Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WAF issues after updating to 9.709-3

Hi,

anyone else noticed that after updating to 9.709-3 Exchange Web Services is not working anymore? We get HTTP Error 500 when connecting to EWS published trhrough WAF. Also, the virtual server changes to orange when this error occurs. Accessing EWS through the browser shows the service page after authentication, but when interacting with EWS by using the Exchange Remote Connectivity Analyzer or EWS Editor generates the HTTP 500 error and the WAF rule turns orange.

When directly connecting to EWS and bypassing UTM works fine and we can interact with EWS.

Before the update everything worked fine.

Franc.



This thread was automatically locked due to age.
Parents
  • I must admit, I have SEVERAL services, including Exchange 2016 sitting behind my WAF, and so far, this update has not caused these issues. From time to time, an update may break Lets Encrypt renewals or new cert sign up processes, but one way or another I do manage to get that working again. I followed the usual update process from within the management console, so just thought I would share my experience. Hopefully they fix whatever is causing these issues for you guys. 

  • Hi David, as far as I know, it's not an on-prem, but hybrid issue, like described by several people.

    e.g. Connection to on-prem EWS behind WAF. Since it's hybrid there is a redirect to O365. Problem is somewhere with the redirect, maybe auth, maybe response (awaited XML - like in our custom application), etc. You can see in logs. 

    Don't mix things up, please. That doesn't help in solution finding. 
    Btw my on-prem EWS behind WAF works also fine, but as said, its not the topic.

Reply
  • Hi David, as far as I know, it's not an on-prem, but hybrid issue, like described by several people.

    e.g. Connection to on-prem EWS behind WAF. Since it's hybrid there is a redirect to O365. Problem is somewhere with the redirect, maybe auth, maybe response (awaited XML - like in our custom application), etc. You can see in logs. 

    Don't mix things up, please. That doesn't help in solution finding. 
    Btw my on-prem EWS behind WAF works also fine, but as said, its not the topic.

Children
  • Alex, what suggestions do folks have in the Microsoft Exchange community?  That might give us a clue on what to do in the UTM.

    Cheers - Bob

  • Alex, my intention was not to mix anything up nor would it prevent finding the solution. 
    I have a client that also uses WAF with on-prem exchange hybrid, today I created a mailbox move request and it was successful. Their UTM is on 9.709-3. Admitedly, I haven’t looked further into their setup as of yet…

    I will take a closer look next week at their setup to see how it may differ to others I manage out there. I am now aware of two of our clients that are having this issue!