[Last Call] Learn how to a build a cloud-first strategyRegister Now


Cannot get IMAP on iPhone 3GS with Exchange 2007 / Forefront TMG to work

Posted on 2009-12-23
Medium Priority
Last Modified: 2012-05-08
Dear all,
It would really be great if some of you guys could help me with this issue - I already spent hours and hours on this problem without being able to finally solve it. The intention itself is rather simple: we are using the Microsoft Essential Business Server 2008 with Exchange 2007 and Forefront TMG. Based on the MS Exchange IMAP protocol, we would like to sync the iPhone 3GS with the mailboxes on MS Exchange. Unfortunately we cannot use Active Sync as this is in use for another account already).

So far so good. We opened the ports 143 and 993 on the Firewall and published the "IMAP4 Server"  and the "IMAPS Server" protocols on Forefront, pointing to the MS Exchange server. We did not yet setup SMTP - I would assume that this is not really an issue until we don't want to send e-mails from the iPhone...

When everything has been setup, I  configured the iPhone. As I was not able to connect to the IMAP mailbox on the Exchange server, I decided to first test the IMAP configuration on the Exchange server itself. On the iPhone, I configured the internal address of the Exchange server and connected via internal WLAN. The synchronization was successful with (143) and without SSL (993). So the configuration (including settings on the iPhone like username, password etc.) on the Exchange side should be ok and valid.

When I switch to the external Address, I am unable to sync, although the ports 143 & 993 have been forwarded to the Exchange server. The error message I get on the iPhone is: "Cannot get Mail. the connection to the server xyz.com failed."

I started the monitoring on the ISA server and found some interesting entries which appear whenever I try to connect, where is the IP of the Exchange Server and is the IP of Forefront's external Interface pointing to the Firewall: -> -> 143 -> IMAP4 Server ->Initiated Connection: 0x0 ERROR_SUCCESS -> -> 143 -> IMAP4 Server -> Closed Connection: 0x80074e21 FWX_E_ABORTIVE_SHUTDOWN -> -> 143 -> IMAP4 ->Denied Connection: 0xc0040017 FWX_E_TCP_NOT_SYN_PACKET_DROPPED      

Why do I get a message like "abortive shutdown" - if the protocol has been published to the Exchange server? And: why is there another connection opened to the external interface of Forefront (

A made another observation, maybe this helps: I have set-up Mozilla Thunderbird and was able to connect from outside via IMAP to my mailbox via SSL / port 993. Interesting is: if I enable "use secure authentication" the connection fails with the message "...you have enabled secure authentication and this server does not support it."
When I disable Thunderbird and try to connect without SSL, the connection is not successful as well.

I would really appreciate if you could help me further with this issue!

Thank you,
Question by:axeon78
  • 3
  • 2
LVL 29

Expert Comment

ID: 26120188
I don't know what you mean by "opened ports on the firewall",....TMG is the firewall,...and there is no such thing as "opening ports" with TMG.  It is built around the concept of Publishing Rules and Protocol Definitions,...there's no "opening ports".

The iPhone may not work with IMAPS due to possible disagreements with Certificates and Certificate Authorities between what the Phone is pre-installed with -vs- what the Exchange2007 does.  But that is a guess,...so don't quote me on that,...that type of stuff is not may area,...but I did have an issue like that with an AT&T Tilt Phone trying to work with OWA, OMA, ActiveSync.

So maybe you should focus on straight IMAP by itself for now and see where you get with it.  I got an iPhone to work perfectly fine with my Exchange2003 via ISA2006 with IMAP just the other day.

Author Comment

ID: 26124401
@pwindell: thanks. What do you mean with "straight IMAP"? Thanks.
LVL 29

Expert Comment

ID: 26124978
straihgt IMAP means,...IMAP,....as opposed to IMAPS

Author Comment

ID: 26127402
also IMAP does not work.
As I have been working with self-signed SSL certs, I thought this could be an issue and installed now a public cert. But even with the newly installed public cert, I get exactly the same error :-( Seems to be really a hard one. And: it does not depend whether I am going to use IMAP or IMAPS / SSL or not... Any idea?

Accepted Solution

axeon78 earned 0 total points
ID: 26127503
I FINALLY have solved this problem. The issue was the authentication on the Forefront / ISA Server's external web listener: the authentication was per default on "Windows" - but it seems that iPhone does not accept this authentication type. So I changed it to "LDAP". After that, I was able to sync over IMAPS immediately :-)

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This month, Experts Exchange sat down with resident SQL expert, Jim Horn, for an in-depth look into the makings of a successful career in SQL.
Exchange administrators are always vigilant about Exchange crashes and disasters that are possible any time. It is quite essential to identify the symptoms of a possible Exchange issue and be prepared with a proper recovery plan. There are multiple…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
This video discusses moving either the default database or any database to a new volume.
Suggested Courses
Course of the Month17 days, 17 hours left to enroll

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question