Exchange Sync Issue and Logging - Galaxy Note 10.1 General

I am one of our Exchange admins here at that company.
One thing we are seeing a growing number of are Android devices throwing an error every so often when a user is syncing mail with their mailbox on our Exchange 2010 servers.
Users are able to setup the account without issues. It seems when they are connected to wifi, they will get the "can't connect to server".
Sometimes it keeps doing this, other times it syncs fine.
One of my network guys will be helping me tomorrow, but in the meantime I wanted to see if anyone else has seen this. I googled and it seems to be a common problem with no answer.
Another thing is, is it possible to turn on some type of logging for the email app? I would like to see if it throws an error in the log.
Would this be the debug logging? Sorry, I have never gatehered logs before on an android device.
I will say I saw this when i was syncing my S3 (I just stopped syncing it so I can 'unplug' when leaving work )

I'm on Exchange 2010 and don't have any issues with my Note II or 10.1. When I was on ICS a phantom "cannot connect” message would randomly pop-up but everything still worked the way it was supposed to. It went away when I updated to JB. Some folks got rid of it by clearing cache and data in the e-mail app and re-inputting their settings from scratch. I'm guessing it's a server-side security policy issue that's preventing the device from authenticating if there's no connectivity at all.
I assume you've already run this...
https://www.testexchangeconnectivity.com/

lardo5150 said:
It seems when they are connected to wifi, they will get the "can't connect to server".
Sometimes it keeps doing this, other times it syncs fine.
Click to expand...
Click to collapse
This can be caused by lack of a FQDN A record in the DNS server, resulting in the handhelds inability resolving the internal exchange server by using the external address.
Example;
Exchange server is called EXCH01 (192.168.1.10)
external webmail address is owa.somecompany.com (200.200.200.200)
Activesync on phone is configured with external webmail address.
While the phone is on the internal wifi it requests owa.somecompany.com and resolves 200.200.200.200, however most SMB/Enterprise firewalls will not easily NAT into itself.
In a proper configuration the dns server for 192.168.1.X wireless should have a A record pointing owa.somecompany.com to 192.168.1.10.
This will also address outlook anywhere issues.

