Can't connect to exchange 2007 when onsite with Ipad

New Exchange 2007 server.  Everything seems to be working ok but one annoyance is that when I bring in my Ipad and I jump on the wireless I can't connect to exchange.  When I'm offsite I can connect just fine.  What do I need to change to fix that?  The Ipad configuration mail server is mail.constoso.com.  Any suggestions? Do I need to change the internal site to be the same as the external and create a DNS record?

I just did an activesync test on testexchangeconnectivity.com and I found this:

Host name mail.contoso.com doesn't match any name found on the server certificate CN=remote.contoso.com.

Should I change the host name back to remote or can I change the certificate?  I'm new to fix this kind of stuff so any help is greatly appreciated.
ETI2010Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

batuckerIT GuyCommented:
You are probably missing a couple of simple things:

First - DNS resolution internally vs. externally:   Does mail.contoso.com exist in your internal DNS,  if not you can add this to your internal DNS server and that alone *may* fix your problem.   You are probably running into the problem where you are looking up mail.contoso.com from the inside,  it's giving you the external WAN ip of your router,  and your router isn't looping that traffic back into you -- very common.   Simple fix if this is your issue,  list  'mail.contoso.com' as a
   
If your internal DNS servers are using your Windows Server(s) as your primary/secondary DNS,  and assuming you have not made contoso.com your NT domain name,  but are properly using something like contoso.local,  then just add mail.contoso.com to your internal DNS  -- go to start -> administrative tools -> DNS, expand forward lookups,  right click on forward lookup zones and select new zone,  click next, select primary zone and click next, Default second option is usually correct and click next, for the zone name type mail.contoso.com and click next, next, finish,  right click mail.contoso.com and select new host (A or AAA),  leave the top box blank,  in the ip address type the internal ip address of the Exchange 2007 server, click add at the bottom.   Now your DNS server will lookup the internal IP for that single mail.contoso.com,     www.contoso.com etc will still be referred out to the internet as you would want and you don't have to replicate all the DNS records for contoso.com locally this way.


And secondly, if you are getting certificate warnings/errors as the testexcahnge tool suggested,  then you probably have a single domain name SSL certificate.   You should look into getting a UCC certificate if you do not have one.  This allows you to have multiple names assigned to a single certificate  (So for instance www.contoso.com,  vpn.contoso.com,  mail.contoso.com,   internal_server_name.NTDOMAIN   will all be valid wihin a single certificate.   They are relatively inexpensive and make life MUCH easier when dealing with/supporting end users/ActiveSync devices etc.  Lots of easy walkthroughs to set this up,  let me know if you need some links.  I prefer GoDaddy and have used them on quite a few 2007/2010 server without issue,  and with a quick search for a coupon code you can have a 2 or 3 year certificate for around $80.00,  other people prefer other providers.

Good Luck!
Brady
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Exchange

From novice to tech pro — start learning today.