<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Secure Exchange Webservices with Sophos UTM WAF	</title>
	<atom:link href="https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/feed/" rel="self" type="application/rss+xml" />
	<link>https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/</link>
	<description>Share your knowledge!</description>
	<lastBuildDate>Sun, 08 Apr 2018 09:03:36 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>
	<item>
		<title>
		By: Ian Green		</title>
		<link>https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1613</link>

		<dc:creator><![CDATA[Ian Green]]></dc:creator>
		<pubDate>Sun, 08 Apr 2018 09:03:36 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=998#comment-1613</guid>

					<description><![CDATA[Thanks Michel,

I have it working, kind of. I get to the RDWeb page no issue, I can log in and get the RDP icon, the web page has the correct secure server certificate with the same name as the RDS server in the browser. When I connect to the RDP session, the RDP client launches and requests User credentials, I enter these and I get the error:- &quot;Your computer can&#039;t connect to the remote computer because the Remote Desktop Gateway server address requested and the certificate subject do not match.&quot; When I look at the certificate in the error, it is the mail certificate for OWA &#038; Exchange.
I have added a third network card to the UTM and used this for the RDS connection so as to separate the RDS &#038; Mail connections and it makes no difference.
1. I have both Mail &#038; RDS Certificates loaded onto the Sophos UTM.
2. I have ensured that the RDS rule in the &quot;Web Application Firewall&quot; has the correct certificate applied to it.
3. I have ensured that the RDS certificate is applied to the RDS server in the Config and that the Mail Certificate is not on the server.

I do only have 1 external IP Address, but as I am using 2 different NIC&#039;s for the Mail and RDS I did not think this would be an issue.
I have googled this error and tried most of the fixes, none have worked.

If you have any insight that would be greatly appreciated, thank you. :-)]]></description>
			<content:encoded><![CDATA[<p>Thanks Michel,</p>
<p>I have it working, kind of. I get to the RDWeb page no issue, I can log in and get the RDP icon, the web page has the correct secure server certificate with the same name as the RDS server in the browser. When I connect to the RDP session, the RDP client launches and requests User credentials, I enter these and I get the error:- &#8220;Your computer can&#8217;t connect to the remote computer because the Remote Desktop Gateway server address requested and the certificate subject do not match.&#8221; When I look at the certificate in the error, it is the mail certificate for OWA &amp; Exchange.<br />
I have added a third network card to the UTM and used this for the RDS connection so as to separate the RDS &amp; Mail connections and it makes no difference.<br />
1. I have both Mail &amp; RDS Certificates loaded onto the Sophos UTM.<br />
2. I have ensured that the RDS rule in the &#8220;Web Application Firewall&#8221; has the correct certificate applied to it.<br />
3. I have ensured that the RDS certificate is applied to the RDS server in the Config and that the Mail Certificate is not on the server.</p>
<p>I do only have 1 external IP Address, but as I am using 2 different NIC&#8217;s for the Mail and RDS I did not think this would be an issue.<br />
I have googled this error and tried most of the fixes, none have worked.</p>
<p>If you have any insight that would be greatly appreciated, thank you. :-)</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Michel		</title>
		<link>https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1611</link>

		<dc:creator><![CDATA[Michel]]></dc:creator>
		<pubDate>Fri, 06 Apr 2018 14:27:21 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=998#comment-1611</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1608&quot;&gt;Ian Green&lt;/a&gt;.

Hi Ian,

I think this is very easy, just configure port 442 in the virtual webserver and configure your remote desktop connection gateway in &quot;mstsc&quot; with &quot;server.customer.com:442&quot;]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1608">Ian Green</a>.</p>
<p>Hi Ian,</p>
<p>I think this is very easy, just configure port 442 in the virtual webserver and configure your remote desktop connection gateway in &#8220;mstsc&#8221; with &#8220;server.customer.com:442&#8221;</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Ian Green		</title>
		<link>https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1608</link>

		<dc:creator><![CDATA[Ian Green]]></dc:creator>
		<pubDate>Fri, 06 Apr 2018 02:27:33 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=998#comment-1608</guid>

					<description><![CDATA[Hi Michel

Do you have any documentation you can share on publishing an HTTPS connection to a Windows RDS (Remote Desktop Server) through UTM using port 442 or another port, as port 443 is used for OWA and we only have a single external IP Address?
Thank you.]]></description>
			<content:encoded><![CDATA[<p>Hi Michel</p>
<p>Do you have any documentation you can share on publishing an HTTPS connection to a Windows RDS (Remote Desktop Server) through UTM using port 442 or another port, as port 443 is used for OWA and we only have a single external IP Address?<br />
Thank you.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Martin Lindemann Frederiksen		</title>
		<link>https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1526</link>

		<dc:creator><![CDATA[Martin Lindemann Frederiksen]]></dc:creator>
		<pubDate>Thu, 01 Feb 2018 15:06:18 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=998#comment-1526</guid>

					<description><![CDATA[Paul Fischer:
Do Not use infrastructure rules in exceptions!

When you look at WAF live logs, there is and ID before the infrastructure ID, it&#039;s THAT ID you need to put in the exception :-)
https://community.sophos.com/kb/en-us/121446

best regards
Martin]]></description>
			<content:encoded><![CDATA[<p>Paul Fischer:<br />
Do Not use infrastructure rules in exceptions!</p>
<p>When you look at WAF live logs, there is and ID before the infrastructure ID, it&#8217;s THAT ID you need to put in the exception :-)<br />
<a href="https://community.sophos.com/kb/en-us/121446" rel="nofollow ugc">https://community.sophos.com/kb/en-us/121446</a></p>
<p>best regards<br />
Martin</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Michel		</title>
		<link>https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1525</link>

		<dc:creator><![CDATA[Michel]]></dc:creator>
		<pubDate>Thu, 01 Feb 2018 15:02:06 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=998#comment-1525</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1524&quot;&gt;Paul Fisher&lt;/a&gt;.

Yeah that is a normal warning :-)]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1524">Paul Fisher</a>.</p>
<p>Yeah that is a normal warning :-)</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Paul Fisher		</title>
		<link>https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1524</link>

		<dc:creator><![CDATA[Paul Fisher]]></dc:creator>
		<pubDate>Thu, 01 Feb 2018 14:46:59 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=998#comment-1524</guid>

					<description><![CDATA[Setting up the &#039;Exchange OWA&#039; Firewall profile, I get an:

&#039;The list of skipped filter rules contains the following required infrastructure rules: 981176, 981203, 981204. Disabling a required infrastructure rule can lead to attacks not being blocked by the Web Application Firewall.&#039;

It lets me save it.]]></description>
			<content:encoded><![CDATA[<p>Setting up the &#8216;Exchange OWA&#8217; Firewall profile, I get an:</p>
<p>&#8216;The list of skipped filter rules contains the following required infrastructure rules: 981176, 981203, 981204. Disabling a required infrastructure rule can lead to attacks not being blocked by the Web Application Firewall.&#8217;</p>
<p>It lets me save it.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Michel		</title>
		<link>https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1523</link>

		<dc:creator><![CDATA[Michel]]></dc:creator>
		<pubDate>Thu, 01 Feb 2018 10:56:38 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=998#comment-1523</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1521&quot;&gt;Paul Fisher&lt;/a&gt;.

Hi Paul,

yeah I would skip them as well.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1521">Paul Fisher</a>.</p>
<p>Hi Paul,</p>
<p>yeah I would skip them as well.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Paul Fisher		</title>
		<link>https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1521</link>

		<dc:creator><![CDATA[Paul Fisher]]></dc:creator>
		<pubDate>Tue, 30 Jan 2018 21:56:07 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=998#comment-1521</guid>

					<description><![CDATA[On he &#039;exception for Outlook Anywhere&#039;, you says select everything and then list individual items. I assume Sophos added some as &#039;outbound&#039; and &#039;true file type control&#039; wasn&#039;t listed. Should I skip them as well?]]></description>
			<content:encoded><![CDATA[<p>On he &#8216;exception for Outlook Anywhere&#8217;, you says select everything and then list individual items. I assume Sophos added some as &#8216;outbound&#8217; and &#8216;true file type control&#8217; wasn&#8217;t listed. Should I skip them as well?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Michel		</title>
		<link>https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1480</link>

		<dc:creator><![CDATA[Michel]]></dc:creator>
		<pubDate>Fri, 15 Dec 2017 13:53:34 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=998#comment-1480</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1479&quot;&gt;Philipp&lt;/a&gt;.

Hi Philipp,

I would recommend doing this directly on the Microsoft IIS]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1479">Philipp</a>.</p>
<p>Hi Philipp,</p>
<p>I would recommend doing this directly on the Microsoft IIS</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Philipp		</title>
		<link>https://networkguy.de/secure-exchange-webservices-with-sophos-utm-waf/#comment-1479</link>

		<dc:creator><![CDATA[Philipp]]></dc:creator>
		<pubDate>Fri, 15 Dec 2017 10:00:19 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=998#comment-1479</guid>

					<description><![CDATA[Hi Michael

Amazing Article! thank you! 

Do you by any chance know if there are some issues with this configuration if you set up a redirection from &#039;/&#039; to &#039;/owa&#039; ?

If have set it up that way, with the Site Path Rules for all the Other Paths but I didn&#039;t get it to work without any Firewall Profile.]]></description>
			<content:encoded><![CDATA[<p>Hi Michael</p>
<p>Amazing Article! thank you! </p>
<p>Do you by any chance know if there are some issues with this configuration if you set up a redirection from &#8216;/&#8217; to &#8216;/owa&#8217; ?</p>
<p>If have set it up that way, with the Site Path Rules for all the Other Paths but I didn&#8217;t get it to work without any Firewall Profile.</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
