WatchGuard XCS and Outlook Web Access 2013

Similar documents
User Guide: MacMail Manual Migration for MS Windows

Outlook for ios/android App. Adding and Removing a Shared Calendar on Outlook for ios/android

RPC Over HTTP Install Windows Server 2003 Configure your Exchange 2003 front-end server as an RPC Proxy server

HOL122 Lab 1: Configuring Microsoft Windows Server 2003 RPC Proxy

Hosted Microsoft Exchange Client Setup & Guide Book

Microsoft Exchange Server 2013 and 2016 Deployment

MailEnable Connector for Microsoft Outlook

Manual Owa Exchange 2010 Url Parameters

OUTLOOK WEB APP (OWA): MAIL

What to Know About Exchange 2013 and Load Balancing

Verify that your operating environment meets all hardware and software requirements. For detailed requirements

[Outlook Configuration Guide]

Using Outlook Web Access (OWA) 2013

Manual Owa Exchange 2010 Not Working Externally

Microsoft Installing, Configuring, and Administering Microsoft Exchange 2003 Server Implementing &Managing MS Exchange Server 2003

MailEnable Connector for Microsoft Outlook

Outlook 2010 Exchange Setup Guide

Installing and Configuring VMware Identity Manager Connector (Windows) OCT 2018 VMware Identity Manager VMware Identity Manager 3.

Account Set Up Guide

Troubleshooting Exchange Calendaring Integrations

Professional mailbox Setup Guide

To: Proofpoint Protection Server administrators From: Proofpoint Re: Informing your user community about encrypting and decrypting secure

Fasthosts Customer Support Software Setup Guide. Professional Mailbox.

User guide NotifySCM Installer

One Identity Starling Two-Factor HTTP Module 2.1. Administration Guide

FAQ 106 How do I access and set up client applications? There are two ways to access a mailbox for sending and receiving messages:

VMware Identity Manager Connector Installation and Configuration (Legacy Mode)

Setting up Microsoft Exchange Server 2016 with Avi

This PDF Document was generated for free by the Aloaha PDF Suite If you want to learn how to make your own PDF Documents visit:

CYAN SECURE WEB Installing on Windows

Software Autodiscover Setup Guide

Manual Owa Exchange 2010 Url Redirect To

Password Change and Mail Client Configuration Guide for sltnet.lk/slt.lk Mail Server

Getting Started with Outlook Web App (OWA)

Hands-on Lab Exercise Guide

Exchange Server 2016 Client Access Namespace Configuration

Troubleshooting External Services (External Message Store, Calendar Integrations, Calendar Information for PCTRs) in Cisco Unity Connection 8.

Change NetSet Settings on an Apple ios 12 Mobile Device using the Mail app

Xplornet on an Apple ios 11 Device

MSP/ISP Multi-Tenant Archiving Platform Online Deployment Customer Activation 10-Step Quick Guide

D9.2.2 AD FS via SAML2

Office 365. Configuring an Additional Mailbox to an Client

VMWARE HORIZON CLOUD WITH VMWARE IDENTITY MANAGER QUICK START GUIDE WHITE PAPER MARCH 2018

Configuring Outlook from an Off-Campus Location to Use Enterprise Exchange

Using the Terminal Services Gateway Lesson 10

Microsoft Exchange Proxy Settings Outlook 2010 Gpo

Microsoft Outlook. How To Share A Departmental Mailbox s Calendar

Vision deliver a fast, easy to deploy and operate, economical solution that can provide high availability solution for exchange server

Resource Account Access in Outlook Web Best Practices for Resource Accounts s

The SSL device also supports the 64-bit Internet Explorer with new ActiveX loaders for Assessment, Abolishment, and the Access Client.

Exchange Migration Guide

Integration with Exchange 2003

Microsoft MB Microsoft Dynamics CRM 2016 Installation. Download Full version :

WatchGuard SSL Web UI 3.2 User Guide

Installation guide for Choic Multi User Edition

VMware Workspace ONE UEM VMware AirWatch Cloud Connector

OUTLOOK ANYWHERE CONNECTION GUIDE FOR USERS OF OUTLOOK 2007

Configure the IM and Presence Service

How do I setup Outlook Express to get my s?

