I am not sure I understand your setup correctly but in short it should be like this
OWA is accessed externally through
https://mail.domain.com/owamail.domain.com A record points to real IP 1.1.1. on firewall
firewall is configure to send all HTTPS(443) requests coming on 1.1.1. to the NLB IP of the CAS
so if this is what you did you should have no problems