Czar, We are using a similar archeticture but we are using static nat. We assigned a static NAT for the frontend system and allow 443 to that only. That is working ok for the past 3 months.
Regards, Dave Date: Tue, 21 Apr 2009 06:20:11 +1000 From: [email protected] Subject: MS Exchange Active Sync and SSL Hi, I've configured a front end/back end exchange 2003 server. The front end is used only for active sync; the back end server does the main mail/smtp work. The backend allows Outlook webaccess (form-based access) and it's working wonderfully. I've just added the front-end server only to do active sync. I have allowed ssl (among others) on cpfw. I've assigned a public ip to the front-end server but hide behind it. After configuring an iphone for exchange active sync, the packet reaches the fw but the packet is immediately dropped (under the drop rule which is the last rule). It seems my active sync rule is not being processed. The rule is simple - accept any to front-end server ssl. Any help, comments or ideas towards resolving this issue is appreciated. Thanks czar Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] ================================================= ------------------------------ Date: Tue, 21 Apr 2009 01:27:19 +0300 From: Eugeniu Patrascu <[email protected]> Subject: Re: MS Exchange Active Sync and SSL [email protected] wrote: > Hi, > > I've configured a front end/back end exchange 2003 server. The front > end is used only for active sync; the back end server does the main mail/smtp > work. > The backend allows Outlook webaccess (form-based access) and it's > working wonderfully. I've just added the front-end server only to do active > sync. > > I have allowed ssl (among others) on cpfw. I've assigned a public ip > to the front-end server but hide behind it. > > After configuring an iphone for exchange active sync, the packet > reaches the fw but the packet is immediately dropped (under the drop > rule which is the last rule). It seems my active sync rule is not being > processed. > What do the logs say ? Is Active Sync running on other port that 443 ? If so, do you have SSL tunneling detection and blocking activated in your SmartDefense ? > > The rule is simple - accept any to front-end server ssl. > > Any help, comments or ideas towards resolving this issue is appreciated. > > Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] ================================================= ------------------------------ End of FW-1-MAILINGLIST Digest - 17 Apr 2009 to 20 Apr 2009 (#2009-70) ********************************************************************** Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] =================================================
