Guest User!

You are not Sophos Staff.

[9.170][BUG] WAF Problem Outlook Web App no longer works

Release 9.170-21. OWA no longer works. Here are the logs:

2013:11:22-23:18:39 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="0" user="-" host="109.44.102.34" method="GET" statuscode="301" reason="-" extra="-" exceptions="-" time="9291661" url="/owa" server="my.domain.de" referer="-" cookie="WhlPII=2" set-cookie="-"
2013:11:22-23:18:39 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="0" user="-" host="109.44.102.34" method="GET" statuscode="302" reason="-" extra="-" exceptions="-" time="161055" url="/owa/" server="my.domain.de" referer="-" cookie="WhlPII=2" set-cookie="sessionid=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT, cadata=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT"
2013:11:22-23:18:40 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="752" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="539215" url="/owa/auth/logon.aspx" server="my.domain.de" referer="-" cookie="WhlPII=2" set-cookie="OutlookSession=81b85f96e2cc4f2a9b798f42f2231409; path=/; secure; HttpOnly"
2013:11:22-23:18:40 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="891" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="85501" url="/owa/14.2.347.0/themes/resources/logon.css" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:40 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="1571" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="31950" url="/owa/14.2.347.0/themes/resources/owafont.css" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:40 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="1658" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="45833" url="/owa/14.2.347.0/scripts/premium/flogon.js" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:41 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="3112" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="52793" url="/owa/auth/logon.aspx" server="my.domain.de" referer="-" cookie="WhlPII=2; OutlookSession=81b85f96e2cc4f2a9b798f42f2231409" set-cookie="-"
2013:11:22-23:18:41 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="4450" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="23680" url="/owa/14.2.347.0/themes/resources/lgntopl.gif" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:41 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="550" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="24330" url="/owa/14.2.347.0/themes/resources/lgntopr.gif" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:41 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="61" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="29681" url="/owa/14.2.347.0/themes/resources/lgnexlogo.gif" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:41 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="742" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="19906" url="/owa/14.2.347.0/themes/resources/favicon.ico" server="my.domain.de" referer="-" cookie="-" set-cookie="OutlookSession=259a54e77a344c8e8732d120b7d67050; path=/; secure; HttpOnly"
2013:11:22-23:18:41 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="9303" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="38640" url="/owa/14.2.347.0/themes/resources/lgnbotl.gif" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:41 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="329" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="15664" url="/owa/14.2.347.0/themes/resources/lgnright.gif" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:41 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="2367" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="31845" url="/owa/14.2.347.0/themes/resources/lgnbotr.gif" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:41 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="313" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="8094" url="/owa/14.2.347.0/themes/resources/lgnleft.gif" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:41 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="58" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="7549" url="/owa/14.2.347.0/themes/resources/lgntopm.gif" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:41 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="249" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="9130" url="/owa/14.2.347.0/themes/resources/lgnbotm.gif" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:51 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="0" user="-" host="109.44.102.34" method="POST" statuscode="302" reason="-" extra="-" exceptions="-" time="68584" url="/owa/auth.owa" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:51 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="763" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="13943" url="/owa/auth/logon.aspx" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:51 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="3191" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="21048" url="/owa/auth/logon.aspx" server="my.domain.de" referer="-" cookie="cookieTest=1; logondata=acc=0&lgn=klaus; WhlPII=2; OutlookSession=81b85f96e2cc4f2a9b798f42f2231409; PBack=0" set-cookie="-"
2013:11:22-23:18:59 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="0" user="-" host="109.44.102.34" method="POST" statuscode="302" reason="-" extra="-" exceptions="-" time="15426" url="/owa/auth.owa" server="my.domain.de" referer="my.domain.de/.../logon.aspx
2013:11:22-23:18:59 asg-1 reverseproxy: srcip="109.44.102.34" localip="172.16.10.10" size="763" user="-" host="109.44.102.34" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="13630" url="/owa/auth/logon.aspx" server="my.domain.de" referer="my.domain.de/.../logon.aspx

the System time is correct [:S]
€dit
On the utm is no Reverse authentication configured. on the Exchange Server is Formebased Auth configured.
