Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Slow OWA access through FORTIGATE

HI, I have exchnage 2000 in NAT mode. I have https enabled to my exchange for OWA access apart from smtp for mail delivery. OWA is very slow till the first security certificate and logon popup appears. after this phase OWA is normal. OWA works absalutely fine when accessed within the internal network.. Any suggestions to where i have gone wrong.
8 REPLIES 8
UkWizard
New Contributor

sounds like you have not got a valid ssl certificate, if you dont, then the initial connection takes ages to start. This is not related to the fortinet though. Could this be your problem ?
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Thanks Wizard, As i mentioned earlier the connection to my server is established immidiately when accessed internally.
Not applicable

What bandwidth do the remote users have? We have the same system and I presumed it was just the size of the certificate going through restricted bandwidth causing the issue... I' ve noticed this takes longer on dial-up than it does on broadband, yet LAN speed is instantanious (however the Exchange server is local). This is why I came the my conclusions.. Rich
Not applicable

Hi, Thanks all, Maybe i figured it out, OWa worked fine from internal clients always. The problem was when it was accessed from the eternal networl like from internet. I opened ports like DNS, HTTP, LDAP, High_Ports (1025-65535), Netbos_DGM, DCE_RPC, Kerberos_Auth, SMB,ICMP_ANY, NTP and now it works absalutley fine. I have a question opening this ports... Is it safe to open all this ? Please advice.
Not applicable

I agree with another contributor who suggests not to open those ports! We had an identical problem which was due do using an SSL Certificate that we generated ourselves with Certificate Services. Once we purchased a commercial Certificate, it works just as quickly from the Internet as it does on the LAN. The issue with our certificate seemed to be related to DNS resolution. We use split DNS where a host resolves differently depending upon where the client is (externally or internally). Our Exchange server was using an internal DNS server which pointed to a private address space. The client' s attempts to resolve / authenticate the certificate eventually went through after a very long delay. (even though it couldn' t really check to see if the certificate was revoked! MS Certificate Services works fine within a LAN, but....
UkWizard
New Contributor

DO NOT OPEN THOSE PORTS You should only have https open inbound, close all the others. Like i said in my earlier post, its probably that you havent got a valid certificate for the http or you have av checking on the inbound traffic. The certificate problem is known for this, as the browser is trying to authenticate the certificate, which times out after a period. When internal, it can get the certificate from the server immediately.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Whoooa! I wouldn' t open all those ports! Many vulnerabilities! At least try to narrow down what makes it work and what isn' t necessary. Then it might be clearer what the problem is... <Nomenludi>
Not applicable

Hi Friends, I found the solution. It was the certificate service working on http and owa on https.. Enabling http did resolve my problem.. All other ports are closed. Thanks for all your help.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors