This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Question regarding certificates generated by Astaro...

Hi,

I've published my exchange server through UTM successfully. 

Sometimes my users will get an outlook error regarding an untrusted certificate if they connect/disconnct a VPN session.  That certificate has the following netscape comment...

 

"Generated by Astaro HTTP Proxy"

 

Can anyone tell me why this might happen?



This thread was automatically locked due to age.
  • Not sure, but it looks like once you connect through VPN your client's HTTPS traffic is decrypted and scanned and thus it will send traffic back using its proxy certificate.

  • Shaun, can you get a screencap to show us?

    Cheers - Bob

  • I'll try and post a screen cap later.

    I'm wondering if this is a WPAD/Proxyconfig.pac issue.  We use both on our internal network so that sites (like our exchange servers) are connected to directly - this works fine for us.  Our VPN clients get their IP's either using a static IP set on their domain account, or assigned by UTM from the VPN L2TP pool.  My question: in this situation, when a client connects via VPN would the WPAD.DAT or PROXYCONFIG.PAC scripts be obeyed?

     

  • Here's the promised screencap...

     

  • Do you use Exchange 365?

    I had an issue which bugged me for weeks, until I found out that this was an issue as Microsoft were changing a few settings, and this exact error would appear.

    it appears every now and again when using Outlook, it is usually when (back-end) servers change and the certificate is not trusted.

  • Sorry no - our exchange is on premisis, and I know the certs are fine.  As I said, this ONLY happens when a user intiates or drops a VPN connection to the company network.

  • Hi Shaun,

    Please refer the guide, Sophos UTM for Microsoft Exchange services and verify the configuration. Also, which VPN type do you use here? Is this an intermittent issue that is caused to some users?

    Thanks

  • I'm happy with my Exchange publishing.  My users are currently using outlook from both outside and inside the office with no problems.

    The ONLY time I see this is when a user is connected to Exchange, either via the internet or via VPN to the company.  If the user either connects or disconnects from a VPN session to the company through UTM, THEN the message MAY be displayed.  The users are connecting through UTM using standard microsoft L2TP VPN connections

    I can't shake the idea that this happens because of a change of connection.  If an outlook client is connected via the external publishing, and then the user Initiates a VPN connection, the traffic flow changes from standard to tunneled - maybe it becomes subject to the HTTPS detection at that point?  Same thing happens in reverse when the connection drops.  At those points, would UTM supply it's own certificate rather than the one in the publishing rule?