Link to home
Start Free TrialLog in
Avatar of awilderbeast
awilderbeastFlag for United Kingdom of Great Britain and Northern Ireland

asked on

ActiveSync not working - OWA does work, ISA 2004 SBS 2003

Hi all

having trouble with active sync on a number of mobile devices

ive just got owa back up but activesync gives me a cannot connect to server message on iphone, we have various types of phone, and works on none of them at the moment

any questions you need to ask ill do my best to provide

thanks

EDIT: my iphone just chucked out this message to me

the certificate mail.domain.org for account myname@domain.oth could not be verfiied

i accepted it then i get cannot connect to server message again
Avatar of awilderbeast
awilderbeast
Flag of United Kingdom of Great Britain and Northern Ireland image

ASKER

i just got the active sync tester app for my iphone and got the following from that

checking connection... OK

checking certificate... FAIL (self signed so that doesnt matter)

checking application... FAIL

activesync is not available.
(activesynv detected,but access denied. [http 403: diabled for this user])

i checked and mobile access and everything is enabled, is there a specific section to enable activesync?
ASKER CERTIFIED SOLUTION
Avatar of Kumar_Jayant123
Kumar_Jayant123

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
got all those things yup

i also have checked the exchange server global mobile settings all enabled there
and user settings all enabled there

see screens

thanks
activesync.jpg
Avatar of Kumar_Jayant123
Kumar_Jayant123

send me an email at xxxxxxxxxxxxx   email addressed removed - Keith Alabaster

Thanks
Kumar
IT WORKS!

i put mail.domain.org/exchange in the settings when it didnt need to be, it needed to be mail.domain.org
thats all, now it works!

i do still have a small problem, but thats a routing problem, ill run it by you see if you have ideas

at work where the exchange server is connected, we have wifi, that only connects to the internet (i set this up) so my iphone connects to that wifi and has web access only, no access to internal addresses

activesync on my iphone when connected via wifi says cannot connect to server
i think it might have something to do with going out and coming in on the same public address

what are your suggestions?
I am trying to access "https://mail..org/Microsoft-Server-ActiveSync" from a Browser and it is showing me the Forms based authentication page. So the Path is working fine.

When you are connected to WiFI from the Device are you in the Internal Network or external Network?

Kumar

-- edited by SouthMod to remove actual domain name
im on the internal network on my iphone but its on a different range to the server and i have access-lists setup so it cant access the local lan, its a wifi thing, my bosses didnt want access to the lan through wifi, just internet access for guests and phones really

so when my iphone accesses the active sync it has to go out the adsl interface and back in on it too

do somethings making it play up there
If it is working for you internally it should work externally as well.

Nothing needs to e changed in the ISA Server really.

Kumar
its a routing issue

i know what it is but cant figure a way out yet

the wifi local addresses are on one range
the lan addressses are on another range, they have blocked access to each other

so for the wifi clients to reach the lan they have to go out the external interface (public address)

so when the request goes out the domain name gets resloved to the external ip address then the client says, well im already there why do i need to go out, im here, so to speak, you following?

alshtough its request is being natted anyway and getting a 443 slapped on the end, hmmmm, ill look into this one, but its definitley a routing issue

thanks
Avatar of Keith Alabaster
Kumar - Please do not post your email address within comments. I have removed reference to it in your earlier post.

Thanks

Keith Alabaster
Zone Advisor
will do that.. Thanks

Kumar
:)

If you NEED to do this at anytime, place the address in your profile and refer people to that instead. Enter it in the form of 'user at something dot com' so you don't get picked up by any of the email harvester routines.

Keith