Question

iPhone inconsistent ActiveSync

Asked by: dance1bb

Basically All Active Sync Testers Internal and external of our network work indicating everything is working as intended.  Firewall ports 443 are open on our GTA GB-OS firewall.  We are using Intrusion Prevention.  For whatever reason the iphone has intermittent access to activesync whether you connect to the wifi on the internal network or utilize the 3G network.  It will connect connect to the server, download messages on an intermittent basis.  It will have an excessive amount traffic passing.   If you utilize the activesync tester on the iphone the test will indiciate failed to connect to the sever, timeout.  Basically what I think is happening is for whatever reason the iphone is taking an excessive amount of time to interact via ActiveSync, it takes so much time that the tester will fail, however the iphone must try much longer and is eventually successfully synching via activesync but takes a very long time and passes an excessive amount of data draining the battery quite quickly.  These are my initial observations.  

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-11-04 at 08:47:05ID24871485
Tags

iPhone

,

Exchange

,

IIS

,

SSL

,

firewall

Topics

iPhone

,

Proxy/Firewall Anti-Virus

Participating Experts
2
Points
500
Comments
56

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Activesync on Iphone not working
    Hi! I have been searching the net the last week and have gotten alot of help but now its about time to write my own Question.. This is the situation: We got a Small Business Server 2003 R1 with Exchange SP2 where we intend to use Activesync. we also have two iPhones (2.0) on...
  2. Exchange ActiveSync and iPhone 3g S
    Have brand new iPhone 3gs running v3.0 iPhone software. Exchange 2003 on SBS 2003 R2 GoDaddy SSL cert. Getting: "Cannot Get Mail The connection to the server failed." Steps I've taken: During Exchange Setup on iPhone account IS verified. I've run the Exchange Active...
  3. Disable iPhone ActiveSync
    Yes, that's right. I am looking to disable iPhones from using Exchange ActiveSync to connect to our Exchange 2007 server. Due to the latest iPhone SMS vulnerability I would like to disable the feature until we can verify that the phone has been updated once the patch is relea...
  4. iPhone & Exchange ActiveSync
    Just brought on our first iPhone yesterday and are synching using the built in Exchange ActiveSync. Not an expert at iPhones at all. Is the GAL at all available via the iPhone? I only see Contacts and Contacts does not include the GAL as far as I can tell. If you know the...
  5. iphone activesync
    Can someone give me a quick rundown of what has to happen to get iphone, versions 2 and 3, to work with activesync? What has to be done in iis and / or exchange?

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: alanhardistyPosted on 2009-11-04 at 08:52:44ID: 25741284

What version of Exchange are you using?

 

by: dance1bbPosted on 2009-11-04 at 08:59:05ID: 25741370

Exchange 2007 SP1

 

by: alanhardistyPosted on 2009-11-04 at 09:07:40ID: 25741478

Have you purchased a 3rd party trusted SSL certificate or a self-certified one?

What Anti-Virus software have you got installed?

 

by: dance1bbPosted on 2009-11-04 at 09:14:47ID: 25741552

Yes, we have a trusted  Unified Messaging certificate for our client access server from Digicert.  OWA works fine.  Symantec Endpoint Protection is installed.

 

by: dance1bbPosted on 2009-11-04 at 09:41:19ID: 25741816

Testing server.mycompany.com (SSL, On LAN):

Communications:
       Doing DNS lookup on server.mycompany.com .... OK (fake address)
       Testing TCP to fake address port 443 ....... OK
SSL Certificate:
       Receiving ................................ OK
       Ensuring not Self-Signed ................. OK
       Verifying certificate .................... OK
ActiveSync:
       Checking for application ................. OK
       Checking version ......................... OK (8.1)
       Checking protocols ....................... OK (1.0,2.0,2.1,2.5,12.0,12.1)
User Permissions:
       Checking "domain_NT/user" ............... OK

Result:
            ActiveSync IS available.

                (To securely enable ActiveSync access from anywhere, see www.accessmylan.com )

 

by: alanhardistyPosted on 2009-11-04 at 09:45:57ID: 25741860

Can you please look at the following document and enter the registry keys at the bottom of the document (Per-MDB configuration):

http://msexchangeteam.com/archive/2004/11/15/257737.aspx

This will stop Symantec messing with Activesync which can cause problems.

Once done - please restart the Infromation Store then test sync again.

 

by: dance1bbPosted on 2009-11-04 at 09:53:35ID: 25741935

The mailbox server is not the client access server. Should this be applied to the client access server or the mailbox server or both?

 

by: dance1bbPosted on 2009-11-04 at 10:47:33ID: 25742479

The behavior persists after making the reg change on the mailbox GUID and restarting the information store service.

 

by: alanhardistyPosted on 2009-11-04 at 11:27:41ID: 25742916

What elements of the SEP client did you install on the server?

Anti-Virus / Proactive Threat Protection / Network Threat Protection?

 

by: dance1bbPosted on 2009-11-04 at 11:42:12ID: 25743066

Anti-Virus and Anti-Spyware Protection

 

by: alanhardistyPosted on 2009-11-04 at 12:19:54ID: 25743489

No network / proactive threat protection at all?

 

by: dance1bbPosted on 2009-11-04 at 13:19:46ID: 25744056

None.

 

by: dance1bbPosted on 2009-11-05 at 04:39:31ID: 25748776

Any other ideas?  Fetch seems to work fine every 15 minutes but like I indicated earlier, it seems as though the Push is inconsitent.  The "Cannot get mail" prompt appears.

 

by: alanhardistyPosted on 2009-11-05 at 04:41:07ID: 25748783

Is Activesync on the phone set to As Items Arrive?

Programs> Activesync> Menu> Schedule.

 

by: dance1bbPosted on 2009-11-05 at 05:42:05ID: 25749290

The IPhone does not have those settings. Push is turned on, fetch is set to manual and  then there is a disclaimer: "If push isn ot available the fetch schedule will be used".

 

by: alanhardistyPosted on 2009-11-05 at 07:53:21ID: 25750769

Sorry - so used to Windows Mobiles!  I have an iPhone, but just for testing purposes.

Do you have any Windows Mobile phones that you can test with - just to see if it is a general issue or an iPhone issue?

 

by: dance1bbPosted on 2009-11-05 at 09:28:45ID: 25751798

I can test one tomorrow since I am out of office today.  From 2007 to June of this year I used a Palm Treo 750 with Exchange ActiveSync and didn't have any issues.

 

by: alanhardistyPosted on 2009-11-05 at 09:31:55ID: 25751832

Okay - it is always nice to try alternatives to narrow down the possibilities.

I'm mobile quite a bit tomorrow, but have my Windows Mobile with me always, so should be able to respond.

 

by: dance1bbPosted on 2009-11-06 at 07:29:04ID: 25759907

Yes, the windows mobile device appears to be working fine.  I suppose a better description for this issue would be "iPhone ActiveSync Push is inconsistent".  To test, we opened up the firewall for a limited time to that server and saw the same behavior.  I even recreated the virtual directory for ActiveSync.  

 

by: alanhardistyPosted on 2009-11-06 at 09:55:08ID: 25761328

I now have a brand new FAQ to hopefully help you with this problem.  Would be interested if anything in it helps you.

http://www.it-eye.co.uk/faqs/readQuestion.php?qid=5

 

by: dance1bbPosted on 2009-11-06 at 10:16:05ID: 25761532

The logs are full of this over and over and over again:
 
***Fri Nov  6 13:02:56 unknown dataaccessd[139] <Warning>: EAS|ASPingTask failed: Error Domain=NSURLErrorDomain Code=-1200 UserInfo=0x174f20 "secure connection failed"
 
***Fri Nov  6 13:00:35 unknown MobileMail[108] <Warning>: EAS|connection died with error Error Domain=NSURLErrorDomain Code=-1200 UserInfo=0x199390 "secure connection failed" 0x4205380
 
***Fri Nov  6 13:00:35 unknown MobileMail[108] <Warning>: EAS|ASFolderItemsSyncTask failed: Error Domain=NSURLErrorDomain Code=-1200 UserInfo=0x199390 "secure connection failed"
 
***Fri Nov  6 13:00:35 unknown MobileMail[108] <Warning>: error syncing folder: Error Domain=MFMessageErrorDomain Code=1042 "Operation could not be completed. (MFMessageErrorDomain error 1042.)"
 
