You
do not use ISA or any publishing Rules to get to the internal OWA when using Clients that are already behind the ISA.
You have to run Split-DNS so that the Internal OWA resolves tot he Private LAN IP# when coming from a LAN Client.
[Those are underscores, not spaces between the words]
You Need to Create a Split DNS!
http://www.isaserver.org/tutorials/You_Need_to_Create_a_Split_DNS.html
Supporting ISA Firewall Networks Protecting Illegal Top-level Domains: You Need a Split DNS!
http://www.isaserver.org/tutorials/2004illegaltldsplitdns.html