Òë×Ô Thomas W Shinder MD, MVP£¬Enabling Full Outlook Client Access Anywhere using the ISA Firewall's Secure Exchange RPC Filter
¡¡
ÄÚÈݸÅÊö£ºÍ¨¹ýISA·À»ðǽǿ´óµÄRPC¹ýÂËÆ÷£¬Äã¿ÉÒÔ°²È«µÄ·¢²¼Exchange RPC·þÎñ£¬ÈÃÍâ²¿ÍøÂçµÄOutlook MAPI¿Í»§¶Ë¿ÉÒÔ·ÃÎÊExchange·þÎñÆ÷µÄÈ«²¿·þÎñ¶ø²»Óõ£ÐݲȫÐÔÎÊÌâ¡£
Äã¿ÉÒÔÔÊÐíÔ¶³ÌOutlook 2000/2002/2003¿Í»§Í¨¹ýInternetÁ¬½Óµ½ÄãÄÚ²¿ÍøÂçµÄExchange·þÎñÆ÷ÉÏÀ´Ê¹ÓÃOutlook MAPI¿Í»§µÄÈ«²¿¹¦ÄÜ¡£ºÍOWA£¨Outlook Web Access£©²»Ò»Ñù£¬ÍêÈ«µÄOutlook MAPI¿Í»§ÔÊÐíÔ¶³ÌÓû§Ê¹ÓÃExchange·þÎñÆ÷ÌṩµÄÓʼþºÍÐ×÷Èí¼þÌØÐÔ£»²¢ÇÒºÍOutlook RPC over HTTP²»Ò»Ñù£¬Äã²»ÐèҪʹÓÃExchange 2003ºÍOutlook 2003¡£
ÕâЩ¶¼¿ÉÒÔͨ¹ýISA·À»ðǽµÄ°²È«Exchange RPC·¢²¼ÌØÐÔÀ´ÊµÏÖ¡£Äã¿ÉÒÔͨ¹ý°²È«Exchange RPC·¢²¼À´ÊÚȨԶ³ÌÓû§·ÃÎÊExchangeµÄÈ«²¿·þÎñ¡£
¶ÔÓÚRPCÁ¬½ÓµÄÒ»°ãÓ¡Ïó¶¼ÈÏΪËü²»¹»°²È«£¬È¥ÄêµÄ³å»÷²¨µÈ²¡¶¾Ò²ÊÇͨ¹ýRPCµÄÒ»¸öÎÊÌâÀ´½øÐÐÈëÇֵġ£µ«ÊÇͨ¹ýISA·À»ðǽµÄExchange RPC¹ýÂËÆ÷£¬Äã¿ÉÒÔ²»Óõ£ÐÄRPCµÄ°²È«ÐÔÎÊÌâ¡£
Exchange RPC¹ýÂËÆ÷´¦ÀíÔ¶³ÌOutlook MAPI¿Í»§ºÍÄÚ²¿Exchange·þÎñÆ÷Ö®¼äµÄÁ¬½Ó£¬²¢ÇÒΪָ¶¨µÄOutlook¿Í»§´´½¨¶¯Ì¬µÄ°ü¹ýÂËÆ÷¡£Í¬Ê±£¬Exchange RPC¹ýÂËÆ÷Ö»ÔÊÐíÓÐЧµÄExchange·þÎñÆ÷µÄÏà¹ØRPCÁ¬½Ó£¬ÆäËûÁ¬½Ó¶¼½«±»¶ªÆú¡£Õâ¸öÊÇÖ»ÔÚISA·À»ðǽÀïÃæ´æÔÚµÄÌØÐÔ¡£
Outlook¿Í»§¿Í»§ÅäÖÃΪÔÚExchange·þÎñÆ÷ºÍËüÖ®¼ä¼ÓÃÜ´«ÊäµÄÊý¾Ý£¬µ«ÊÇ£¬Õâ¸öÊǿͻ§¶ËµÄÉèÖ㬲¢ÇÒÒÀÀµÓÚ¿Í»§µÄÅäÖá£ISA·À»ðǽµÄ°²È«Exchange RPC¹ýÂËÆ÷ÔÊÐíÄãÇ¿ÖÆÔ¶³ÌOutlook MAPI¿Í»§Ê¹ÓüÓÃܵÄͨÐÅ¡£·Ç¼ÓÃÜͨÐŵÄÁ¬½ÓÇëÇ󽫻ᱻISA·À»ðǽµÄExchange RPC¶ªÆú¡£
·¢²¼Exchange RPCÊǷdz£¼òµ¥µÄ¡£Ò»¸ö·þÎñÆ÷·¢²¼¹æÔòÔÊÐíÄãµÄÔ¶³ÌOutlook MAPI¿Í»§·ÃÎÊÄÚ²¿µÄExchange·þÎñÆ÷¡£Äã²»ÐèÒª´´½¨Ä¿µÄ¼¯»òÖ¸¶¨ÐÒ鶨Òå¡£ÄÚ½¨µÄExchange RPCÐÒé¿ÉÒÔºÍRPC¹ýÂËÆ÷ºÜºÃµÄÅäºÏ£¬ÌṩÊܱ£»¤µÄ¡¢°²È«µÄ·¢²¼¹éÔò¡£
ΪÁËÈÃÓû§¿ÉÒÔ·ÃÎÊÍêÈ«µÄExchange·þÎñ£¬´«Í³µÄ·À»ðǽ¹ÜÀíÔ±ÔÊÐíVPNÁ¬½Ó·ÃÎÊÕû¸ö¹«Ë¾ÍøÂç¡£ÕâÑù´øÀ´Á˰²È«ÉϵķçÏÕ£¬ÊÂʵÉÏÄãÖ»ÊÇÏëÈÃÓû§·ÃÎÊExchangeµÄ·þÎñ¶øÒÑ¡£ISA·À»ðǽµÄ°²È«RPC·¢²¼ÌØÐÔÔÊÐíÄãÖ»ÊÇÈÃOutlook MAPI¿Í»§·ÃÎÊÍêÈ«µÄExchange·þÎñ¶ø²»¸øÓèÆäËû¶îÍâµÄȨÏÞ¡£
Óû§³£±§Ô¹ËûÃÇÔÚ¹«Ë¾ÍøÂçºÍÔ¶³ÌÕ¾µã¼äÒÆ¶¯Ê±ÐèҪʹÓò»Í¬µÄÓʼþ¿Í»§¶Ë£¬¶øÓû§Ï²»¶Ê¹Óù̶¨µÄ¿Í»§¶Ë³ÌÐò£¬ÈçOutlook 2000/2002/2003¡£Exchange RPC·¢²¼¿ÉÒÔÈÃËûÃÇÎÞÂÛÔÚ¼Ò»¹ÊÇ·É϶¼Ê¹ÓÃÊìϤµÄOutlook 2000/2002/2003¡£
°²È«Exchange RPC·¢²¼ÊÇÈçºÎ¹¤×÷µÄ£¿
µäÐ͵ÄÇé¿öÏ£¬Ô¶³ÌOutlook MAPI¿Í»§Í¨¹ý±¾µØµÄISP»òÕß¿í´ø·þÎñÌṩÉÌÏòInternetÉϵÄExchange·þÎñÆ÷½¨Á¢Á¬½Ó¡£µ±´ò¿ªOutlookʱ£¬»áÖ´ÐÐÒÔ϶¯×÷£º
ÏÂͼÏÔʾÁËÉÏÊö²½ÖèµÄ¹ý³Ì£º
×¢Ò⣺