***Fri Nov  6 13:02:56 unknown dataaccessd[139] <Warning>: EAS|connection died with error Error Domain=NSURLErrorDomain Code=-1200 UserInfo=0x174f20 "secure connection failed" 0x173d10

 

by: alanhardistyPosted on 2009-11-06 at 10:30:37ID: 25761685

Did you take a look at my FAQ?

 

by: dance1bbPosted on 2009-11-10 at 12:30:17ID: 25789457

We looked at your FAQ and many do not seem to apply. We reissued the trusted certificate yesterday and we see the same behavior.   Any ideas?  It seems to be a Push/connectivity issue.  Our certificate authority pointed to the firewall but the network administrator is quite confident that outbound and inbound openings are sound.   Any more ideas?

 

by: alanhardistyPosted on 2009-11-10 at 12:32:26ID: 25789480

What is your Firewall (Make / Model) and what Anti-Virus / Anti-Spam software do you have installed on the Exchange server?

 

by: dance1bbPosted on 2009-11-13 at 08:13:21ID: 25815109

Firewall:  Global Technology Associates GB-2000  OS: 5.2.2
Intrusion prevention is also an add-on for our firewall
Antivirus: Symantec Endpoint Protection

Direct Push Technology seems to function properly with a Windows Mobile Device

 

by: dance1bbPosted on 2009-11-16 at 04:09:46ID: 25829472

Any ideas, Alan?  I opened a case with Microsoft and we confirmed that both an emulator and an activesync device work properly witht he Directpush.  The Windows mobile device seemed to work flawlessly.

 

by: dance1bbPosted on 2009-11-16 at 06:56:01ID: 25830633

The Activesync Tester test on the iphone shows this:

Checking connection . . .ok
Checking certificate . . . ok
Checking application . . .ok
Checking version . . .
ActiveSynce IS NOT available.
(Failed to connect to the server. [Timeout])

 

by: dance1bbPosted on 2009-11-16 at 08:42:13ID: 25831587

I found this on the internet.  Is this true?
http://forums.macrumors.com/showthread.php?t=803618

 

by: alanhardistyPosted on 2009-11-16 at 08:45:24ID: 25831618

Not sure about the iPhone version and Exchange 2007 - perfectly possible though.  I'll make a call to someone I know with an iPhone and Exchange 2007 and see if they have the issue.

Watch this space.

From the sounds of it - it does seem to be an iPhone problem if Activesync works!!

 

by: dance1bbPosted on 2009-11-16 at 11:16:10ID: 25832989

We also have a Droid from Verizon Wireless and it also has issues with Push Technology.

 

by: alanhardistyPosted on 2009-11-16 at 11:53:32ID: 25833394

Do you want to send me details of a test account so that I can setup my iPhone to see if it works?

 

by: dance1bbPosted on 2009-11-17 at 04:52:51ID: 25839158

How can I send you a private message?

 

by: alanhardistyPosted on 2009-11-17 at 06:12:17ID: 25839744

Just click on my name in any of my posts and this will take you to my profile page.  From there - near the bottom of my blurb is my email address (without the @ symbol).

 

by: demazterPosted on 2009-11-18 at 01:43:13ID: 25847923

OK, I had a completely working iPhone on Exchange 2007 with Version 3 of the iPhone software, I upgraded to version 3.1 and all of a sudden it stops working!!

To fix this do the following:

In Exchange Management Console navigate to: Organization Configuration > Client Access > Exchange Activesync Mailbox Policies, right click the policy and select properties then on the password tab uncheck Require encryption on the device.

