I have OWA 2003 configured and working with SSO. This running in SA2500 (6.1)
However dispite the fact that I have suppressed the ability to carry out the download/upload of attachments in the Jumiper GUI, users are still able perform these actions.
Can anyone suggest where I am going wrong?
It's time to get familiar with the Admin Guide - this topic is on p. 726.
In general, you specify the user ID and the realm, and then check the events you wish to record, and click "Start Recording". (You'll want to record Web Policies.). Then run the test through another browser window, and come back to the Admin GUI and click on "View Log". You'll see all the policy tests for all URLs fetched - you want to look for the URLs used to fetch the attachments, and see why they passed.
Remember to turn off policy trace when you are finished.
For OWA 2003, if you request no download or upload of attachments, the SA generates the following web access rules (assuming owaserver.company.com is the name of the server and it is accessed using HTTPS) -
The first two rules attempt to deny any URL which downloads or uploads an attachment, and the third rule allows anything else.
Assuming you did not manually change these rules, and you applied them to the correct role, I would guess they should work. If they don't, Juniper must have the form of the URLs incorrectly, and you should open a case with them.
All rules you have pointed out have been appplied to my setup as default but to no avail.
I have now opened a support case with Juniper and will let you know the result.