¶ÔÓÚ¸üΪÉîÈëµÄ¹ØÓÚExchange RPC¹ýÂËÆ÷ÊÇÈçºÎ¹¤×÷µÄ¼¼Êõ×ÊÁÏ£¬Çë²Î¼ûhttp://www.microsoft.com/technet/prodtechnol/isa/2000/maintain/rpcwisa.mspx
×¼±¸Exchange RPC·¢²¼µÄÍøÂç»ù´¡·þÎñ ÔÚÄã³É¹¦·¢²¼Exchange RPC֮ǰ£¬ÄãÐèÒªÔ¤ÏȲ¿ÊðÒ»Ð©ÍøÂç»ù´¡·þÎñ£¬°üÀ¨£º ¡¡ ¡¡
½¨Á¢Ö§³ÖµÄDNS»ù´¡·þÎñ
ΪÁËÈÃOutlook MAPI¿Í»§ÕýÈ·µÄ½âÎöExchange·þÎñÆ÷µÄÃû×Ö£¬±ØÐ뽨Á¢DNS·þÎñ¡£ÎªÁËÈÿͻ§ÔÚ²»Í¬µÄµØµãʹÓÃÏàͬµÄÃû×ÖÀ´·ÃÎÊExchange·þÎñ£¬Äã±ØÐëʹÓ÷ÖÀëDNS¡£·ÖÀëDNSÐèÒªÄãÔÚ²»Í¬µÄµØµã±£³Ö¶ÀÁ¢µÄDNS·þÎñ£¬ÀýÈ磬ÔÚÍâ²¿ÍøÂçºÍÄÚ²¿ÍøÂç¶¼²¿ÊðDNS·þÎñ£¬È»ºóÄÚ²¿µÄDNS½âÎöExchange·þÎñÆ÷Ãû×Öµ½ÄÚ²¿ÍøÂçÖеÄExchange·þÎñÆ÷µÄIP£¬¶øÍâ²¿ÍøÂçÖеÄDNS½âÎöExchange·þÎñÆ÷µÄÃû×Öµ½·¢²¼Exchange·þÎñÆ÷µÄIPµØÖ·ÉÏ¡£
·ÖÀëDNS·þÎñÐèÒª°üº¬ËùÓеÄExchange·þÎñÆ÷¡£ÀýÈ磬ÄãÓÐÁ½¸öExchange·þÎñÆ÷£¬exchange.domain.comºÍexchange2.domain.com£¬ÄãÐèÒªÔÚ·ÖÀëDNS·þÎñÉÏΪÕâÁ½¸öÃû×Ö½¨Á¢¶ÔÓ¦µÄÃû×Ö½âÎöÏîºÍ·þÎñÆ÷·¢²¼¹æÔò¡£
ʹÓÃHOSTSÎļþÀ´×öÃû×Ö½âÎö²»¾ßÓÐÀ©Õ¹ÐÔ£¬²¢ÇÒ¶ÔÓû§µÄÒªÇóÒ²ºÜ¸ß¡£ÄãÐèҪΪExchange·þÎñÆ÷¼ÆËã»úµÄNetbiosÃû×ÖÀ´½¨Á¢HOSTSÎļþ£¬×¢Ò⣬Äã²»ÐèҪΪExchange·þÎñÆ÷½¨Á¢FQDNµÄÃû×Ö½âÎöÏֻÐèÒªNetbiosÃû×Ö¡£
×¢Ò⣺