 

by: alanhardistyPosted on 2009-11-18 at 04:06:43ID: 25848755

Thanks Glen :-)

 

by: demazterPosted on 2009-11-18 at 04:10:12ID: 25848773

No worries, was just browsing the iphone questions and spotted this one, thought I would upgrade one of my iPhones and hey presto! BROKE!

 

by: alanhardistyPosted on 2009-11-18 at 04:12:43ID: 25848787

Another one for the "if it ain't broke, don't fix it" file!

 

by: demazterPosted on 2009-11-18 at 04:52:02ID: 25849028

I am just attempting a downgrade to 3.0.1 to see if it fixes it.

 

by: alanhardistyPosted on 2009-11-18 at 04:53:18ID: 25849036

Is backwards possible - I always thought that forwards was the only way?

 

by: dance1bbPosted on 2009-11-18 at 05:12:30ID: 25849237

Alan, are you seeing proper flow to the handheld now?  I removed the encryption check, removed the mobile device, reset IIS and rebooted the CAS.  I will now setup the account again on the IPhone.

 

by: alanhardistyPosted on 2009-11-18 at 05:15:54ID: 25849284

Will test in a sec - need more info from you and have just emailed you back.

 

by: alanhardistyPosted on 2009-11-18 at 05:25:56ID: 25849387

It comes up as all tests passed.  Should be okay!

 

by: dance1bbPosted on 2009-11-18 at 06:05:15ID: 25849796

It should be ok according to Apple and Microsoft but it's still not working out.  Mail will sync initially but I just tried to send  a test message and it is hanging. and the connection refreshing icon continues to spin.

 

by: alanhardistyPosted on 2009-11-18 at 06:06:43ID: 25849813

Are you syncing a new account or one with plenty in it?

 

by: demazterPosted on 2009-11-18 at 06:09:37ID: 25849834

Still trying to downgrade one of my iPhones, it's now in "recovery mode" so running 2nd attempt!

 

by: alanhardistyPosted on 2009-11-18 at 06:09:41ID: 25849835

What OS version is the Apple currently on?

 

by: demazterPosted on 2009-11-18 at 06:11:28ID: 25849861

Also have you cycled the power?
Check the OS version on the phone > Settings > General > About

 

by: alanhardistyPosted on 2009-11-18 at 06:21:24ID: 25849953

I'm on 3.0 and it does not work with your settings!

 

by: dance1bbPosted on 2009-11-18 at 06:23:21ID: 25849976

I'm on version 3.1.2.  So, where could the breakdown be if ActiveSync Push is working properly with Windows Mobile devices?

 

by: alanhardistyPosted on 2009-11-18 at 06:28:47ID: 25850020

Just trying using the IP address instead of FQDN.  Back shortly.

 

by: alanhardistyPosted on 2009-11-18 at 06:32:49ID: 25850063

Account setup went through without a problem.  Sending a test message not happy - sitting on sending!

 

by: alanhardistyPosted on 2009-11-18 at 06:35:54ID: 25850089

2nd attempt seems to have been able to send the message.

 

by: alanhardistyPosted on 2009-11-18 at 07:11:32ID: 25850499

I am 99% convinced that it is your firewall that is messing with the traffic.

If you can either bypass it or swap it out for another less complicated beast and test the iPhones / droid again, that would be great.

Have you tried testing via Wi-Fi internally?  Does this work happily?

 

by: dance1bbPosted on 2009-11-19 at 11:08:39ID: 25863749

I tried testing internally with WiFI and Exchange email works flawlessly.

 

by: alanhardistyPosted on 2009-11-19 at 11:25:39ID: 25863923

In that case - can you replace the router with another, or reset the router and set it up again?

Preference would be to replace it with a 'spare' router of a simpler variety, or buy one to test with.

Something simple like a Netgear DG834G or DGN2000 would be good.

http://www.netgear.com/Products/RoutersandGateways/WirelessNRoutersandGateways/DGN2000.aspx

 

by: dance1bbPosted on 2010-01-07 at 11:49:45ID: 31650070

We used another firewall for testing and a Droid, which uses the same Direct Push Technology, worked well.  Thanks!

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...