Exchange New federation trust not working : an underlaying connection was closed

Marion CAMELIO 0 Reputation points
2025-02-26T13:09:02.1666667+00:00

Hello,

Quick summary of my issue : I need to set up an Organizational Relatioship Between two of my exchange organization to share some of my user calendar (both are on premise servers with no hybrid activated). I set it up on one of them with no issue but the other one won't event create a New-FederationTrust.

The only log i have after doing the command (or activating it via ecp) is : "Can't access federation metadata file from federation partner. More informations : "An underlaying connection was closed : an unexpected error occured during send."."

 

I tried multiple solutions :

On my firewall all i see are accept and server-rst logs to/from Azure Ips.

Please help me resolve this issue,

Thanks in advance,

 

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,808 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Kaiyue Gong (Shanghai Wicresoft Co Ltd) 230 Reputation points Microsoft Vendor
    2025-02-27T08:50:26.8633333+00:00

    Hi @,

    Thank you for posting your question in the Microsoft Q&A forum.

    As per your description, your issue is that you are unable to create a federation trust between two exchange organizations. Is it convenient for you please clarify/provide the following information so that we can check further:

    1. what is your exchange version?

    2.What is the difference in configuration between your two exchange organizations?

    Based on the information so far I have the following suggestions which I hope will help you:

    1. make sure the Exchange server and Windows server are fully compliant with the latest updates and patches. Older versions can sometimes cause problems with authentication trust.
    2. please check that federated sharing is enabled for your exchange organization using the Get-FederatedOrganizationIdentifier command.
    3. Please check your version of the .NET Framework to ensure that it supports TLS 1.2. You can refer to the following link for detailed instructions on how to determine the .NET version and how to install the update. How to enable Transport Layer Security (TLS) 1.2 on clients - Configuration Manager | Microsoft Learn
    4. Use the Get-ExchangeCertificate command to check that your certificate associated with the IIS service is not expired and is available. If it is not available, you can regenerate it using the New-ExchangeCertificate command.
    5. Check your prerequisites and configuration process for errors in conjunction with this document. For example: The domain used for establishing a federation trust should be resolvable from the Internet; Both Exchange organizations in a federated sharing relationship must use the same Microsoft Entra authentication system for their federation trusts, and so on. Configure a federation trust: Exchange 2013 Help | Microsoft Learn

    If the answer is helpful, please click on “Accept answer” as it could help other members of the Microsoft Q&A community who have similar questions and are looking for solutions.

    Thank you for your support and understanding.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.