BlackBerry Enterprise Server Express for Microsoft Exchange

BEST PRACTICES ARCHIVE in contentaccess

VMware AirWatch Cloud Connector Guide ACC Installation and Integration

Simplicity Itself. User Guide

Using the Orchestration Console in System Center 2012 R2 Orchestrator

AX Series with Microsoft Exchange Server 2010

GroupWise Mobility Quick Start for Microsoft Outlook Users

Configuring WebConnect

LifeSize Control Installation Guide

CUSTOMER CONTROL PANEL... 2 DASHBOARD... 3 HOSTING &

VII. Corente Services SSL Client

; Deploy Office Web Apps Server

Administration GUIDE. OnePass Agent for Exchange Mailbox. Published On: 11/19/2013 V10 Service Pack 4A Page 1 of 177

Deploying the BIG-IP System v11 with Microsoft Exchange 2010 and 2013 Client Access Servers

SETUP FOR OUTLOOK (Updated October, 2018)

PDF SHARE FORMS. Online, Offline, OnDemand. PDF forms and SharePoint are better together. PDF Share Forms Enterprise 3.0.

AD FS v3. Deployment Guide

On-demand target, up and running

Configuration Guide. BlackBerry UEM Cloud

Manual Owa Exchange 2010 Blank Page Error

VMware Enterprise Systems Connector Installation and Configuration. JULY 2018 VMware Identity Manager 3.2 VMware Identity Manager VMware AirWatch 9.

Microsoft Entourage 2008 Setup Guide

Help Document Series: Connecting to your Exchange mailbox via Outlook from off-campus

C IBM. IBM WebSphere App Server Network Deployment V8.0- Core Admin

VMware Enterprise Systems Connector Installation and Configuration

Microsoft Dynamics CRM Installation (MB2-708)

Kerio Connect. Step-by-Step. Kerio Technologies

StorageZones Controller 3.3

BlackBerry UEM Configuration Guide

Thunderbird POP Instructions Bloomsburg University Students

HySecure Quick Start Guide. HySecure 5.0

Deploying F5 with Microsoft Exchange 2016 Mailbox Servers

and Calendar at Home. Version 4

Version 1.0 Last updated: August 11, 2017 Author: Albert Wang & Mike Hull

Install Microsoft Exchange account in Outlook 2007

Microsoft Exchange Server 2007 and 2010 Operations

Clientless SSL VPN End User Set-up

Configuration Guide. BlackBerry UEM. Version 12.9

Deploy Hybrid Calendar Service for Microsoft Exchange

Syncplicity Panorama with Isilon Storage. Technote

Transcription:

WatchGuard XCS and Outlook Web Access 2013 The Secure WebMail proxy provides a highly secure mechanism for accessing Microsoft OWA (Outlook Web Access). OWA uses a very similar interface to Outlook and provides an attractive, easy to use remote interface for users to access their Exchange mailboxes remotely. With OWA, users can see all of their mail, contacts, and calendar using a web browser. As OWA is accessible from the Internet, its use presents a number of security challenges. The Secure WebMail Proxy feature is designed to support OWA use while protecting the system from Internet attacks. The OWA connection is managed using a full application proxy. The WatchGuard XCS completely recreates all HTTP and HTTPS requests made by the external client to the internal OWA Exchange server. In a typical deployment, OWA users will connect to the OWA interface via the public interface of the WatchGuard XCS. The WatchGuard XCS will then proxy the traffic via its private interface to the OWA server. The connection is secure because the requests by the OWA clients are recreated by the WatchGuard XCS. If the WatchGuard XCS is deployed in the DMZ network of a network firewall, OWA users will first connect to the public interface of the network firewall. The traffic is forwarded to the WatchGuard XCS and then the requests will be recreated and forwarded to the OWA server. On the network firewall, incoming port 443 needs to be opened from the public interface to the DMZ to allow traffic from the Internet to the WatchGuard XCS. Port 80 from the DMZ to the private network also needs to be configured to allow the WatchGuard XCS to connect to the OWA server. 1

