fl name, userprincipalname, primarysmtpaddress

Name               : Alan.Reid
UserPrincipalName  : Alan.Reid@exchangeserverpro.local
PrimarySmtpAddress : Alan.Reid@exchangeserverpro.local</pre>
<li><strong>Username Only</strong> &#8211; with this option the Exchange administrator specifies a default domain for OWA logons, and users in that domain can logon with username only.  Users in other domains must still use Domain\Username.</li>
</ul>
<h2>Configuring Outlook Web App for Integrated Authentication</h2>
<p>In this example the Exchange Server 2010 OWA virtual directory is being configured for Integrated Authentication.</p>
<p>Using the Exchange Management Console navigate to <strong>Server Configuration</strong> -&gt; <strong>Client Access</strong>, and choose the server you wish to configure.  Select the <strong>Outlook Web App</strong> tab, then right-click the <strong>OWA virtual directory</strong> and choose <strong>Properties</strong>.</p>
<div id="attachment_2089" class="wp-caption aligncenter" style="width: 590px"><img class="size-full wp-image-2089" title="exchange-2010-configure-owa" src="http://exchangeserverpro.com/wp-content/uploads/2010/09/exchange-2010-configure-owa.png" alt="" width="580" height="377" /><p class="wp-caption-text">Configuring an Exchange Server 2010 OWA Virtual Directory</p></div>
<p>Select the <strong>Authentication</strong> tab.  Choose <strong>Use one or more Standard Authentication Methods</strong> and tick the <strong>Integrated Windows Authentication</strong> box.</p>
<div id="attachment_2091" class="wp-caption aligncenter" style="width: 454px"><img class="size-full wp-image-2091" title="exchange-2010-owa-integrated-authentication" src="http://exchangeserverpro.com/wp-content/uploads/2010/09/exchange-2010-owa-integrated-authentication.png" alt="" width="444" height="225" /><p class="wp-caption-text">Enabling Integrated Authentication for Exchange Server 2010 OWA</p></div>
<p>Click <strong>OK</strong> to apply the change.</p>
<p>To perform the same configuration using the Exchange Management Shell run this command.</p>
<pre>[PS] C:\&gt;Set-OwaVirtualDirectory "EX3\owa (Default Web Site)" -BasicAuthentication $false -WindowsAuthentication $true -DigestAuthentication $false</pre>
<p>You will notice that three settings were specified in the command.  This is because Basic, Integrated, and Digest Authentication can be enabled concurrently so that the OWA virtual directory supports multiple authentication methods.  Because of this you should explicitly configure the authentication methods the way that you intend them to be set, rather than modifying only a single authentication method.</p>
<h2>Configuring Outlook Web App for Forms-Based Authentication</h2>
<p>In this example the Exchange Server 2010 OWA virtual directory is being configured for Forms-Based Authentication.</p>
<p>Using the Exchange Management Console navigate to <strong>Server Configuration</strong> -&gt; <strong>Client Access</strong>, and choose the server you wish to configure.  Select the <strong>Outlook Web App</strong> tab, then right-click the <strong>OWA virtual directory</strong> and choose <strong>Properties</strong>.</p>
<div id="attachment_2089" class="wp-caption aligncenter" style="width: 590px"><img class="size-full wp-image-2089" title="exchange-2010-configure-owa" src="http://exchangeserverpro.com/wp-content/uploads/2010/09/exchange-2010-configure-owa.png" alt="" width="580" height="377" /><p class="wp-caption-text">Configuring an Exchange Server 2010 OWA Virtual Directory</p></div>
<p>Select the <strong>Authentication</strong> tab.  Choose <strong>Use forms-based authentication</strong> and then choose a logon format, in this example <strong>User name only</strong>.</p>
<div id="attachment_2093" class="wp-caption aligncenter" style="width: 440px"><img class="size-full wp-image-2093" title="exchange-2010-owa-enabled-forms-based-authentication" src="http://exchangeserverpro.com/wp-content/uploads/2010/09/exchange-2010-owa-enabled-forms-based-authentication.png" alt="" width="430" height="349" /><p class="wp-caption-text">Configuring Forms-Based Authentication for Exchange Server 2010 OWA</p></div>
<p>Click <strong>OK</strong> to apply the change.</p>
<p>To perform the same configuration using the Exchange Management Shell run the following command.</p>
<pre>[PS] C:\&gt;Set-OwaVirtualDirectory "EX3\owa (Default Web Site)" -FormsAuthentication $true -LogonFormat UserName -DefaultDomain exchangeserverpro.local</pre>
<h2>Other Steps When Changing Outlook Web App Authentication Settings</h2>
<p>You will notice as you modify OWA virtual directory authentication settings that two additional steps are usually required:</p>
<ul>
<li>Resetting IIS &#8211; this is required any time you switch to or from Forms-Based Authentication.  From a command prompt window run the following command:</li>
