PDA

View Full Version : help setting up owa external access in exchange 2007


hlwin999
03-18-2009, 12:45 PM
Hi Instructor Dshack,

After repeatedly following you instruction on how to setup owa access from external, I failed miserably. Apparently, it is difficult to do when it involve multiple servers and firewall in production environment. So here is what I have done and failed. See if you can advise to help me out.
First step: put a record and reverse point in ISP’s dns system
mail.domain.com public ip address

On owa external URL, set to: https://mail.domain.com/owa

Our website is hosted by other hosting company, but our ip address are from AT&T which I has access to dns setting on my own.

On the Sonic Wall firewall, I opened up https port for owa access and direct it to internal ip address of exchange 2007 server.

Now the question is how does internal exchange server would know its external URL that I set on owa and how does firewall know how to forward this to correct external URL list on internal exchange server?

You sort of mention that I would put forward lookup zone for external domain which is hosted by other hosting company. When I did create one for internal use like you suggested, weird thing happened. All of a sudden, I cannot go to that domain which is again hosted by outside company.

I put owa and auto discovery A records with internal ip address pointing to the server in the forward lookup zone. Once it completed when I go to www.ourexternaldomainname.com, I can no longer get there. Any idea why? Do I need to put www record and point it to external ip address of the domain?

I am very confused. Other thing is that now we have IIS7 instead of 6 per your instruction video and that is somehow very confusing to follow the setting as well.

Let me know if there anything that I can try.

Thanks,

Henry

DShack
03-20-2009, 10:58 AM
To make OWA work from the outside, you need to add a record for "mail" to your DNS zone. I think you said that AT&T is controlling your DNS records and that you were able to change it there. Usually your RDNS records and your regular DNS records will be managed by separate entities, but that's not true in all situations.

On the internal network, if you add a forward lookup zone for your external domain, you WILL need to recreate records that map to external resources. So you would need to create a new "www" record pointing to the external web hosts IP in order for internal users to reach the external website.

The most important place to create AutoDiscovery records is in your external DNS.

You're right, IIS7 does make things more complicated, but you shouldn't have to mess with it too much. The URL changes should be able to be configured in the EMC and/or the EMS.