Configure the Secure WebMail OWA proxy To configure the Secure WebMail proxy for OWA: 1. Select Configuration > WebMail > WebMail. 2. Click Add Server. 3. Specify the HTTP URL of the server where OWA is located in the Address field (including the ending / character), for example: http://exchange.example.com/owa/ 4. Enter an optional name to describe this server in the Label field. 5. Select any local users that will be allowed to use OWA by selecting the corresponding check box. Users can also be authenticated to OWA via Active Directory or another LDAP service. For more information, see Add a Directory Server on page 3. 6. Enable the Try WebMail ID/login first option if the LDAP user s samaccountname is equivalent to the mail attribute. The WatchGuard XCS sends the user account portion of the user s mail attribute to the OWA server by default (such as user in the address user@example.com). If this is different from the samaccountname attribute, the Try WebMail ID/login first option should not be selected. If it is selected, the user will get an invalid ID error message. The user must enter their user name and password again to gain access to OWA. 7. Click Apply. 8. Select Configuration > WebMail > WebMail. 9. Make sure that the Proxy mail option is enabled in the Access Types section. 2 WatchGuard XCS and Outlook Web Access 2013

10. Select Configuration > Network > Interfaces. 11. Make sure the WebMail option is enabled on the network interface from which users will be accessing WebMail. Add a Directory Server To add a directory server for remote authentication for users: 1. Select Configuration > LDAP > Directory Servers. 2. Enter your LDAP server configuration. 3. Click Apply. 3

Add Remote Authentication Configuration 1. Select Administration > Accounts > Remote Authentication. 2. Click New to add a new LDAP source. 3. Click Apply. 4. From the Default Server drop-down list, select the OWA server you created to use as the default LDAP user profile. 5. Click Apply. 4 WatchGuard XCS and Outlook Web Access 2013

Configure Outlook Web Access OWA (Outlook Web Access) provides a way to access Exchange server mailboxes and folders with standard web browsers. OWA 2013 is included with Microsoft Exchange server. Disable SSL for Outlook Web Access on the IIS Server OWA uses IIS (Internet Information Server) to access the Exchange server. Internal communications between the WatchGuard XCS and the OWA server are in plain HTTP, and you must disable SSL in your OWA settings. To configure IIS for use with OWA 2013: 1. Open the Internet Information Services (IIS) Manager. 2. Select [SERVERNAME] > Sites > Default Web Site > owa. 3. Select SSL Settings. 4. Disable the Require SSL option. 5. Restart IIS from PowerShell with the command: iisreset /noforce 5

Enable Basic Authentication The WatchGuard XCS only supports Basic Authentication when communicating with the OWA server. To make sure that Basic Authentication is installed on your IIS server: 1. Open the Internet Information Services (IIS) Manager. 2. Select Servers > Virtual Directories > OWA > Authentication. 3. Select Basic Authentication. If you do not see the Basic Authentication option, you must install the Basic Authentication module during the initial IIS installation. Select Server Manager > Roles > Web Server (IIS). Click Add Role Services. Make sure that Basic Authentication is installed. You may be prompted with a warning that you should switch the ECP authentication method to Basic Authentication. Perform this step in servers > virtual Directories > ecp > authentication. 4. Restart IIS by running the following command from the command line: iisreset /noforce 6 WatchGuard XCS and Outlook Web Access 2013

Disable the OWA Premium Client The WatchGuard XCS Secure WebMail Proxy does not support OWA Premium Client mode, and you must disable Premium Client mode in the OWA configuration. Public Folders are not available when using the regular client mode. 1. Open the Exchange Control Panel (ECP), then go to servers > virtual directories > owa > features. 2. Disable the Premium client option. 7

3. From Exchange Control Panel, go to permissions > Outlook Web App policies > default. 4. Disable the Premium client option. 5. Restart IIS by running the following command from the command line: iisreset /noforce 6. Test OWA and make sure the regular OWA2013 client is presented after you log in. 8 WatchGuard XCS and Outlook Web Access 2013