Solved

Email on Iphone will Work on external Netowrks but not internal wifi

Posted on 2013-01-02
9
449 Views
Last Modified: 2013-01-04
We have a 2003 SBS DC.  Email works push perfectly outside the company network but, will not work via internal wifi.  I know that you cannot access the external ip address from inside.  Is there any way to correct this issue?
0
Comment
Question by:cameljoe121
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 15

Expert Comment

by:jerseysam
ID: 38736809
Have a look at issue 3 here: http://support.apple.com/kb/TS1868

Seems to be a known issue
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 38736844
You need a split DNS system so that the external host name resolves internally.
http://exchange.sembee.info/network/split-dns.asp

The single host name replacement method should work fine.

Simon.
0
 

Author Comment

by:cameljoe121
ID: 38736954
I need a little more help here.  The internal clients connect to the mail using the FQDN Server01.Comanyname.local I dont want to have to change all the clients existing config.   The way the existing setup for external mail is either the IP address or MX.companyname.com cant i just add something for the interanl DNS lookup so is the see the MX.companyname.com it will point to the mail server or will this cause an issue?
0
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 
LVL 17

Expert Comment

by:OriNetworks
ID: 38737016
I am assuming the iphone is already set up with the email account and then you are turning on wifi to start using it internally. Since it is already using the external ip address, it will still be trying to reach that address. On your firewall you can enable the wifi clients to only access the external IP for the email server instead of blocking all traffic. Or for internal DNS, point the server name that you used to set up the account on the iphone to the internal ip address of the mail server.

Another possibility is that it may be trying to validate the SSL certificate with an external certificate authority and it does not have internet access to do that. In this case you should enable the internal clients to have outside access to the crl lists e.g. crl.verisign.com
http://www.verisign.com/repository/crl.html

Simplest answer:
If the iphone is set to point to mail.mycompany.com make sure the internal record for the mail host is set to the internal ip address.
0
 
LVL 17

Expert Comment

by:OriNetworks
ID: 38737025
I just read your last comment. Since you have split DNS, you need to create a duplicate zone in DNS for companyname.com. Add a host for whatever the mail server name is and point it to the internal ip address of the server. Basically you are copying any external DNS record to the internal zone and referencing the internal ip addresses. You would not need to reconfigure  internal clients.
0
 

Author Comment

by:cameljoe121
ID: 38737974
Still no joy I added the company.com record in the dns and it still wont point if i used the FQDN company.com-tcp.company.local it will go to the mail server when I do a NSlookup I still get the external ip address
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 38738493
Whatever you are entering in to the ActiveSync clients as the FQDN needs to have an internal DNS entry.

You are probably entering host.example.com rather than just example.com.
Also ensure that the clients are using the server for DNS only, and are not getting DNS from the router for example.

Simon.
0
 

Author Comment

by:cameljoe121
ID: 38740308
DNS is provided by the server.  On the device I am entering host.company.com.  In the DNS console I added the Host.company.com forwarder it lists under the .com entry but still when i run lookup I get the exernal IP
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 38742338
Ensure that you have flushed the DNS cache on whatever you are using to test it. Check from the server itself.

Forwarder? Not sure that was the right thing to do.

The easiest way is to create a new zone called host.example.com, then create a new blank A record with the internal IP address of the Exchange server. That way it doesn't interfere with anything else.

Simon.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Suggested Courses
Course of the Month7 days, 23 hours left to enroll

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question