Related

Direct Push - Connects & Syncs, but Inbox remains empty

I've searched and searched, but I can't seem to find anyone with this problem.
Basically, I'm trying to get my new Treo 750 to sync over wireless with my Exchange server. I run the Exchange server from my own house, on it's own domain. I've upgraded the Treo 750 to WM6. I previously did not try wireless sync on WM5. My Exchange server is 2003 SP2.
At first, I tried connecting via SSL only to get a message about the certificate not being valid. After fighting and fighting with trying to get the cert on the phone, I finally gave up and disabled SSL on the device in an attempt to connect.... via any means possible.
What I first thought was success has turned into another problem. I know I'm communicating with the server, as the policy from the domain controller made me set a device password. It was at that point that I knew I was getting somewhere. Now, when I hit "sync", I see it checking for changes. At the bottom of the screen, it'll run through each step: Contacts, Calendar, Email and Tasks.
Let me see if I can describe this..... It'll briefly pause at say... 0/80 for my Inbox, then count (very quickly, in large increments) till it hits the 80 and move on to the next item in the synchronization list. This cycle restarts after 5-10 seconds.
When I go to look in my Inbox, it's empty. The only thing I see is at the bottom: "Outlook E-mail 0 Items". Same with Contacts, Calendar, etc...
Now here's the kicker. If I send myself a test email from an outside account... say, Gmail, the sync app will then show "Email 0/81", then tick up to 81 and move on to the next item. However, nothing is downloaded. I can pull up a list of all the personalized folders I've created for my mailstore, and they're all there. I can "subscribe" to them, yet they remain empty as well.
I'm completely at a loss. I don't know what else to do at this point, and it's proving to be a difficult thing to search for. Any advice you can give would be very much appreciated....
As I said, this sync thing is happening pretty much non-stop. It'll rotate through the 4 steps (email, contacts, calendar, Tasks), wait a few seconds, then start it all over.
I've noticed that no other net apps work while this is happening. I actually have to go into ActiveSync and hit stop. After that, net applications (IM, PIE, Opera, etc...) work just fine.
Here is a (truncated) log from the device.
That looks pretty similar to the log I get from my device when I ActiveSync to Exchange. Jave you tried doing a backup and then hard resetting? I find that DirectPush is very finnicky with when it does and doesn't work but may just be my server.
Actually, to completely eliminate the device, I setup the MS WM6 emulator from a computer on an outside network. I got exactly the same thing as on the device. That pretty much tells me it's something on the server.
Here's another tidbit that might help. Before getting this phone, I setup BES Express on my Exchange server. I had problems with it working at first, and read through several guides before I had permissions working right. To this end, I made a lot of permissions-based changes on the Exchange server.
Could this be a permissions issue? How can I check if the permissions are correct?
Ok here's your problem, running another MAPI client on an Exchange server is NEVER a good idea. If you shut down the BES services and then reboot the server, what happens? Also, have you tried checking the Exchange Server event viewer for any info on what's happening server side?
Urthwhyte said:
Ok here's your problem, running another MAPI client on an Exchange server is NEVER a good idea. If you shut down the BES services and then reboot the server, what happens? Also, have you tried checking the Exchange Server event viewer for any info on what's happening server side?
Click to expand...
Click to collapse
Very good point. I hadn't even consider that. I don't even need it anymore.
That being said, what is the best way to go about uninstalling BES Express w/o jacking up the rest of the Exchange system? Also, have you ever actually heard of this causing the problem I'm experiencing? You sound pretty darn certain when you say: "Ok here's your problem". Each time I find or come up with a possible solution, it never seems to make a difference. Sure, my Exchange installation is "cleaner" and more standardized with each solution I try, but it never resolved the issue.
If you can provide me a decent guide or recommendation for uninstalling BES, I would appreciate it. Unless you have some better tips, I'm using these two pages as guides:
Perform a clean uninstall of the BlackBerry Enterprise Server
How to uninstall and re-install BlackBerry Enterprise Server on the same computer with minimal disruption
Ok, stopped all the services, uninstalled BES, deleted all related program directories, and removed all associated registry keys. Logged out of BESAdmin account and removed it from Active Directory.
I did all this from Remote Desktop, so the only thing left to do is reboot the server. I could do it remotely through command line, but it has a habit of freezing up during shut down (it's been doing it for years, doesn't seem to harm a thing). So I won't be able to reboot until I get back in town tonight.... just in case it freezes.
I have a few questions, though. Do I need to make any changes to MAPI (remove, stop, change, etc...)? I still need IMAP access for remote relatives, but I'm gonna get rid of that soon once I get them setup through the VPN.
Anything else I should remove/change?
Oh yeah, just for ****s and giggles, I tried synching again, both with the actual Treo 750 and also with a WM6 emulator on the remote server. I've also tried running the WM6 emulator from the same network as the Exchange server, just to eliminate the firewall, as Direct Push only seems to use ports 80 or 443, depending on whether you have SSL enabled or not.
Correct me if I'm wrong about the firewall ports.
Those are the same ports I have open, but much like yourself (and correct me if I'm wrong) just a casual Sysadmin. While I'm not entirely certain if BES is your issue, I'm inclined to think it may be a MAPI collision between the two. I haven't used BES myself so I can't really advise on the best method to uninstall, but I had a similar issue where my Outlook clients couldn't connect when I installed Outlook on the Exchange server. On another note, why set up VPN when you could just configure RPC over HTTP if you're running the server on Win2k3, it's probaly cut my support calls with users by aboyt 25%. If you'd like I can give you access to a server to compare it to, just PM me if you think that'd help.