FQDNµÄÖ÷»úÃû×Ö²¿·Ö£¨×î×ó±ßµÄ²¿·Ö£©±ØÐëºÍExchange RPC·þÎñÆ÷·¢²¼¹æÔòʹÓõÄExchange·þÎñÆ÷Ãû×ÖÒ»Ö¡£Outlook MAPI ¿Í»§±ØÐëÅäÖÃΪʹÓÃExchange·þÎñÆ÷µÄ¼ÆËã»úÃû×Ö£¬²¢ÇÒ¿ÉÒÔÕýÈ·µÄ½âÎö´ËÃû×Ö¡£¶øOutlook¿Í»§¼ÆËã»ú±ØÐëʹÓÃÒ»¸öÓòÃû»òÕßÍøÂçÊÊÅäÆ÷Ö¸¶¨ÓòÃûÀ´ÕýÈ·µÄÏÞ¶¨Exchange·þÎñÆ÷µÄNetbiosÃû×Ö¡£
ͨ¹ýÉÏÊöÄÚÈÝ£¬Äã¿ÉÄÜ»á¾õµÃÃû×Ö½âÎöÓеãÂé·³¡£Outlook 2003ÊǸüΪInternet»¯µÄ£¬Ê¹ÓÃFQDNs£¬µ«ÊǾɰ汾µÄOutlookÒªÇó¿Í»§¼ÆËã»ú¿ÉÒÔÕýÈ·µÄÏÞ¶¨Ãû×Ö¡£¹ØÓÚ¿Í»§¶Ë¸üΪÏêϸµÄÅäÖÃÐÅÏ¢£¬Çë²Î¼ûISA Server 2000 Exchange²¿Ê𹤾߰ühttp://isaserver.org/news/exchangekit.html¡£
½¨Á¢DNSºÍSMTPÐÒ鹿Ôò Exchange·þÎñÆ÷ÐèҪת·¢´ÓOutlook MAPI¿Í»§ÊÕµ½µÄÓʼþµ½InternetÉϵÄSMTP·þÎñÆ÷£¬ÕâÐèÒª½¨Á¢ÔÊÐíËü·ÃÎʵķÃÎʹæÔò£¬ÐèÒªÔÊÐíËü·ÃÎÊÒÔÏÂÐÒ飺 DNS·ÃÎʹæÔòÔÊÐíExchange SMTP·þÎñ½âÎöMXÓòÃû¡£²»¹ýÄãÓ¦¸Ã¸ù¾ÝDNS·þÎñÆ÷ºÍSMTP·þÎñÆ÷µÄλÖÃÀ´ÅäÖ÷ÃÎʹæÔò¡£ ¡¡ ¡¡ ¡¡
ÅäÖÃÈÏÖ¤·½Ê½ µ±Outlook¿Í»§µÇ¼µ½Exchange·þÎñÆ÷£¬Exchange·þÎñÆ÷ָʾOutlook MAPI¿Í»§Í¨¹ýDCÀ´½øÐÐÉí·ÝÑéÖ¤£»µ«ÊÇ£¬¶ÔÓÚÔ¶³Ì¿Í»§À´Ëµ£¬»î¶¯Ä¿Â¼ÊDz»¿ÉÒÔ·ÃÎʵġ£Äã¿ÉÒÔͨ¹ýÅäÖÃExchange·þÎñÆ÷Ϊ¿Í»§´úÀí½øÐÐÉí·ÝÑéÖ¤À´±ÜÃâÕâ¸öÎÊÌâ¡£ ÐÞ¸ÄExchange·þÎñÆ÷ÉϵÄÕâ¸ö×¢²á±í¼üÖµÀ´ÈÃExchange·þÎñÆ÷ΪOutlook MAPI¿Í»§´úÀíÉí·ÝÑéÖ¤£º HKLM\System\CurrentControlSet\Services\MSExchangeSA\Parameters Add the following: Ìí¼Ó¼üÖµºóÖØÆôExchange·þÎñÆ÷¡£
Value: NoRFRService
Type: REG_DWORD
Data: 1
Outlook MAPI¿Í»§Î»ÓÚNAT·ÓÉÆ÷/·À»ðǽ/ISA Serversºó Èç¹ûOutlook¿Í»§Î»ÓÚNAT·ÓÉÆ÷»òÕßÀàËÆÉ豸ºó£¬Ëü¿ÉÄܲ»ÄܽÓÊÕµ½Óʼþ֪ͨ»òÕ߸ù±¾²»ÄÜ·ÃÎÊExchange·þÎñÆ÷¡£×Ô´Ó³å»÷²¨²¡¶¾ºó£¬Ðí¶àISP·âËøÁËTCP 135¶Ë¿Ú£¬ÕâÑùÒ²×èÖ¹ÁËOutlook MAPI¿Í»§¶ËµÄÁ¬½Ó¡£ ÐÂÓʼþ֪ͨ²¢²»ºÍ´æÔÚµÄRPC»á»°ÓÐÈκιØÏµ£¬¶ÔÓÚ¿Í»§¶ËµÄ·À»ðǽÀ´Ëµ£¬ÐÂÓʼþ֪ͨÊÇδ֪µÄÁ¬½Ó£¬ËùÒԻὫÆä¾Ü¾ø¡£Èç¹ûOutlook MAPI¿Í»§Î»ÓÚÓ¦Óòã¹ýÂË·À»ðǽ£¨ÈçISA·À»ðǽ£©Ö®ºó£¬Outlook MAPI¿Í»§¾Í¿ÉÒÔ½ÓÊÕµ½ÐÂÓʼþ֪ͨ¡£ Õâ²¢²»ÊÇ˵λÓÚNAT·ÓÉÆ÷»òÕßÀàËÆÉ豸ºóµÄOutlook¿Í»§²»ÄܽÓÊÕµ½ÐÂÓʼþ֪ͨ¡£µ±Outlook¿Í»§ÏòExchange·þÎñÆ÷·¢ËÍÓʼþʱ£¬Exchange·þÎñÆ÷»áͨ¹ýÏÖ´æµÄ»á»°Í¨µÀÏò¿Í»§·¢ËÍÐÂÓʼþ֪ͨ£¬´Ëʱ¿Í»§¾Í¿ÉÒÔ½ÓÊÕµ½ÐÂÓʼþ֪ͨÁË¡£ Èç¹ûÄãÔÚOutlook MAPI¿Í»§Ç°Ê¹Ó󣹿µÄ°ü¹ýÂË·À»ðǽ£¬·À»ðǽ¹ÜÀíÔ±ÐèÒªÔÊÐí½øÈëµÄTCP 135Ö÷ÒªÁ¬½Ó£¬È»ºóÉèÖø¨ÖúÁ¬½Ó¡£Õâµã¾ÍÏÔʾ³öÁËISA·À»ðǽµÄRPC¹ýÂËÆ÷µÄÓÅÐãÖ®´¦¡£ Èç¹ûÄãʹÓÃISA·À»ðǽ£¬Äã¿ÉÒÔ½¨Á¢Ò»¸ö·ÃÎʹæÔòÀ´ÔÊÐíOutlook MAPI¿Í»§·ÃÎÊ£»Ö´ÐÐÒÔϲ½ÖèÀ´½¨Á¢·ÃÎʹæÔò£º
½¨Á¢Exchange RPC·þÎñÆ÷·¢²¼¹æÔò Exchange RPC Server·¢²¼¹æÔòʹÓÃRPC¹ýÂËÆ÷ÌṩµÄÐÒ鶨Ò壬ËùÒÔÄã±ØÐëÊ×ÏÈÈ·¶¨RPC¹ýÂËÆ÷ÊÇ·ñÆôÓá£Äã¿ÉÒÔÔÚISA¹ÜÀí¿ØÖÆÌ¨µÄÅäÖõIJå¼þ½ÚµãϽøÐмì²é£¬¿´RPC¹ýÂËÆ÷ÊÇ·ñÆôÓᣠ¼ÇµÃΪÿһ¸öÌṩÓʼþ·þÎñµÄExchange·þÎñÆ÷½¨Á¢Ò»¸ö°²È«Exchange