<pre>iisreset /noforce</pre>
<li>Modifying the ECP virtual directory &#8211; ECP stands for Exchange Control Panel and is the self-service web portal for end users to make changes to their mailbox, distribution lists they manage, and some other items.  The authentication method for this virtual directory should be configured to match the OWA virtual directory.</li>
</ul>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/exchange-server-2010-error-outlook-web-app-initialize" title="Exchange Server 2010 Error: Outlook Web App Didn&#8217;t Initialize">Exchange Server 2010 Error: Outlook Web App Didn&#8217;t Initialize</a></li><li><a href="http://exchangeserverpro.com/exchange-server-2010-cas-array" title="Getting Started with Exchange Server 2010 Client Access Server Arrays">Getting Started with Exchange Server 2010 Client Access Server Arrays</a></li><li><a href="http://exchangeserverpro.com/iis-6-wmi-compatibility-component-required-exchange-2010-sp2-upgrade" title="Error Message &#8220;The &#8216;IIS 6 WMI Compatibility&#8217; component is required&#8221; During Exchange 2010 SP2 Upgrade">Error Message &#8220;The &#8216;IIS 6 WMI Compatibility&#8217; component is required&#8221; During Exchange 2010 SP2 Upgrade</a></li><li><a href="http://exchangeserverpro.com/exchange-2010-online-mailbox-moves" title="Exchange 2010 FAQ: How to Minimise Downtime During Mailbox Migration from Exchange 2007">Exchange 2010 FAQ: How to Minimise Downtime During Mailbox Migration from Exchange 2007</a></li><li><a href="http://exchangeserverpro.com/owa-error-mailbox-trying-access-not-currently-available" title="OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available">OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/exchange-server-2010-outlook-web-app-authentication-settings">Exchange Server 2010 Outlook Web App Authentication Settings</a> is © 2010 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/exchange-server-2010-outlook-web-app-authentication-settings/feed</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>SSL Certificate Trust Errors for New Thawte Certificates</title>
		<link>http://exchangeserverpro.com/ssl-certificate-trust-errors-for-new-thawte-certificates</link>
		<comments>http://exchangeserverpro.com/ssl-certificate-trust-errors-for-new-thawte-certificates#comments</comments>
		<pubDate>Fri, 27 Aug 2010 09:00:46 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[Solutions]]></category>
		<category><![CDATA[Certificates]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[OWA]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Thawte]]></category>

		<guid isPermaLink="false">http://exchangeserverpro.com/?p=2018</guid>
		<description><![CDATA[If you renew a Thawte SSL certificate or purchase a new one since 26th July 2010 you may encounter SSL certificate trust errors when clients connect to published websites such as Outlook Web Access.]]></description>
			<content:encoded><![CDATA[<p>If you renew a Thawte SSL certificate or purchase a new one since 26th July 2010 you may encounter SSL certificate trust errors when clients connect to published websites such as Outlook Web Access.</p>
<p>Web browsers will return an error such as:</p>
<blockquote><p>The security certificate issued by this website was not issued by a trusted certificate authority</p></blockquote>
<p>On inspection of the certificate being issued by the website you may see this error:</p>
<blockquote><p>The issuer of this certificate could not be found</p></blockquote>
<p>This can be confusing for people who assume that any certificate issued by a commercial CA such as Thawte will be trusted by devices and web browsers that people are connecting from, especially when it occurs after renewing an existing Thawte SSL certificate.</p>
<p>Thawte has <a href="https://search.thawte.com/support/ssl-digital-certificates/index?page=content&amp;id=SO15171&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1282614432001">published the reason for this</a>:</p>
<blockquote><p>On June 27 2010, in the interest of better security, thawte signed all certificates with a primary and secondary intermediate that need to be installed along with the SSL certificate. Any certificate issued on or after this date requires the primary and secondary intermediate to be installed.</p></blockquote>
<p>The new certificates are issued by an intermediate CA known as &#8220;Thawte SSL CA&#8221;.  This CA is not automatically trusted by most web browsers.  <a href="https://search.thawte.com/support/ssl-digital-certificates/index?page=content&amp;id=SO15171&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1282614432001">Thawte provides instructions</a> for installing the correct certificates on the web server or ISA Server that is publishing the website.</p>
<p>Take note of the final steps, the change may not take effect until IIS or ISA Server are restarted.</p>
<blockquote><p>If your site still have the chaining error, restart the IIS service. If the problem continues, the whole server needs a reboot to use the new roots.</p></blockquote>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/exchange-2010-wildcard-ssl-certificates" title="Exchange 2010 FAQ: Are Wildcard SSL Certificates Supported?">Exchange 2010 FAQ: Are Wildcard SSL Certificates Supported?</a></li><li><a href="http://exchangeserverpro.com/autodiscover-ssl-warnings-exchange-2010-migration" title="Autodiscover and SSL Warnings during Exchange 2010 Migration">Autodiscover and SSL Warnings during Exchange 2010 Migration</a></li><li><a href="http://exchangeserverpro.com/exchange-2010-ssl-certificates" title="Exchange 2010 SSL Certificates">Exchange 2010 SSL Certificates</a></li><li><a href="http://exchangeserverpro.com/exchange-server-2010-and-the-benefits-of-commercial-ssl-certificates" title="Exchange Server 2010 and the Benefits of Commercial SSL Certificates">Exchange Server 2010 and the Benefits of Commercial SSL Certificates</a></li><li><a href="http://exchangeserverpro.com/how-to-issue-a-san-certificate-to-exchange-server-2010-from-a-private-certificate-authority" title="How to Issue a SAN Certificate to Exchange Server 2010 from a Private Certificate Authority">How to Issue a SAN Certificate to Exchange Server 2010 from a Private Certificate Authority</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/ssl-certificate-trust-errors-for-new-thawte-certificates">SSL Certificate Trust Errors for New Thawte Certificates</a> is © 2010 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/ssl-certificate-trust-errors-for-new-thawte-certificates/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Exchange Server 2010 OWA Support Browser Matrix</title>
		<link>http://exchangeserverpro.com/exchange-server-2010-owa-support-browser-matrix</link>
		<comments>http://exchangeserverpro.com/exchange-server-2010-owa-support-browser-matrix#comments</comments>
		<pubDate>Fri, 09 Apr 2010 02:04:11 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[OWA]]></category>

		<guid isPermaLink="false">http://exchangeserverpro.com/?p=1274</guid>
		<description><![CDATA[Find out which browsers and OS platforms support the full Outlook Web App feature set.]]></description>
			<content:encoded><![CDATA[<p>Microsoft&#8217;s <a href="http://help.outlook.com/en-us/140/bb899685%28EXCHSRVCS.140%29.aspx">Outlook Web App help site</a> has the list of web browsers on different OS platforms that support the full Outlook Web App feature set.</p>
<blockquote><p>To use the complete set of features available in  Outlook Web App and the Web management interface, you can use the  following browsers on a computer running Windows XP, Windows 2003,  Windows Vista, or Windows 7:</p>
<ul>
<li> Internet Explorer 7 and later versions.</li>
<li> Firefox 3.0.1 and later versions.</li>
<li> Chrome 3.0.195.27 and later versions.</li>
</ul>
<p>On a computer running Max OS X, you can use:</p>
<ul>
<li> Safari 3.1 and later versions.</li>
<li> Firefox 3.0.1 and later versions.</li>
</ul>
<p>On a computer running Linux, you can use:</p>
<ul>
<li> Firefox 3.0.1 and later versions.</li>
</ul>
<p>If you use a Web browser that doesn&#8217;t support the full feature  set, Outlook Web App will open in the light version.</p></blockquote>
<p>The light version is primarily designed for accessibility for the visually impaired.  However with its stripped down interface and limited features it is also useful when on slow connections and has the broadest browser compatiblity of the two versions.</p>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/owa-error-mailbox-trying-access-not-currently-available" title="OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available">OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available</a></li><li><a href="http://exchangeserverpro.com/exchange-server-2010-error-outlook-web-app-initialize" title="Exchange Server 2010 Error: Outlook Web App Didn&#8217;t Initialize">Exchange Server 2010 Error: Outlook Web App Didn&#8217;t Initialize</a></li><li><a href="http://exchangeserverpro.com/publish-outlook-web-app-isa-server-2006" title="How to Publish Outlook Web App with ISA Server 2006">How to Publish Outlook Web App with ISA Server 2006</a></li><li><a href="http://exchangeserverpro.com/exchange-2010-owa-legacy-url-redirection-http-500-error" title="Exchange 2010 OWA Legacy URL Redirection HTTP 500 Error">Exchange 2010 OWA Legacy URL Redirection HTTP 500 Error</a></li><li><a href="http://exchangeserverpro.com/exchange-server-2010-outlook-web-app-authentication-settings" title="Exchange Server 2010 Outlook Web App Authentication Settings">Exchange Server 2010 Outlook Web App Authentication Settings</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/exchange-server-2010-owa-support-browser-matrix">Exchange Server 2010 OWA Support Browser Matrix</a> is © 2010 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/exchange-server-2010-owa-support-browser-matrix/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Exchange Remote Connectivity Analyzer Updated</title>
		<link>http://exchangeserverpro.com/exchange-remote-connectivity-analyzer-updated</link>
		<comments>http://exchangeserverpro.com/exchange-remote-connectivity-analyzer-updated#comments</comments>
		<pubDate>Tue, 20 Oct 2009 00:08:29 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[ActiveSync]]></category>
		<category><![CDATA[Entourage]]></category>
		<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[Exchange Web Services]]></category>
		<category><![CDATA[OWA]]></category>

		<guid isPermaLink="false">http://exchangeserverpro.com/?p=1014</guid>
		<description><![CDATA[Microsoft has released an updated version of the Exchange Remote Connectivity Analyzer tool with brand new features and Exchange Server 2010 compatiblity.]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released an update to the useful Exchange Remote Connectivity Analyzer.  Announced by the <a href="http://msexchangeteam.com/archive/2009/10/19/452905.aspx">MS Exchange Server Team today</a>, the update includes:</p>
<ul>
<li>New CAPTCHA interface</li>
<li>New tests for Exchange Web Services (useful for testing Entourage for Mac clients) and Outbound SMTP</li>
<li>Updates for Exchange 2010 Outlook Web Access</li>
<li>Password confirmation to reduce test failures from password typos</li>
<li>Removal of the &#8220;Beta&#8221; label</li>
</ul>
<p>The tool also has a slick new interface.  Check out the differences between the old site and the new site.</p>
<div id="attachment_1015" class="wp-caption alignnone" style="width: 510px"><img class="size-full wp-image-1015" title="Old Interface" src="http://exchangeserverpro.com/wp-content/uploads/2009/10/exchangeremoteconntest.png" alt="Old Exchange Remote Connectivity Test Interface" width="500" height="319" /><p class="wp-caption-text">Old Exchange Remote Connectivity Test Interface</p></div>
<div id="attachment_1016" class="wp-caption alignnone" style="width: 510px"><img class="size-full wp-image-1016" title="New Interface" src="http://exchangeserverpro.com/wp-content/uploads/2009/10/exchremoteconntest_oct2009.PNG" alt="New Exchange Remote Connectivity Test Interface" width="500" height="283" /><p class="wp-caption-text">New Exchange Remote Connectivity Test Interface</p></div>
<p>Check out the <a href="https://www.testexchangeconnectivity.com/">Exchange Remote Connectivity Analyzer Tool</a>.</p>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/owa-error-mailbox-trying-access-not-currently-available" title="OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available">OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available</a></li><li><a href="http://exchangeserverpro.com/poll-exchange-mobile-access" title="Poll: Which Exchange mobile access platform do you use?">Poll: Which Exchange mobile access platform do you use?</a></li><li><a href="http://exchangeserverpro.com/configuring-the-exchange-server-2007-client-access-server" title="Configuring the Exchange Server 2007 Client Access Server">Configuring the Exchange Server 2007 Client Access Server</a></li><li><a href="http://exchangeserverpro.com/test-your-exchange-server-remote-connectivity" title="Test your Exchange Server remote connectivity">Test your Exchange Server remote connectivity</a></li><li><a href="http://exchangeserverpro.com/generate-smtp-error-statistics-using-log-parser-and-exchange-server-2010-protocol-logs" title="Generate SMTP Error Statistics using Log Parser and Exchange Server 2010 Protocol Logs">Generate SMTP Error Statistics using Log Parser and Exchange Server 2010 Protocol Logs</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/exchange-remote-connectivity-analyzer-updated">Exchange Remote Connectivity Analyzer Updated</a> is © 2009 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/exchange-remote-connectivity-analyzer-updated/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Publish Exchange Server 2007 OWA Using ISA Server 2006</title>
		<link>http://exchangeserverpro.com/publish-exchange-server-2007-owa-using-isa-server-2006</link>
		<comments>http://exchangeserverpro.com/publish-exchange-server-2007-owa-using-isa-server-2006#comments</comments>
		<pubDate>Mon, 31 Aug 2009 08:30:27 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[Exchange Server 2007 Transition Guide]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[OWA]]></category>

		<guid isPermaLink="false">http://exchangeserverpro.com/?p=849</guid>