I just saw that you also had IMAP open, that's definetly not going to be causing the issue, as I also have that running on my server and have people using it at this very minute. Also, have you tried checking on your device if you go into ActiveSync>Right Softkey>Options and then checking that the boxes besides Contacts, Calendars, Tasks, etc... are checked? I know it's stupid, but I've had issues like that before where I couldn't figure it out for the life of me.
Urthwhyte said:
Those are the same ports I have open, but much like yourself (and correct me if I'm wrong) just a casual Sysadmin. While I'm not entirely certain if BES is your issue, I'm inclined to think it may be a MAPI collision between the two. I haven't used BES myself so I can't really advise on the best method to uninstall, but I had a similar issue where my Outlook clients couldn't connect when I installed Outlook on the Exchange server. On another note, why set up VPN when you could just configure RPC over HTTP if you're running the server on Win2k3, it's probaly cut my support calls with users by aboyt 25%. If you'd like I can give you access to a server to compare it to, just PM me if you think that'd help.
Click to expand...
Click to collapse
I'm not 100% sure, but I don't think Direct Push uses MAPI at all, so I'm pretty sure it can't be a "MAPI collision", so to speak. I was able to completely remove BES w/o any issues. I rebooted the computer last night, just to be sure, and I'm still showing the same problem. ActiveSync connects and looks like it's synchronizing, but in the end, nothing is actually downloaded from my phone.
I really believe it has something to do with permissions. I say this, because I had a very difficult time getting BES to work. I had to mess with a lot of permissions to get mail flowing to my Blackberry. I can't be sure that I didn't goof something up in the process.
With that being said, everything else works just fine. I can use OMA. I can use OWA either HTTP or SSL (forms-based authentication disabled, of course). I can connect without issue from IMAP, or directly via Exchange over VPN, etc...
Urthwhyte said:
I just saw that you also had IMAP open, that's definetly not going to be causing the issue, as I also have that running on my server and have people using it at this very minute. Also, have you tried checking on your device if you go into ActiveSync>Right Softkey>Options and then checking that the boxes besides Contacts, Calendars, Tasks, etc... are checked? I know it's stupid, but I've had issues like that before where I couldn't figure it out for the life of me.
Click to expand...
Click to collapse
I have tried that. I've also tried changing the settings for email from 3 days, to all the other options. It will change the amount of emails ActiveSync "sees", but they still do not download to the phone.
Oh yeah, as far as RPC over HTTP goes, it's one of those "I've always used..." things.
What are the advantages of RPM over HTTP?
I'm not quite sure it's a permissions issue, because as far as I know ActiveSync only uses the standard exchange accounts/services,+ a few virtual directories. What you can try doing is deleting the ActiveSync virtual directory, and then restarting the IIS and Exchange System Attendant services and see if that helps.
RPC over HTTP alleviates the need to have to login to a VPN to check email, it also makes it much easier to configure the client, as they only have to enter their Username+Password and enter the FQDN of the server.
Urthwhyte said:
I'm not quite sure it's a permissions issue, because as far as I know ActiveSync only uses the standard exchange accounts/services,+ a few virtual directories. What you can try doing is deleting the ActiveSync virtual directory, and then restarting the IIS and Exchange System Attendant services and see if that helps.
RPC over HTTP alleviates the need to have to login to a VPN to check email, it also makes it much easier to configure the client, as they only have to enter their Username+Password and enter the FQDN of the server.
Click to expand...
Click to collapse
I deleted the ActiveSync virtual dir (which actually had a much longer name), as well as the OMA virtual dir.
Now I get this message when I try to connect. I guess I need some help on rebuilding it now... heh.
As for RPC over HTTP... brainfart. I knew what it is, but I wanted access to remote shares.
As far as permissions go, I'm pretty sure it's not the problem as well. I just created a brand new user and had the same thing happen.
Flapjack said:
I deleted the ActiveSync virtual dir (which actually had a much longer name), as well as the OMA virtual dir.
Now I get this message when I try to connect. I guess I need some help on rebuilding it now... heh.
As for RPC over HTTP... brainfart. I knew what it is, but I wanted access to remote shares.
As far as permissions go, I'm pretty sure it's not the problem as well. I just created a brand new user and had the same thing happen.
Click to expand...
Click to collapse
Did you try stopping and then starting the Exchange System Attendant and IIS services, the folders should come back automatically. If all else fails, reboot and see if the folders come back.
Urthwhyte said:
Did you try stopping and then starting the Exchange System Attendant and IIS services, the folders should come back automatically. If all else fails, reboot and see if the folders come back.
Click to expand...
Click to collapse
I know that trick, but if there is anything wrong in the metabase, it will not be overwritten.
I'll be using this guide to completely blast out and rebuild all the owa-related folders:
http://support.microsoft.com/kb/883380/en-us
Ok, I rebuilt everything using Method 2 in the above-linked guide.
Now, I'm getting support code 0x85010014
This pages says the cause is SSL being enabled on the main site, but it's definitely not. There are other vdir pages that have SSL enabled, but none of the default MS dirs... only personal ones I created for other things.
http://www.messagingtalk.org/content/479.html
Is there any chance that you have FBA enabled, if you do theres supposed to be some way that you can trick ActiveSync to use a different folder or something. It wasn't really worth it to me, so I just ended up disabling it.
Urthwhyte said:
Is there any chance that you have FBA enabled, if you do theres supposed to be some way that you can trick ActiveSync to use a different folder or something. It wasn't really worth it to me, so I just ended up disabling it.
Click to expand...
Click to collapse
That's the thing. I don't even have a certificate on the site right now. I got rid of the self-issued one, and now I'm waiting on my GoDaddy one. So I don't have FBA enabled. That's why that messages seems so weird...
Hmm, that's odd. I got the same error when I first configure ActiveSync, but now I forget what I did to resolve it. Also, is there any chance you have some sort of IM application, such as Google Talk or AIM? It's a bit easier to resolve these things if you can have a more back and orth communication then a orum post.

Exchange OMA Help!

I have searched and searched for an answer to this problem and have not been able to find anything. Hopefully someone here has run into this before and might have an idea or solutuion. Her is my problem.
I have two exchange servers (2003 SP2) on of which is a front end server handling OWA and OMA. We sync about 18 Windows Mobile 6.1 devices over the air using OMA. We are using SSL. All of our devices have random problems connecting to the server. They will sync fine most of the time but will randomly for no particular reason ask the user for their exchange password. We are not enforcing any password policies on the server and we are always checking the box to save the password. In order to get the device synching again the user has to re-enter their password multiple times and often has to kill and restart activesync on their device.
Any ideas as to what might be causing this?
Any help would be much appreciated.
You could try unchecking the box in Activesync on the phone that requires SSL. We use SSL as well, but we have to uncheck that box on the phone. Although our problem is that the phone never syncs when its checked as opposed to your problem of randomly not syncing and asking for a password.
Unfortunately that is not an option. Our SSL is required for authentication. It will not connect without it. It seems like what is happening is that the device is not always passing the credentials to the server. Usually when it asks me for the password I enter the password once making sure I check the Save Password box then when it asks me the second time I hit cancel. ActiveSync then gives me a could not authenticate error. Now if I just hit Sync again it goes through and works just fine without asking for the password. So my guess is that it is not passing the credentials until after the connection is reinitialized.
From what I understand, Push Email relies on the OMA functionality which uses IIS. The problem my lie there. Although I've never tried, you may have to uninstall/reinstall (or confirm) that the OMA part of Exchange is functioning correctly. Sorry I can't be of more help.
Do the log files on the server show anything when a phone can't log in?
No, the exchange logs don't show much. I almost think it might be something with the device configuration. At this point I just don't know. We will be migrating to Exchange 2007 sometime in the next few months. Hopefully that will resolve the problem permanently. I was just hoping maybe by some chance someone here had seen this problem before. Thanks a bunch for your help.
Is the FE server doing the authentication (NTLM) or is there an ISA server in the way configured with Forms Based Authentication? You should make sure the IIS virtual directory for OMA is set only for Basic Auth - and the following article might be worth a read.... http://searchexchange.techtarget.com/tip/0,289483,sid43_gci1188440,00.html
Hope that helps - good luck!!
Mark.
^^^What he said. Took the words right out of my mouth. You'll still be secured through the SSL certificate, even though you're doing "basic auth" you aren't exactly sending your password as clear text. Requiring SSL on the OMA site will automatically encrypt the connection so you have no need to worry.
Try it out and get back in here. I manage a site with about 50 WM 6.1 Black Jack II's that sync with Exchange 2007 with no issues whatsoever. Also verify that you have all your hotfixes related to OMA installed on your Exchange 2003 server.

Nexus & Exchange email

Morning - looks like I am one of the few in the Uk to have got my Nexus - arrived yesterday morning complete with engraving on the back.
As an aside the DHL tracking on the web still shows as only "shipment details received"!
The reason for my post is getting email from my Exchange server - it all works fine with my iPhone and Hero, but when ever I try to connect with the Nexus I keep getting "Setup could not finish - Unable to open connection to the server"
I have tried Touchdown and it is also upable to get the activesync profile from my server! gets a Error 500:
Is there something simple I am missing? I am able to browse the wen and get my gmail on the device but no exchange!
Any help would be great
Thanks
John
I have been able to use both the Android mail connection & Touchdown to connect to my hosted Exchange server (2007) using SSL, I guess as you have connected from other devices you must know the settings of the server.
Are you connecting via Wifi or 3G ?
Shouldn't make a difference, but which carrier are you on & did you get the 3G correct ?
Can you connect to the server on OWA via the browser ?
Good luck
Working fine for me, have you tried playing around with the settings? E.g. mine doesn't work unless I've checked the SLL box (but not the accept SLL certificates box), and make sure you precede the username with domain\
tried on both 3g and wifi - both no joy
just been looking for roadsync on the market and I don't appear to have any paid apps either...
been using an O2 sim just putting my orange sim to see if it makes a difference but doubt it will as wifi doesn't work...
stumpted!
I originally had a problem connecting with the native activesync with a similar error, however touchdown worked fine. I would try touchdown quick config and see if it can figure it out. You also might need to look at the certificate options under touchdown. Forcing that might help.
I have tried again with Touchdown - and managed to capture these results from the log:
I have reset my hero and reconnected to my exchange server and it connects fine...
I have called HTC to arrange a hardware replacement but the guy on the phone didn't seem to know what he was doing.
Checking Certificate...
Checking ActiveSync with SSL...
ActiveSync location returned HTTP code 500 : ( The request was rejected by the HTTP filter. Contact the server administrator. )
ActiveSync Version :ActiveSync ERROR :500
Trying activesync protocol 121...
ActiveSync provisioning returns HTTP:400
Error provisioning ActiveSync: Policy status is 0
Trying activesync protocol 2.5...
ActiveSync provisioning returns HTTP:200
ActiveSync provisioning success
The following policies have been requested :
- Allow Simple password
Refreshing AS folders
Error refreshing folders
Socket is not connected:Exception performing request
ActiveSync version check returned negative, but still trying for 12.1
Checking 2007 with SSL...
attr value delimiter missing! (position:START_TAG <HTML dir='null'>@2:11 in [email protected]) for operation: Subscribe-> Error renewing a subscription
Socket is not connected for operation: Subscribe-> Error renewing a subscription
Checking 2003 with SSL...
Checking 2003 without SSL...
Socket is not connected:Exception performing request
Would welcome any help from someone wiser than me
Cheers
John
How did you capture the log from Touchdown?
I'm using Touchdown here as well and have no issues to speak of. From what it looks like it might be something server-side?
Quick connect in touchdown captures the log as it tries to connect.
I agree it all points towards a server issue, but what is different between the nexus and the hero? I have reset my hero and reconnected with the standard android active sync connnector and it works fine. I use a neuxs with the exact same settings on either touchdown or the android connector and it fails!
It is driving me mad - I have synced my outlook contacts with my gmail account so I at least have numbers etc. but without email this phone is going to end up on ebay real fast
John
Not sure, but have you set the simple password in Touchdown? It looks like that is a required policy and if touchdown doesn't report back that it is set you won't be able to configure.
because the hero doesn't support the simple pin I got my exchange admin to remove this requirement for me
An even bigger thing for me was the lack of Exchange Calendar Sync on the N1. Seems a terrible omission when the Droid/Milestone supports it without trouble.

Exchange server syncing problems

All my other mail accounts sync perfectly on my HD2 except my outlook exchange account which I have yet to access. All the setting (domain, mail server) are correct and my co-workers who use android, and iphone have no problem logging into their work email. What's the deal? The error message reads, "a network or server error is currently preventing your device from syncing".
I about blew my brains out trying to set up my exchange account on my HD2. The most frustrating part is that all of the settings were correct. What finally got it set up and syncing? Hitting "sync" over and over again. It took me about an hour and a half of checking and unchecking boxes until everything was finally synced for the first time. Now that it's finally set up, it's running just fine.
Not sure if it's a glitch, or just an ActiveSync thing, but it took me a while before everything synced correctly.
leo876 said:
All my other mail accounts sync perfectly on my HD2 except my outlook exchange account which I have yet to access. All the setting (domain, mail server) are correct and my co-workers who use android, and iphone have no problem logging into their work email. What's the deal? The error message reads, "a network or server error is currently preventing your device from syncing".
Click to expand...
Click to collapse
I have the same problem and did everything in my power to get it to work. The main problem with me and the company's exchange server are the Certificates are not allowing the device to sync correctly. Since we are using WMo I guess it is more difficult to overrule the Security Certificates that by the way are expired and need to be updated.
Long story short…”I gave up” and only use the POP3 line that only gives you access to emails instead of Contacts, calendar, etc…
I think all of you probably need to talk to your Admin about getting a security certificate to install on your phone.
Setting up Exchange on the HD2 is simple and works for me every time... Our server requires me to have a certificate and I've reset my phone about 5 times and set up my outlook email with no probs every single time... But to get it to sync I have to install the Security Certificate. Any secure exchange server with a smart Admin requires one to access the server from the outside...
If you are putting in the correct user, pass, domain and server address, then that is probably it. Also make sure you Data Connection is not disabled in Settings/Wireless Controls.
Hope this helps...

Email "unable to connect server"

Hey
I have problems connecting my account with Email app :S
I get this each time:
http://postimage.org/image/74zbd2pvn/
I was logged into a large hospital's complimentary WIFI service as a "guest" recently. Most apps that required Internet access worked just fine. The exception was the email app. I got a message similar to what you posted. Yahoo mail worked perfectly, however.
The strange thing is that the email app works just fine when connected to most other wifi signals. I have only observed this problem at when connected to this particular wifi source.
Strange
That's because most workplace has internet filtering on. Blocking personal emails are common practice.
For OP's issue, to connect to Hotmail/Live accounts, you must manually configure it as exchange account type. Use m.hotmail.com as your mail server.

Categories

Resources