?
Solved

Email on Iphone will Work on external Netowrks but not internal wifi

Posted on 2013-01-02
9
Medium Priority
?
452 Views
Last Modified: 2013-01-04
We have a 2003 SBS DC.  Email works push perfectly outside the company network but, will not work via internal wifi.  I know that you cannot access the external ip address from inside.  Is there any way to correct this issue?
0
Comment
Question by:cameljoe121
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 15

Expert Comment

by:jerseysam
ID: 38736809
Have a look at issue 3 here: http://support.apple.com/kb/TS1868

Seems to be a known issue
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 38736844
You need a split DNS system so that the external host name resolves internally.
http://exchange.sembee.info/network/split-dns.asp

The single host name replacement method should work fine.

Simon.
0
 

Author Comment

by:cameljoe121
ID: 38736954
I need a little more help here.  The internal clients connect to the mail using the FQDN Server01.Comanyname.local I dont want to have to change all the clients existing config.   The way the existing setup for external mail is either the IP address or MX.companyname.com cant i just add something for the interanl DNS lookup so is the see the MX.companyname.com it will point to the mail server or will this cause an issue?
0
Easily manage email signatures in Office 365

Managing email signatures in Office 365 can be a challenging task if you don't have the right tool. CodeTwo Email Signatures for Office 365 will help you implement a unified email signature look, no matter what email client is used by users. Test it for free!

 
LVL 17

Expert Comment

by:OriNetworks
ID: 38737016
I am assuming the iphone is already set up with the email account and then you are turning on wifi to start using it internally. Since it is already using the external ip address, it will still be trying to reach that address. On your firewall you can enable the wifi clients to only access the external IP for the email server instead of blocking all traffic. Or for internal DNS, point the server name that you used to set up the account on the iphone to the internal ip address of the mail server.

Another possibility is that it may be trying to validate the SSL certificate with an external certificate authority and it does not have internet access to do that. In this case you should enable the internal clients to have outside access to the crl lists e.g. crl.verisign.com
http://www.verisign.com/repository/crl.html

Simplest answer:
If the iphone is set to point to mail.mycompany.com make sure the internal record for the mail host is set to the internal ip address.
0
 
LVL 17

Expert Comment

by:OriNetworks
ID: 38737025
I just read your last comment. Since you have split DNS, you need to create a duplicate zone in DNS for companyname.com. Add a host for whatever the mail server name is and point it to the internal ip address of the server. Basically you are copying any external DNS record to the internal zone and referencing the internal ip addresses. You would not need to reconfigure  internal clients.
0
 

Author Comment

by:cameljoe121
ID: 38737974
Still no joy I added the company.com record in the dns and it still wont point if i used the FQDN company.com-tcp.company.local it will go to the mail server when I do a NSlookup I still get the external ip address
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 38738493
Whatever you are entering in to the ActiveSync clients as the FQDN needs to have an internal DNS entry.

You are probably entering host.example.com rather than just example.com.
Also ensure that the clients are using the server for DNS only, and are not getting DNS from the router for example.

Simon.
0
 

Author Comment

by:cameljoe121
ID: 38740308
DNS is provided by the server.  On the device I am entering host.company.com.  In the DNS console I added the Host.company.com forwarder it lists under the .com entry but still when i run lookup I get the exernal IP
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 2000 total points
ID: 38742338
Ensure that you have flushed the DNS cache on whatever you are using to test it. Check from the server itself.

Forwarder? Not sure that was the right thing to do.

The easiest way is to create a new zone called host.example.com, then create a new blank A record with the internal IP address of the Exchange server. That way it doesn't interfere with anything else.

Simon.
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Among the most obnoxious of Exchange errors is error 1216 – Attached Database Mismatch error of the Jet Database Engine. When faced with this error, users may have to suffer from mailbox inaccessibility and in worst situations, permanent data loss.
After a recent Outlook migration from a 2007 to 2010 environment, some issues with Distribution List owners were realized. In this article, I explain how that was rectified.
how to add IIS SMTP to handle application/Scanner relays into office 365.
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…
Suggested Courses

592 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question