		<description><![CDATA[Step by step guide for how to publish Exchange Server 2007 Outlook Web Access using an ISA Server 2006 firewall.]]></description>
			<content:encoded><![CDATA[<p>Before we begin we must first use the same procedure used for <a href="http://exchangeserverpro.com/migrate-ssl-certificates-from-exchange-server-2003-to-exchange-server-2007/">migrating the SSL certificate from Exchange Server 2003 to Exchange Server 2007</a> to also migrate the certificate to the ISA Server 2006 firewall.  Once an SSL certificate has been configured on the ISA server we can continue with the publishing rules for Outlook Web Access.</p>
<p>Open the <strong>ISA Server Management</strong> console and navigate to <strong>&lt;ISA server name&gt;/Firewall Policy</strong>.<img class="alignnone size-full wp-image-850" title="isa011" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/isa011.png" alt="isa011" width="211" height="103" /></p>
<p>Click on <strong>Publish Exchange Web Client Access</strong> in the Tasks pane on the right side of the ISA Server Management Console.</p>
<p><img class="alignnone size-full wp-image-852" title="exweb01" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb01.png" alt="exweb01" width="179" height="205" /></p>
<p>Enter a meaningful name for the new publishing rule such as &#8220;Exchange Remote Access&#8221;.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-853" title="exweb02" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb02.png" alt="exweb02" width="324" height="97" /></p>
<p>Select the Exchange version <strong>Exchange Server 2007</strong> and tick the <strong>Outlook Web Access</strong> box.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-854" title="exweb03" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb03.png" alt="exweb03" width="464" height="159" /></p>
<p>Choose <strong>Publish a single Web site or load balancer</strong>.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-855" title="exweb04" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb04.png" alt="exweb04" width="455" height="221" /></p>
<p>Choose <strong>Use SSL to connect to the published Web server or server farm</strong> as this is the most secure option.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-856" title="exweb05" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb05.png" alt="exweb05" width="484" height="207" /></p>
<p>Enter the FQDN of the Client Access Server.  If for any reason your ISA Server is not able to resolve this name you should also tick the box and enter a name or IP that ISA can use to connect to the server.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-857" title="exweb06" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb06.png" alt="exweb06" width="483" height="240" /></p>
<p>Enter the <strong>Public Name</strong> of the server.  This should match the name on the SSL certificate you imported on the Exchange and ISA servers, the External URL setting on the OWA virtual directory for the Exchange Client Access Server configuration, and the external DNS name that your clients use to connect to Exchange remote access.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-858" title="exweb07" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb07.png" alt="exweb07" width="492" height="135" /></p>
<p>Click <strong>New</strong> to create a new web listener for Exchange Remote Access.</p>
<p><img class="alignnone size-full wp-image-859" title="exweb08" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb08.png" alt="exweb08" width="458" height="105" /></p>
<p>Give the listener a meaningful name such as &#8220;ExchangeSSL&#8221;.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-860" title="exweb09" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb09.png" alt="exweb09" width="271" height="87" /></p>
<p>Choose <strong>Require SSL secured connections with clients</strong>.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-861" title="exweb10" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb10.png" alt="exweb10" width="474" height="193" /></p>
<p>Select the <strong>External</strong> network to listen for incoming web requests.  If you have more than one external IP address you must click <strong>Select IP Addresses</strong> and specify which IP address bound to the External network to listen on.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-862" title="exweb11" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb11.png" alt="exweb11" width="480" height="224" /></p>
<p>Click <strong>Select Certificate</strong> and choose the SSL certificate you imported on the ISA Server firewall.  Click <strong>Select</strong> and then click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-863" title="exweb12" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb12.png" alt="exweb12" width="475" height="179" /></p>
<p>Leave the authentication settings set to <strong>HTML Form Authentication</strong> with <strong>Windows (Active Directory)</strong>.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-864" title="exweb13" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb13.png" alt="exweb13" width="504" height="293" /></p>
<p>Clear the <strong>Enable SSO</strong> check box.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-865" title="exweb14" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb14.png" alt="exweb14" width="504" height="261" /></p>
<p>Click <strong>Finish</strong> to complete the New Web Listener wizard.  Select the web listener you have just created and click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-866" title="exweb15" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb15.png" alt="exweb15" width="502" height="270" /></p>
<p>Choose <strong>Basic Authentication</strong> for authentication delegation.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-867" title="exweb16" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb16.png" alt="exweb16" width="501" height="217" /></p>
<p class="alert">Note:  Delegation using Basic authentication allows a single SSL certificate, public IP address, and ISA publishing rule to be used for all Exchange remote access methods (eg Outlook Web Access and   Outlook Anywhere).  In environments with multiple public IP addresses and a requirement to delegate Outlook Anywhere authentication using Kerberos/NTLM then Negotiate(Kerberos/NTLM) would be   chosen.</p>
<p>Leave the users set to <strong>Authenticated Users</strong>.  Click <strong>Next</strong> to continue.</p>
<p><img class="alignnone size-full wp-image-868" title="exweb17" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb17.png" alt="exweb17" width="505" height="218" /></p>
<p>Click <strong>Finish</strong> to complete the Publishing Rule wizard.</p>
<p>Right click the newly created rule and choose <strong>Properties</strong>.</p>
<p><img class="alignnone size-full wp-image-869" title="exweb18" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb18.png" alt="exweb18" width="474" height="151" /></p>
<p>Navigate to the <strong>Paths</strong> tab.  Click the <strong>Add</strong> button to add more paths to the publishing rule for ActiveSync, AutoDiscover, and Outlook Anywhere.</p>
<p class="alert">Note:  If you are planning to publish these services on separate IP addresses and SSL certificates you would not perform these steps.</p>
<p>Add the following paths:</p>
<ul class="unIndentedList">
<li> /rpc/*</li>
<li> /Microsoft-Server-ActiveSync/*</li>
<li> /AutoDiscover/*</li>
</ul>
<p><img class="alignnone size-full wp-image-871" title="exweb20" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb20.png" alt="exweb20" width="374" height="279" /></p>
<p>Click <strong>OK</strong> when you have added each of the paths to the rule.</p>
<p><img class="alignnone size-full wp-image-870" title="exweb19" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/exweb19.png" alt="exweb19" width="398" height="124" /></p>
<p>Apply the ISA rule changes.</p>
<p><img class="alignnone size-full wp-image-851" title="isa111" src="http://exchangeserverpro.com/wp-content/uploads/2009/08/isa111.png" alt="isa111" width="500" height="103" /></p>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/publish-incoming-smtp-to-the-exchange-server-2007-server-with-isa-server-2006" title="Publish incoming SMTP to the Exchange Server 2007 server with ISA Server 2006">Publish incoming SMTP to the Exchange Server 2007 server with ISA Server 2006</a></li><li><a href="http://exchangeserverpro.com/configuring-the-exchange-server-2007-hub-transport-server" title="Configuring the Exchange Server 2007 Hub Transport Server">Configuring the Exchange Server 2007 Hub Transport Server</a></li><li><a href="http://exchangeserverpro.com/configuring-the-exchange-server-2007-client-access-server" title="Configuring the Exchange Server 2007 Client Access Server">Configuring the Exchange Server 2007 Client Access Server</a></li><li><a href="http://exchangeserverpro.com/owa-error-mailbox-trying-access-not-currently-available" title="OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available">OWA Error: The Mailbox You&#8217;re Trying to Access Isn&#8217;t Currently Available</a></li><li><a href="http://exchangeserverpro.com/500-internal-server-error-exchange-2007-outlook-web-access" title="500 Internal Server Error for Exchange 2007 Outlook Web Access">500 Internal Server Error for Exchange 2007 Outlook Web Access</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/publish-exchange-server-2007-owa-using-isa-server-2006">Publish Exchange Server 2007 OWA Using ISA Server 2006</a> is © 2009 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/publish-exchange-server-2007-owa-using-isa-server-2006/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