Parents
  • Yeah ever since latest Up2Date I am having the same issue with forms based reverse auth. Keeps saying password mismatch:

    2014:02:08-14:50:19 portal reverseproxy: _Sat Feb 08 14:50:19.905974 2014_ _authn_aua:error_ _pid 18414:tid 4122024816_ _client 205.206.186.112:62387_ found expired _timeout_ session for user _dfolk_, expired by 108, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:50:19 portal reverseproxy: _Sat Feb 08 14:50:19.906006 2014_ _auth_form:error_ _pid 18414:tid 4122024816_ _client 205.206.186.112:62387_ AH01807: user _dfolk_: authentication failure for _/OWALogin_login_: password Mismatch, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:50:20 portal reverseproxy: srcip=_205.206.186.112_ localip=_68.179.58.83_ size=_185_ user=_dfolk_ host=_205.206.186.112_ method=_POST_ statuscode=_302_ reason=_-_ extra=_-_ exceptions=_SkipURLHardening, SkipFormHardening_ time=_151416_ url=_/OWALogin_login_ server=_mail.domain.com_ referer=_mail.domain.com/.../_ is not allowed, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:50:20 portal reverseproxy: _Sat Feb 08 14:50:20.121154 2014_ _auth_form:error_ _pid 18414:tid 4122024816_ _client 205.206.186.112:62387_ AH01807: user _dfolk_: authentication failure for _/_: password Mismatch, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:50:20 portal reverseproxy: srcip=_205.206.186.112_ localip=_68.179.58.83_ size=_198_ user=_dfolk_ host=_205.206.186.112_ method=_GET_ statuscode=_302_ reason=_-_ extra=_-_ exceptions=_SkipURLHardening_ time=_35056_ url=_/_ server=_mail.domain.com_ referer=_mail.domain.com/.../OWALogin_form_ cookie=___utma=178264369.1627797870.1391294698.1391294698.1391294698.1_ __utmz=178264369.1391294698.1.1.utmcsr=_direct__utmccn=_direct__utmcmd=_none__ set-cookie=_OWALogin_cookie=AVatOJELEeOmeo98dXVteYY 9SAoZ582zgkzjfvwXEFE+WqKiFMBeFCRhgyNsrxil2VtSuHfNigpPMtMH2ZnLsP9mW9MB8UPIy/rJrRlPWM=_path=/_httponly_secure, OWALogin_cookie=AVatOJELEeOmeo98dXVteYY+9SAoZ582zgkzjfvwXEFE+WqKiFMBeFCRhgyNsrxil2VtSuHfNigpPMtMH2ZnLsP9mW9MB8UPIy/rJrRlPWM=_path=/_httponly_secure_ 2014:02:08-14:50:20 portal reverseproxy: srcip=_205.206.186.112_ localip=_68.179.58.83_ size=_0_ user=_-_ host=_205.206.186.112_ method=_GET_ statuscode=_304_ reason=_-_ extra=_-_ exceptions=_SkipURLHardening_ time=_35189_ url=_/REF_RevAutOwaLogin/company_logo.png_ server=_mail.domain.com_ referer=_mail.domain.com/.../_httponly_secure_ 2014:02:08-14:50:20 portal reverseproxy: srcip=_205.206.186.112_ localip=_68.179.58.83_ size=_0_ user=_-_ host=_205.206.186.112_ method=_GET_ statuscode=_304_ reason=_-_ extra=_-_ exceptions=_SkipURLHardening_ time=_34458_ url=_/OWALogin_form_ server=_mail.domain.com_ referer=_-_ cookie=___utma=178264369.1627797870.1391294698.1391294698.1391294698.1_ __utmz=178264369.1391294698.1.1.utmcsr=_direct__utmccn=_direct__utmcmd=_none__ set-cookie=_OWALogin_cookie=AZssdJELEeOmeo98dXVtecdA6Qpiu+cL/UAjhwJSbFjVlRaKz7V2aK4GFj1SMFbEQewC+uFz+myfhGPRBqJEV5JBl+caQgovL/3R4AS5QPI=_path=/_httponly_secure, OWALogin_cookie=AZssdJELEeOmeo98dXVtecdA6Qpiu+cL/UAjhwJSbFjVlRaKz7V2aK4GFj1SMFbEQewC+uFz+myfhGPRBqJEV5JBl+caQgovL/3R4AS5QPI=_path=/_httponly_secure_ 2014:02:08-14:50:43 portal reverseproxy: srcip=_209.91.107.161_ localip=_68.179.58.83_ size=_25_ user=_-_ host=_209.91.107.161_ method=_POST_ statuscode=_200_ reason=_-_ extra=_-_ exceptions=_-_ time=_32673_ url=_/Microsoft-Server-ActiveSync_ server=_mail.domain.com_ referer=_-_ cookie=_-_ set-cookie=_OWALogin_cookie=_Max-Age=0_path=/_httponly_secure, OWALogin_cookie=_Max-Age=0_path=/_httponly_secure_ 2014:02:08-14:51:20 portal reverseproxy: _Sat Feb 08 14:51:20.269837 2014_ _authn_aua:error_ _pid 18414:tid 3937385328_ _client 205.206.186.112:63039_ found expired _timeout_ session for user _dfolk_, expired by 60, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:51:20 portal reverseproxy: _Sat Feb 08 14:51:20.269880 2014_ _auth_form:error_ _pid 18414:tid 3937385328_ _client 205.206.186.112:63039_ AH01807: user _dfolk_: authentication failure for _/OWALogin_login_: password Mismatch, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:51:20 portal reverseproxy: _Sat Feb 08 14:51:20.317987 2014_ _auth_form:error_ _pid 18414:tid 3937385328_ _client 205.206.186.112:63039_ AH01807: user _dfolk@domain.com_: authentication failure for _/OWALogin_login_: password Mismatch, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:51:20 portal reverseproxy: srcip=_205.206.186.112_ localip=_68.179.58.83_ size=_198_ user=_dfolk@domain.com_ host=_205.206.186.112_ method=_POST_ statuscode=_302_ reason=_-_ extra=_-_ exceptions=_SkipURLHardening, SkipFormHardening_ time=_81559_ url=_/OWALogin_login_ server=_mail.domain.com_ referer=_mail.domain.com/.../OWALogin_form_ cookie=___utma=178264369.1627797870.1391294698.1391294698.1391294698.1_ __utmz=178264369.1391294698.1.1.utmcsr=_direct__utmccn=_direct__utmcmd=_none__ set-cookie=_OWALogin_cookie=JTub5pELEeOmeo98dXVteTc6ztQtvCqkrd5qOO7EfZZ8zwMPXkqNqnD3hIeZPE96Rsv4WtZO/pB2/kO4dL0i8QgVYtkVxD9Gr7nNw+NIltw=_path=/_httponly_secure, OWALogin_cookie=JTub5pELEeOmeo98dXVteTc6ztQtvCqkrd5qOO7EfZZ8zwMPXkqNqnD3hIeZPE96Rsv4WtZO/pB2/kO4dL0i8QgVYtkVxD9Gr7nNw+NIltw=_path=/_httponly_secure_ 2014:02:08-14:51:20 portal reverseproxy: srcip=_205.206.186.112_ localip=_68.179.58.83_ size=_0_ user=_-_ host=_205.206.186.112_ method=_GET_ statuscode=_304_ reason=_-_ extra=_-_ exceptions=_SkipURLHardening_ time=_40411_ url=_/REF_RevAutOwaLogin/company_logo.png_ server=_mail.domain.com_ referer=_mail.domain.com/.../_httponly_secure_
Reply
