none
OWA-Zugriff führt zu Umleitungsfehler RRS feed

  • Frage

  • Hallo,

    auf unserem Exchange 2016 (läuft auf Windows Server 2016) schlägt der OWA-Zugriff mit einem Umleitungsfehler fehl, ECP und ActiveSync funktionieren jedoch.

    Die letzte im Browser agezeigte URL ist https://<EXCH-Name_Intern>:444/owa/auth/errorFE.aspx?httpCode=404, d.h. nach der Anmeldung und dem Übergang zum Backend versucht der OWA die Anfrage auf die interne URL umzuleiten. Interessanterweise kommt es allerdings auch beim Zugriff auf aus dem internen Netz zu einem Umleitungsfehler.

    Im IIS-Log findet man dazu:

    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/logon.aspx url=https://<EXCH-Name_Intern>:444/owa/&reason=0&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 235
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 36
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 35
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 34
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 36
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 33
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 35
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 35
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 38
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 39
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 34
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 29
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 32
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 29
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 29
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 30
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 31
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 30
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 140
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 32
    2020-06-29 11:05:46 192.168.50.205 GET /owa/auth/errorFE.aspx httpCode=404&ClientId=363A272D33674A7E940BDCE8F70901E9&ClientRequestId=&ActID=&CorrelationID=<empty>&ex=E409 444 - 192.168.50.254 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:77.0)+Gecko/20100101+Firefox/77.0 https://<EXCH-Name_Extern>/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2f<EXCH-Name_Extern>%2fowa%2f 302 0 0 69

    Da wir einen Split-DNS betreiben sollten die interne und externe URL jedoch identisch sein.

    Die virtuellen Directories des Exchange-Servers legen das auch nahe:

    Server                        : SRV-EXCHANGE
    Name                          : OAB (Default Web Site)
    ExternalUrl                   : https://mail.externe-domäne/OAB
    InternalUrl                   : https://mail.externe-domäne/OAB
    BasicAuthentication           : False
    WindowsAuthentication         : True
    OAuthAuthentication           : True
    InternalAuthenticationMethods : {WindowsIntegrated, OAuth}
    ExternalAuthenticationMethods : {WindowsIntegrated, OAuth}

    Server                        : SRV-EXCHANGE
    Name                          : EWS (Default Web Site)
    ExternalUrl                   :
    InternalUrl                   : https://srv-exchange.interne-domäne/EWS/Exchange.asmx
    CertificateAuthentication     :
    InternalAuthenticationMethods : {Ntlm, WindowsIntegrated, WSSecurity, OAuth}
    ExternalAuthenticationMethods : {Ntlm, WindowsIntegrated, WSSecurity, OAuth}
    LiveIdNegotiateAuthentication :
    WSSecurityAuthentication      : True
    LiveIdBasicAuthentication     : False
    BasicAuthentication           : False
    DigestAuthentication          : False
    WindowsAuthentication         : True
    OAuthAuthentication           : True
    AdfsAuthentication            : False

    Server                        : SRV-EXCHANGE
    Name                          : ecp (Default Web Site)
    ExternalUrl                   : https://mail.externe-domäne/ecp
    InternalUrl                   : https://mail.externe-domäne/ecp
    InternalAuthenticationMethods : {Basic, Fba}
    BasicAuthentication           : True
    WindowsAuthentication         : False
    DigestAuthentication          : False
    FormsAuthentication           : True
    LiveIdAuthentication          : False
    AdfsAuthentication            : False
    OAuthAuthentication           : False
    ExternalAuthenticationMethods : {Fba}

    Server                             : SRV-EXCHANGE
    Name                               : Rpc (Default Web Site)
    ExternalHostname                   : mail.externe-domäne
    InternalHostname                   : srv-exchange.interne-domäne
    ExternalClientAuthenticationMethod : Basic
    InternalClientAuthenticationMethod : Ntlm
    IISAuthenticationMethods           : {Basic, Ntlm, Negotiate}

    Server                        : SRV-EXCHANGE
    Name                          : owa (Default Web Site)
    ExternalUrl                   : https://mail.externe-domäne/owa
    InternalUrl                   : https://mail.externe-domäne/owa
    ClientAuthCleanupLevel        : High
    InternalAuthenticationMethods : {Basic, Fba}
    BasicAuthentication           : True
    WindowsAuthentication         : False
    DigestAuthentication          : False
    FormsAuthentication           : True
    LiveIdAuthentication          : False
    AdfsAuthentication            : False
    OAuthAuthentication           : False
    ExternalAuthenticationMethods : {Fba}

    Server                        : SRV-EXCHANGE
    Name                          : mapi (Default Web Site)
    ExternalUrl                   :
    InternalUrl                   : https://mail.externe-domäne/mapi
    IISAuthenticationMethods      : {Ntlm, OAuth, Negotiate}
    InternalAuthenticationMethods : {Ntlm, OAuth, Negotiate}
    ExternalAuthenticationMethods : {Ntlm, OAuth, Negotiate}


    An welcher Stelle sollte ich ansetzen um die Fehlerursache eingzugrenzen ?

    Grüße

    Tobias

    Dienstag, 30. Juni 2020 10:51

Alle Antworten