CAS behind the Proxy Server
Hi All,I have a scenario here in my Exchange Server 2007 Setup. I have HUB/CAS installed in the same server box and a separate server for myMailBox. My CAS was not configured toenable Outlook anywhere, Autodiscover service was configured correctly and my mail client is Outlook 2007. All of my users are joined in domain and wasconfigured to use proxy server (IE) regardless if its local or internet access. My proxy server (not ISA)is in the DMZ, it has a local and public dnsand was configured to exempt the localHTTPS request used by autodiscover service. I found out the following scenario:1. If i disable the user's IE proxy server settings, i will be able to configure my Outlook 2007, and the autodiscover service will work and will be able to get the user credentials in AD.2. If i enable the user's IE proxy server settings, the autodiscover service will work butprompts me with the user credentials in AD.In my environment, the user's are required to use proxy whenever they will need to use IE/(HTTP/HTTPS), and if i enabled, the Outlook 2007 it will always prompt a logon credentials.Any ideas on how to fix this?Regards,LRMCP
September 10th, 2009 2:20pm

Have you configured your OL profile as Basic Authentication?Vinod |CCNA|MCSE 2003 +Messaging|MCTS|ITIL V3|
Free Windows Admin Tool Kit Click here and download it now
September 10th, 2009 2:54pm

Another thought would be to check DNS.I'm thinking that when you have the proxy configured the flow is going out and then back in to your environment. I'm guessing these are for local users? They should be hitting the CAS servers internally for autodiscover rather than going outside. You could test your OL connectivity. Do a Ctrl - right click on the OL icon in the sys tray and select the test connectivity option. Try that for both proxy on and off.Another thought would be to ping the url and see what IP you resolve.SF - MCITP:EMA, MCTS: MOSS 2007, OCS 2007, Exchange 2007
September 10th, 2009 4:47pm

HiSince the Autodiscover URL point's to your local domain, u have an option of selecting "Bypass proxy server for local address" in your browsers Proxy server settings.is your local domain and external public domain having the same name Ex: Local domain name: domain.local and public domain name: domain.comAs scott we must also check theDNS configurationHope thebelow article helps you outhttp://support.microsoft.com/kb/940881
Free Windows Admin Tool Kit Click here and download it now
September 10th, 2009 7:30pm

Hi All,Thanks for replies. The OL connectivity test is intermittent,sometime it willsucceed even if the proxy is enabled but if the proxy is disabled,it'll will always succeeded. I'm having a thought that this might be a DNS, but i need a proof, the current design of the DNS is centralize, wherein all subdomains has one DNS.NSLOOKUP will resolved either the request is from DMZ or from internal network. My Local and External domain has the same name, but my local domain has Netbios Name. Example: domain.local,Domain Netbios= mydomain, and domain.com.countrysuffix. Scott's guess was right, they should be hitting the internal CAS and should not go out, the behavior sometimes is connect to autodiscover.domain.com.countrysuffix.I'll try this resolution http://support.microsoft.com/kb/940881. Will get back to you guys on results.Regards,LRMCP
September 11th, 2009 5:37am

If you have split DNS, one outward and one inward, you coudl configure the same URL for both. The outward DNS will reference the public IP for the ISA box while the inward DNS will reference the CAS server. Then you would set up your internal and external URLs for OWA to be the same (internal will act as external if external is not configured). SF - MCITP:EMA, MCTS: MOSS 2007, OCS 2007, Exchange 2007
Free Windows Admin Tool Kit Click here and download it now
September 11th, 2009 6:39pm

Hi,For internal Outlook clients, it connects the Autodiscover service by using SCP from the AD rather than the external URL. Thus, if you enable proxy server, we need to add the SCP record for the proxy server in the public DNS. After that, proxy server can forward the request to the CAS.ThanksAllen
September 14th, 2009 10:57am

Hi,The only workaround on this is to set the value of IE "Bypass proxy server for local addresses".Thanks.LRMCP
Free Windows Admin Tool Kit Click here and download it now
September 14th, 2009 12:28pm

You can also test yourinternet connectivity: https://www.testexchangeconnectivity.com/SF - MCITP:EMA, MCTS: MOSS 2007, OCS 2007, Exchange 2007
September 14th, 2009 9:50pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics