From: jas0n on
Hello

Running Windows 2003 / ISA 2006 SP1, publishing Outlook Web Access for
2008x64 Exchange 2007, part way through transition from 2003 with both
2003/2007 mailbox servers and 1 CAS server.

I have been moving mailboxes this last week and most are fine but some users
have had issues accessing Outlook Web Access, they receive an error
message:-

HTTP Error 400. The size of the request headers is too long

It seems to be users who are members of many active directory groups, remove
a lot of groups and they user can gain access.

I'm trying to troubleshoot this but going around in circles, I don't appear
to see any errors in the http logs on the CAS server, I'm thinking the
connection doesn't reach it.

I am new to ISA, what data would I be able to gather from ISA about the
failed connection attempt ?

I've been through http://support.microsoft.com/kb820129 with regards to

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters

MaxFieldLength
MaxRequestBytes

.... added these in on the CAS server and set to 64k but this made no
difference.

Also looked at 'configure HTTP' in ISA on the rules which also appear to
have some header values but without some logs to look at its just hit and
miss and not good practice.

How do I troubleshoot this ?


From: jas0n on

"jas0n" <no(a)thank.you> wrote in message
news:OUKkAiBsKHA.1352(a)TK2MSFTNGP06.phx.gbl...
> Hello
>
> Running Windows 2003 / ISA 2006 SP1, publishing Outlook Web Access for
> 2008x64 Exchange 2007, part way through transition from 2003 with both
> 2003/2007 mailbox servers and 1 CAS server.
>
> I have been moving mailboxes this last week and most are fine but some
> users have had issues accessing Outlook Web Access, they receive an error
> message:-
>
> HTTP Error 400. The size of the request headers is too long

The problem was resolved with:-

http://support.microsoft.com/kb/920862/en-us

It says only relevant to Exchange 2003 but its also works for 2007, was
needed on the CAS & Mailbox server, well, all Web servers in our
environment, rebooted and now working.