IBM Security Verify

 View Only
  • 1.  Connecting to Exchange Server with Outlook via WebSEAL

    Posted Mon February 01, 2021 02:51 AM
    I have setup Security Verify Access 10 and performed the following steps:`

    1. Created a Reverse Proxy instance that listens on port 443
    2. Tried connecting to mail (microsoft exchange server) via Outlook Client by specifying WebSEAL's IP address in the server field.
    3. The outlook successfully connects and syncs with the mail server

    However, I get only unauthenticated request logs in the WebSEAL log file as below:

    192.168.0.30 - unauthenticated 01/Feb/2021:01:32:00 +0500 "OPTIONS /Microsoft-Server-ActiveSync?User=babar.hussain&DeviceId=CD205584ED32160CB8DD57485C723897&DeviceType=WindowsMail HTTP/1.1" 200 12459
    192.168.0.30 - unauthenticated 01/Feb/2021:01:32:12 +0500 "POST /Microsoft-Server-ActiveSync?User=babar.hussain&DeviceId=CD205584ED32160CB8DD57485C723897&DeviceType=WindowsMail&Cmd=FolderSync HTTP/1.1" 200 12459

    Note: I have not made any changes to any ACL in place. (using default ACLs)

    Did anyone else try this and face the same issue? Where WebSEAL allows outlook client to connect to mail server with unauthenticated requests.



    ------------------------------
    Muhammad Talha
    ------------------------------


  • 2.  RE: Connecting to Exchange Server with Outlook via WebSEAL

    Posted Fri August 06, 2021 03:16 PM
    Hi Muhammad,

    Which Outlook client version did you use in that connection?

    Regards,
    Rodrigo

    ------------------------------
    Rodrigo Xavier
    ------------------------------



  • 3.  RE: Connecting to Exchange Server with Outlook via WebSEAL

    Posted Mon August 09, 2021 03:40 AM
    G'Day Muhammad.

    A few questions -
    1. what authentication options do you have enabled for your WebSEAL instance - Basic, Client Certificate, other (assuming it's one of the first two)

    2. what type of junction - Transparent Path, Standard with Junction Mapping Table, Virtual Host

    3. what -b option (HTTP Basic Authentication Header on Identity tab) do you have enabled on the junction?


    4. are you running this scenario as part of the Email Access Gateway (EAG) with IBM Security MaaS360, or your own deployment scenario?


    ------------------------------
    Scott Andrews
    ------------------------------