POP3 SSL Connection Failure

M

Mike H

This will really probably get solved in the SBS NG, but maybe someone
has seen this little anomaly and has some info that will help us solve
my problem.

I'm using XP and Outlook 2003 in an SBS 2003 SP2 domain w' Exchange
Server 2003 SP2 and ISA Server 2004 SP3. The workstation is using the
ISA firewall client. The Windows Firewall Service is started. I have a
user account as well as several accounts on Exchange Server that forward
to me. All of that works well (after solving an RPC Server connection
failure due to the RPC filter in ISA Server - the filter is now
disabled).

What is NOT working are accounts in Outlook for foreign POP3 accounts
that require SSL connections, for example, ATT, GMail, .mil accounts,
etc. They ALL fail.

I have POP3S and SMTPS policies on ISA Server that work in the following
scenarios:

Outlook Express will operate on the server in all respects.
Outlook Express will operate on the workstations in all respects.
The MAIL control panel applet will correctly test the "SSL required"
accounts, to find, connect, send, and receive.

HOWEVER

Outlook, using the same profile established with the MAIL control panel
applet, WILL NOT connect to those mail servers. Furthermore, accessing
account properties and trying to do the very same test done in the
Control Panel Applet fails while "finding incoming mail server". I'm
told by the Errors tab that the server was found, but that there was no
response. Check SSL information, ports, etc....

A routine send/receive yields somewhat different information for an
error: "Receiving' reported error (0x800CCC0F): 'The connection to the
server was interrupted. ..." I see that AV scanning, among other things,
can cause that error. I disabled scanning both on the workstation and
server to no effect.

I have also deleted the offending accounts and recreated them. This
makes no difference.

The error is presented nearly instantly when a send/receive is
initiated. By that, I mean within one second.

I see no connection closures and disallows in ISA Server logging. It
dutifully keeps the ports open for about 15 seconds. However, Outlook
appears to be dropping the ball.

Any thoughts, especially on why the Control Panel Mail Applet account
test will work and the Outlook account test will not work?
 
M

Mike H

On this date I finally discovered the problem. It turns out to be
Firewall Client configuration for ISA Server 2004.

While inspecting the firewall I browsed some more areas of it that I
hadn't used yet. In ISA Server 2004, under "Configuration/General/Define
Firewall Client Settings", "Application Settings", I discovered the
following entry for Outlook.exe:

Application: outlook
Key: Disable
Value: 1

That tweaked me to use the following search string in Google:

"firewall client" settings for Outlook

which led me to http://www.isaserver.org/articles/2004olpop3smtp.html

The article explains almost exactly what the problem was. I modified his
instructions slightly to apply to my situation, being sure the POP3S and
SMTPS policies were in place in the firewall, and then changing the
firewall client key from Value=1 to Value=0. I then refreshed the
firewall client.

This works perfectly. You sure learn to appreciate something when you
spend 13 days working at it!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top