Czar,

We are using a similar archeticture but we are using static nat.  We assigned a 
static NAT for the frontend system and allow 443 to that only.  That is working 
ok for the past 3 months.

Regards,
Dave

Date:    Tue, 21 Apr 2009 06:20:11 +1000
From:    [email protected]
Subject: MS Exchange Active Sync and SSL

Hi,
 
I've configured a front end/back end exchange 2003 server. The front end is 
used only for active sync; the back end server does the main mail/smtp work.
The backend allows Outlook webaccess (form-based access) and it's working 
wonderfully. I've just added the front-end server only to do active sync.
 
I have allowed ssl (among others) on cpfw. I've assigned a public ip to the 
front-end server but hide behind it.
 
After configuring an iphone for exchange active sync, the packet reaches the fw 
but the packet is immediately dropped (under the drop rule which is the last 
rule). It seems my active sync rule is not being processed.
 
The rule is simple - accept any to front-end server ssl.
 
Any help, comments or ideas towards resolving this issue is appreciated.
 
Thanks
czar


Scanned by Check Point Total Security Gateway.

=================================================
To set vacation, Out-Of-Office, or away messages, send an email to 
[email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your subscription options, email 
[email protected] =================================================

------------------------------

Date:    Tue, 21 Apr 2009 01:27:19 +0300
From:    Eugeniu Patrascu <[email protected]>
Subject: Re: MS Exchange Active Sync and SSL

[email protected] wrote:
> Hi,
>  
> I've configured a front end/back end exchange 2003 server. The front 
> end is used only for active sync; the back end server does the main mail/smtp 
> work.
> The backend allows Outlook webaccess (form-based access) and it's 
> working wonderfully. I've just added the front-end server only to do active 
> sync.
>  
> I have allowed ssl (among others) on cpfw. I've assigned a public ip 
> to the front-end server but hide behind it.
>  
> After configuring an iphone for exchange active sync, the packet 
> reaches the fw but the packet is immediately dropped (under the drop 
> rule which is the last rule). It seems my active sync rule is not being 
> processed.
>   
What do the logs say ? Is Active Sync running on other port that 443 ? 
If so, do you have SSL tunneling detection and blocking activated in your 
SmartDefense ?
>  
> The rule is simple - accept any to front-end server ssl.
>  
> Any help, comments or ideas towards resolving this issue is appreciated.
>  
>   


Scanned by Check Point Total Security Gateway.

=================================================
To set vacation, Out-Of-Office, or away messages, send an email to 
[email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your subscription options, email 
[email protected] =================================================

------------------------------

End of FW-1-MAILINGLIST Digest - 17 Apr 2009 to 20 Apr 2009 (#2009-70)
**********************************************************************

Scanned by Check Point Total Security Gateway.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

Reply via email to