  • Yeah ever since latest Up2Date I am having the same issue with forms based reverse auth. Keeps saying password mismatch:

    2014:02:08-14:50:19 portal reverseproxy: _Sat Feb 08 14:50:19.905974 2014_ _authn_aua:error_ _pid 18414:tid 4122024816_ _client 205.206.186.112:62387_ found expired _timeout_ session for user _dfolk_, expired by 108, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:50:19 portal reverseproxy: _Sat Feb 08 14:50:19.906006 2014_ _auth_form:error_ _pid 18414:tid 4122024816_ _client 205.206.186.112:62387_ AH01807: user _dfolk_: authentication failure for _/OWALogin_login_: password Mismatch, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:50:20 portal reverseproxy: srcip=_205.206.186.112_ localip=_68.179.58.83_ size=_185_ user=_dfolk_ host=_205.206.186.112_ method=_POST_ statuscode=_302_ reason=_-_ extra=_-_ exceptions=_SkipURLHardening, SkipFormHardening_ time=_151416_ url=_/OWALogin_login_ server=_mail.domain.com_ referer=_mail.domain.com/.../_ is not allowed, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:50:20 portal reverseproxy: _Sat Feb 08 14:50:20.121154 2014_ _auth_form:error_ _pid 18414:tid 4122024816_ _client 205.206.186.112:62387_ AH01807: user _dfolk_: authentication failure for _/_: password Mismatch, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:50:20 portal reverseproxy: srcip=_205.206.186.112_ localip=_68.179.58.83_ size=_198_ user=_dfolk_ host=_205.206.186.112_ method=_GET_ statuscode=_302_ reason=_-_ extra=_-_ exceptions=_SkipURLHardening_ time=_35056_ url=_/_ server=_mail.domain.com_ referer=_mail.domain.com/.../OWALogin_form_ cookie=___utma=178264369.1627797870.1391294698.1391294698.1391294698.1_ __utmz=178264369.1391294698.1.1.utmcsr=_direct__utmccn=_direct__utmcmd=_none__ set-cookie=_OWALogin_cookie=AVatOJELEeOmeo98dXVteYY 9SAoZ582zgkzjfvwXEFE+WqKiFMBeFCRhgyNsrxil2VtSuHfNigpPMtMH2ZnLsP9mW9MB8UPIy/rJrRlPWM=_path=/_httponly_secure, OWALogin_cookie=AVatOJELEeOmeo98dXVteYY+9SAoZ582zgkzjfvwXEFE+WqKiFMBeFCRhgyNsrxil2VtSuHfNigpPMtMH2ZnLsP9mW9MB8UPIy/rJrRlPWM=_path=/_httponly_secure_ 2014:02:08-14:50:20 portal reverseproxy: srcip=_205.206.186.112_ localip=_68.179.58.83_ size=_0_ user=_-_ host=_205.206.186.112_ method=_GET_ statuscode=_304_ reason=_-_ extra=_-_ exceptions=_SkipURLHardening_ time=_35189_ url=_/REF_RevAutOwaLogin/company_logo.png_ server=_mail.domain.com_ referer=_mail.domain.com/.../_httponly_secure_ 2014:02:08-14:50:20 portal reverseproxy: srcip=_205.206.186.112_ localip=_68.179.58.83_ size=_0_ user=_-_ host=_205.206.186.112_ method=_GET_ statuscode=_304_ reason=_-_ extra=_-_ exceptions=_SkipURLHardening_ time=_34458_ url=_/OWALogin_form_ server=_mail.domain.com_ referer=_-_ cookie=___utma=178264369.1627797870.1391294698.1391294698.1391294698.1_ __utmz=178264369.1391294698.1.1.utmcsr=_direct__utmccn=_direct__utmcmd=_none__ set-cookie=_OWALogin_cookie=AZssdJELEeOmeo98dXVtecdA6Qpiu+cL/UAjhwJSbFjVlRaKz7V2aK4GFj1SMFbEQewC+uFz+myfhGPRBqJEV5JBl+caQgovL/3R4AS5QPI=_path=/_httponly_secure, OWALogin_cookie=AZssdJELEeOmeo98dXVtecdA6Qpiu+cL/UAjhwJSbFjVlRaKz7V2aK4GFj1SMFbEQewC+uFz+myfhGPRBqJEV5JBl+caQgovL/3R4AS5QPI=_path=/_httponly_secure_ 2014:02:08-14:50:43 portal reverseproxy: srcip=_209.91.107.161_ localip=_68.179.58.83_ size=_25_ user=_-_ host=_209.91.107.161_ method=_POST_ statuscode=_200_ reason=_-_ extra=_-_ exceptions=_-_ time=_32673_ url=_/Microsoft-Server-ActiveSync_ server=_mail.domain.com_ referer=_-_ cookie=_-_ set-cookie=_OWALogin_cookie=_Max-Age=0_path=/_httponly_secure, OWALogin_cookie=_Max-Age=0_path=/_httponly_secure_ 2014:02:08-14:51:20 portal reverseproxy: _Sat Feb 08 14:51:20.269837 2014_ _authn_aua:error_ _pid 18414:tid 3937385328_ _client 205.206.186.112:63039_ found expired _timeout_ session for user _dfolk_, expired by 60, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:51:20 portal reverseproxy: _Sat Feb 08 14:51:20.269880 2014_ _auth_form:error_ _pid 18414:tid 3937385328_ _client 205.206.186.112:63039_ AH01807: user _dfolk_: authentication failure for _/OWALogin_login_: password Mismatch, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:51:20 portal reverseproxy: _Sat Feb 08 14:51:20.317987 2014_ _auth_form:error_ _pid 18414:tid 3937385328_ _client 205.206.186.112:63039_ AH01807: user _dfolk@domain.com_: authentication failure for _/OWALogin_login_: password Mismatch, referer: https://mail.domain.com/OWALogin_form 2014:02:08-14:51:20 portal reverseproxy: srcip=_205.206.186.112_ localip=_68.179.58.83_ size=_198_ user=_dfolk@domain.com_ host=_205.206.186.112_ method=_POST_ statuscode=_302_ reason=_-_ extra=_-_ exceptions=_SkipURLHardening, SkipFormHardening_ time=_81559_ url=_/OWALogin_login_ server=_mail.domain.com_ referer=_mail.domain.com/.../OWALogin_form_ cookie=___utma=178264369.1627797870.1391294698.1391294698.1391294698.1_ __utmz=178264369.1391294698.1.1.utmcsr=_direct__utmccn=_direct__utmcmd=_none__ set-cookie=_OWALogin_cookie=JTub5pELEeOmeo98dXVteTc6ztQtvCqkrd5qOO7EfZZ8zwMPXkqNqnD3hIeZPE96Rsv4WtZO/pB2/kO4dL0i8QgVYtkVxD9Gr7nNw+NIltw=_path=/_httponly_secure, OWALogin_cookie=JTub5pELEeOmeo98dXVteTc6ztQtvCqkrd5qOO7EfZZ8zwMPXkqNqnD3hIeZPE96Rsv4WtZO/pB2/kO4dL0i8QgVYtkVxD9Gr7nNw+NIltw=_path=/_httponly_secure_ 2014:02:08-14:51:20 portal reverseproxy: srcip=_205.206.186.112_ localip=_68.179.58.83_ size=_0_ user=_-_ host=_205.206.186.112_ method=_GET_ statuscode=_304_ reason=_-_ extra=_-_ exceptions=_SkipURLHardening_ time=_40411_ url=_/REF_RevAutOwaLogin/company_logo.png_ server=_mail.domain.com_ referer=_mail.domain.com/.../_httponly_secure_
Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?