RPC·þÎñÆ÷·¢²¼¹æÔò¡£ÀýÈ磬Èç¹ûÄãÓÐËĸöExchange·þÎñÆ÷ÔÚÌṩÓʼþ·þÎñ£¬ÄãÐèÒª·¢²¼ÕâËĸö·þÎñÆ÷¡£×¢ÒâÈç¹ûÄãÓÐǰ¶ËExchange·þÎñÆ÷£¬Äã²»ÐèÒª·¢²¼Ëü£¬ÒòΪËü²»ÄÜ´úÀí±¾ÖʵÄRPCÐÒé¡£ÓëÖ®¶Ô±ÈµÄÊÇ£¬Ç°¶ËExchange·þÎñÆ÷¿ÉÒÔ´úÀí»ùÓÚHTTPËíµÀµÄRPCÁ¬½Ó£¨RPC over HTTP£©¡£ Ö´ÐÐÒÔϲ½ÖèÀ´½¨Á¢Ò»¸ö°²È«Outlook MAPI¿Í»§·ÃÎÊ·þÎñÆ÷·¢²¼¹æÔò£º
ÅäÖÃOutlook 2003¿Í»§Ê¹Óð²È«Exchange RPC½øÐÐÁ¬½Ó 1¡¢ÅäÖÃÃû×Ö½âÎö Äã¿ÉÒÔʹÓÃ΢ÈíOutlook MAPI¿Í»§¶ËµÄÈκΰ汾À´²âÊԸղލÁ¢µÄ·þÎñÆ÷·¢²¼¹æÔò¡£ÔÚ´ËÀýÖУ¬ÎÒÃÇʹÓÃOutlook 2003¿Í»§½øÐвâÊÔ£¬Outlook 2000ºÍOutlook 2002 MAPI¿Í»§¶ËµÄÅäÖûù±¾Ò»Ö¡£ ÔÚÒÔϵIJâÊÔÖУ¬ÎÒÃÇʹÓÃHOSTSÎļþÀ´Ó³ÉäExchangeµÄIPµØÖ·µ½ISA·À»ðǽµÄÍⲿIPµØÖ·ÉÏ¡£ ×¢Ò⣺ Ö´ÐÐÒÔϲ½ÖèÀ´ÔÚOutlook 2003 MAPI¿Í»§¼ÆËã»úEXTCLIENTÉϽ¨Á¢HOSTSÎļþ£º ÔÚÎļþ½áβÌí¼ÓÏÂÃæÕâÏ 192.168.1.70 exchange2003be.msfirewall.org ÕâÏExchange¼ÆËã»úµÄÃû×ÖÓ³Éäµ½ISA·À»ðǽµÄÍⲿIPµØÖ·ÉÏ¡£¼ÇµÃÔÚ´ËÐеÄ×îºóÇøö»Ø³µ£¬ÕâÑù²ÅÄÜÈÃWindowsÕýȷʶ±ðÄãÊäÈëµÄÕâÏî¡£ ¡¡ ¡¡
ÔÚÉÌÓÃÍøÂçÖУ¬ÄãÓ¦¸Ã²¿Êð·ÖÀëµÄDNS·þÎñ¡£
2¡¢ÅäÖÃOutlook 2003¿Í»§ ½ÓÏÂÀ´ÊÇÅäÖÃOutlook¿Í»§¶ËÁ¬½ÓExchange·þÎñÆ÷µÄÅäÖÃÎļþ£¬Ö´ÐÐÒÔϲ½ÖèÀ´ÅäÖÃOutlook¿Í»§¶Ë£º 

ÏÖÔÚÎÒÃÇ¿ÉÒÔͨ¹ý°²È«Exchange RPC·þÎñÆ÷·¢²¼¹æÔòºÍExchange·þÎñÆ÷½¨Á¢Á¬½ÓÁË£¬Ö´ÐÐÒÔϲ½Ö裺
| ×ÔÓÉ¹ã¸æÇø |
| ¡¡ |