Solved

Exchange 2010 - ActiveSync (Internal and External)

Posted on 2014-11-05
17
728 Views
Last Modified: 2014-11-07
Hi Guys,

Got a small issue that I can't seem to get my head around.

I have one Exchange 2010 server running with a Geo Trust SSL certificate with services such as OWA, Activesync etc.  Everything is working fine, apart from one small problem - ActiveSync.

ActiveSync works externally, however, it will not work internally. I believe this to be a DNS issue.   So I just want to run through the config, to see if anyone can spot my mistake.

Mobiles devices are currently pointing at:

mail.company.co.uk  (I have a SANs cert for this domain)

Question.

** When using a browser for webmail - I use the address mail.company.co.uk/OWA (this works fine with my SSL cert)

However, when configuring ActiveSync on a mobile device  you can ONLY use the address mail.company.co.uk.  Even though in EMC it's mail.company.co.uk/activesync - So there must be a way the system knows it's an ActiveSync connection?

Which comes to my question.

I have an internal DNS entry for mail.company.co.uk which points to my Exchange server.  When a device is connected internally, this address resolves correctly to the Exchange box, however, the ActiveSync mail does not work unless I use the internal address that's set in EMC.  ie severname/Microsoft-Server-ActiveSync

So, how do I get the devices to work Externally and Internally.  My gut feeling is, DNS.  But I just can't figure out what needs to be done.

Any help offered will be greatly appreciated.

IM
0
Comment
Question by:ianmclachlan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 6
  • 2
  • +2
17 Comments
 
LVL 13

Expert Comment

by:Andy M
ID: 40423880
Typically with activesync you only require the mail.company.co.uk address - Activesync uses port 443 same as OWA.

The fact that it is working externally (i'm guessing on the same phones) indicates Activesync is working and the internal issue would lean towards either a config issue on the server or dns.

Looking at your information I would firstly change the internal EMC activesync address on the exchange server to match the external one - mail.company.co.uk. You already have a dns record in place for this and as you have noted it resolves fine. Remember to include the activesync parts after the address (just copy and paste the external one) - the server requires this but the devices do not.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 40423926
0
 

Author Comment

by:ianmclachlan
ID: 40424152
Hi Guys,

Thanks for your replies.

Alan - This is exactly my problem.  However the solution doesn't seem to work in my case.  Have create the zone and a blank host record pointing at the Exchange box.  I am using an iPad and have networking tools installed.  And although I can ping mail.company.co.uk from my internal wifi, Activesync will still not work, yet externally it's fine.

I've tried Andy's solution of changing the internal address in the EMC to mail.company.co.uk, but again, no luck.  There are no errors coming up in the event log on the exchange box.  So I really don't have a lot to go on.

Can you think of anything else.

Really appreciate your time and help.

IM
0
Office 365 Training for Admins

Learn how to provision tenants, synchronize on-premise Active Directory, and implement Single Sign-On with these master level course.  Only from Platform Scholar

 
LVL 19

Expert Comment

by:Adam Farage
ID: 40424321
What errors in the event log?
0
 

Author Comment

by:ianmclachlan
ID: 40424330
Hi,

There are no errors in the events log.

IM
0
 
LVL 19

Expert Comment

by:Adam Farage
ID: 40424357
Sorry, I misread above. You are using an iPad on the internet network right? A few questions:

- Is there a firewall between the production LAN and the WLAN (wireless LAN)? Is TCP 443 nat'ed to that?
- What is your InternalURL for ActiveSync (EAS) and your settings?
- What is your internal DNS A records look like?
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 40424533
Can you get to https://mail.company.co.uk/owa from the iPad using Safari on WiFi?
0
 

Author Comment

by:ianmclachlan
ID: 40425703
Hi Guys,

Again, thanks for your reply.

Adam :

No there is no firewall between the wireless lan and the corporate lan.  The wireless lan is on the same subnet as the exchange box.
Have tried both internal urls as :   https://mail.copmpany.co.uk/microsoft-server-activesync   as well as :  https://servername.domain/microsoft-server-activesync - both fail (issued cmd iisreset after making both changes)
I have create a new zone in my DNS called :  mail.company.co.uk in which have created a blank A record to point to the exchange box.

Alan :

Interestingly enough, I can't access the OWA internally from the ipad.   Yet, if I ping mail.company.co.uk from the ipad, I get a response from the exchange box (on the internal IP)

There is no doubt it's a DNS issue.  I just can't see it.  On paper this should work.  The DNS server address is issued by DHCP when connecting to the WLAN.

Found that if I change the URL in the ipad to the local address :  servername.domain/microsoft-server-activesync it works, but not with the public name.

IM
0
 
LVL 12

Expert Comment

by:Md. Mojahid
ID: 40425714
It is a dns issue. Create a new zone in DNS for your mail server called domain.com.
Then create an A record for mail.domain.com that points to the private ip of your exchange server.

If they can access OWA through Safari via the wireless then we have prooved that there is no DNS problem (as long as you are using the same domain name in the active sync configuration)..

Do you have any IP restrictions applied to any of the exchange virtual directories? I am running out of ideas...

For more
http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_27974749.html
https://social.technet.microsoft.com/Forums/en-US/7f7b9d96-84b3-46ed-a888-adeee1543f39/exchange-2010-activesync-internal-vs-external-networks-issues
0
 

Author Comment

by:ianmclachlan
ID: 40426060
Hi Guys,

I have since discovered this isn't an issue with my split-dns.  I hooked up an Android device in the same senario and it works fine.  It's an issue with the iphones/ipads.  This KB touches on it:

http://support.apple.com/en-us/TS1868   (point 3)

The only probable fix for this is by setting up a reflected NAT on my Firewall and using external DNS servers to resolve the address.  I'm not happy about doing this.  Does anyone know of a better solution?  

I have a feeling that with the popularity of the device and platform, there must be a better fix.

Again, thanks for your help and support.

IM
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 40426073
That only says what's already been touched upon above.

Adding the relevant DNS zone / A record should resolve the issue unless you have some funky wireless filtering / restrictions going on whilst on WiFi.

What WAP are you using?
0
 

Author Comment

by:ianmclachlan
ID: 40426123
Hi,

The DNS is working and resolving correctly.  I had originally set the zone up properly.  The red herring was the fact I was using an ipad to test this.  Had I picked an Andriod device, I would of quickly came to the conclusion (when they didn't work) that the Apple devices are at fault.  I can confirm this as I have setup an Andriod tablet using mail.company.co.uk, then moved it to my corporate wifi ... and it works.  It doesn't work with an ipad.  Same setup.

My wifi is pretty standard WPA with Radius.  There is no filtering or restrictions.  I can rule out wifi as well as DNS to a point.  The issue appears to be the relationship between Apple devices and resolving the activesync URL internally - (which DNS has to play a part of).

I am no expert with Apple devices, so I can't understand why it finds this a problem.

Again thanks for yor reply.

IM
0
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 500 total points
ID: 40426140
I've never known a problem with an Apple device not working internally when the DNS zones are working as suggested.

I've never used WiFi with Radius, so that might be something that the Apple Devices struggle with.  Can you disable the Radius element for testing and just use simple Wi-Fi security, then if it works, you have something to chew on.

Thanks

Alan
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 40426147
The following Apple article might help you:

http://support.apple.com/en-us/HT6187

Alan
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 40426151
Read the last 2 or 3 comments from the link below:

https://discussions.apple.com/thread/6536955?start=15&tstart=0

Which is where my first link is from.
0
 

Author Comment

by:ianmclachlan
ID: 40427950
Hi Guys,

Thanks for the feedback.  You're right, it's something to do with the WPA enterprise WLAN.  I plugged in an unsecured AP to the corporate LAN and it worked fine.

So now I need to find a way of configuring iPads/iPhones for my wifi.  It strange though.  I'm getting a DHCP address and if I use imap instead of exchange the mail runs ok over the WPA (E).

This has been one long saga.  I would have never of guessed it was the wifi causing the issues.

So I'll Google this out and see if I can find a fix.

Again, thanks for all your help.
0
 

Author Comment

by:ianmclachlan
ID: 40427975
Finally ....  Fixed it.

So obvious.  The ipad connects onto the WPA(E).  We manually set a proxy address for the ipad for web access.  What appears to happen is that the system tries to "sync", and pushes to mail.company.co.uk - this then squirts it straight to the proxy to deal with, without first, trying to resolve the address using our internal DNS.  As we have not setup reflective NAT it fails.  Therefore, I set a static route on the proxy to push the trafffic back to the Exchange box.

I assume it worked with imap as I used the IP address and it knew it was on the same subnet.

Been round the houses with this one guys.

Alan, I will award you the points as you pointed me in the right direction suggesting the wifi.

Many thanks for everyones help.

IM
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
Many of my clients call in with monstrous Gmail overloading issues with Outlook. A quick tip is to turn off the All Mail and Important folders from synching. Here is a quick video I made to show you how to turn off these and other folders in Gmail s…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question