Home > Microsoft Exchange Tips > Exchange Server Administration Tips > Using ActiveSync without a front-end Exchange server
Exchange Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

EXCHANGE SERVER ADMINISTRATION TIPS

Using ActiveSync without a front-end Exchange server


Brien Posey
05.29.2008
Rating: --- (out of 5)


Exchange Server tips, tutorials and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Whether or not you're using Exchange ActiveSync with a network address translation (NAT) firewall, ActiveSync problems occur in organizations that don't utilize a dedicated front-end Exchange server. Fortunately, some workarounds are available to troubleshoot this ActiveSync issue.

If an organization doesn't use a dedicated front-end Exchange server, it's very common for users to receive the HTTP_500 error, along with a message stating that "Synchronization failed due to an error on the server." This occurs because Exchange ActiveSync uses the /Exchange virtual directory to access DAV on the back-end Exchange server. While this isn't a problem, there are two conditions that can prevent the /Exchange virtual directory from working properly.

  • If no front-end server is present, the /Exchange virtual directory cannot be configured to require Secure Sockets Layer (SSL). If SSL is required, directory access will fail. This is only the case for back-end Exchange servers. If the /Exchange virtual directory is located on a front-end server, then SSL is supported and recommended.
  • If forms-based authentication is enabled, you can't enable it on a back-end Exchange server if you want to use ActiveSync. Enabling forms-based authentication on a front-end Exchange server isn't problematic.

There are two ways to correct a forms-based authentication failure. The preferred method is to deploy a front-end Exchange server. If you're trying to use ActiveSync without a dedicated front-end server, deploying one may not be an option because of budgetary issues. A workaround that involves editing the mailbox server registry can be helpful in this situation. I recommend making a full-system backup before continuing.

More on Exchange ActiveSync:
How to solve common ActiveSync error messages

Exchange ActiveSync tips and tutorials

ActiveSync and front-end DNS aliases

If you have SSL and/or forms-based authentication enabled, there is probably a logical reason for this. They don't need to be disabled permanently. Instead, we will create a second instance of the /Exchange virtual directory that doesn't require SSL or use forms-based authentication. Before beginning this procedure, disable forms-based authentication on your /Exchange virtual directory. You can re-enable it afterward.

  1. Open the Internet Information Services (IIS) Manager, and navigate through the console tree to the \Web Sites\Default Web Site\Exchange container.
  2. Right click on the Exchange container, and choose the All Tasks -> Save Configuration to a File commands from the menu. You will be prompted to enter a path and a filename. You can name the file anything that you want.
  3. Go into the IIS Manager's console tree to the Default Web Site container. Right click on this container, and choose the New -> Virtual Directory (From File) commands.
  4. Windows will display the Import Configuration dialog box. Click Browse, choose the file that you created earlier and click Open and then Read File. You should now see the Exchange virtual directory listed in the Import Configuration dialog box (Figure 1).
  5. Exchange virtual directory in the Import Configuration dialog box
    Figure 1. The Exchange virtual directory will be listed in the Import Configuration dialog box.

  6. Select your virtual directory, and click OK. A screen will ask if you want to create a new virtual directory or replace the existing one. Select the option to create a new virtual directory, and enter Exchange-OMA as the directory's alias. The virtual directory that you have just created should now be listed among the list of virtual directories, as shown in Figure 2.
  7. IIS Manager console lists Exchange virtual directories
    Figure 2. The new Exchange virtual directory will be listed in the IIS Manager console.

  8. To configure the new virtual directory, right click on it and choose Properties from the menu. The console will display the virtual directory's properties sheet.
  9. Go to the Directory Security tab and click Edit from the Authentication and Access Control section. The console then will open the Authentication Methods dialog box. Make sure that either the Integrated Windows Authentication or Basic Authentication checkbox is selected – not both. Figure 3 shows what this will look like.
  10. Configuring Integrated Windows authentication or Basic authentication
    Figure 3. Select either the Integrated Windows Authentication or Basic Authentication checkbox.

  11. Click OK, and then click the Edit button found in the IP Address and Domain Name Restrictions section.
  12. When the IP Address and Domain Name Restrictions dialog box appears, click the Denied Access button and then click Add. Choose Single Computer, enter the server's IP address and then click OK.
  13. Click Edit in the Secure Communications section. When IIS displays the Secure Communications dialog box, be sure that the Require Secure Channel (SSL) checkbox isn't selected.
  14. Click OK twice and then close the IIS Manager.

You must modify the server's registry to make Exchange Server aware that the virtual directory you created exists. To do so:

  1. Open the Registry Editor and navigate through the tree to: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MassSync\Parameters
  2. Right click on the Parameters container and choose New -> String Value.
  3. Enter ExchangeVDir as the value's name. NOTE: This value name is case sensitive.
  4. Right click on the value you created, and choose Modify from the menu. Enter the name of the new virtual directory -- /Exchange-OMA.
  5. Click OK, close the Registry Editor and reboot the server.

About the author: Brien M. Posey, MCSE, has previously received Microsoft's MVP award for Microsoft Exchange, Windows Server and Internet Information Server (IIS). He has served as CIO for a nationwide chain of hospitals and was once responsible for the Department of Information Management at Fort Knox. As a freelance technical writer, Brien has written for Microsoft, TechTarget, CNET, ZDNet, MSD2D, Relevant Technologies and other technology companies. You can visit Brien's personal website at www.brienposey.com.

Do you have comments on this tip? Let us know.

Please let others know how useful this tip was via the rating scale below. Do you know a helpful Exchange Server, Microsoft Outlook or SharePoint tip, timesaver or workaround? Email the editors to talk about writing for SearchExchange.com.

Rate this Tip
To rate tips, you must be a member of SearchExchange.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Mobile Devices
Configure Microsoft SharePoint mobile access via Exchange Server 2007
Synchronizing the Windows Mobile emulator with Exchange Server 2007
Configure a mobile device to receive POP3 email from Exchange Server
Email sent to a PDA doesn't get saved in Exchange Server mailbox
Synchronizing Apple iPhone email with Microsoft Exchange Server
Use the free Windows Mobile emulator to test mobility on Exchange
Why Exchange ActiveSync fails with NAT firewalls
Is it time to upgrade users' Windows Mobile devices?
Deploying ISA Server as a firewall for Exchange Server mobile devices
Adjust your firewall to avoid Exchange 2007 Direct Push failures

Exchange Server Administration Tips
Migrating .PST files to an Exchange Server information store
Virtualizing Exchange Server 2007 with Microsoft's Hyper-V
Configure SMTP connection limits in Exchange Server 2003 and SBS
Five Microsoft Exchange Server backup worst practices
How to export Global Address List data to Microsoft Office Access
Create a group policy to prevent .PST file storage in Exchange 2007
Synchronizing the Windows Mobile emulator with Exchange Server 2007
Considerations for virtualizing an Exchange Server environment
Why are .PST files a security threat to Exchange Server mailboxes?
EMS add-on tool generates graphical Exchange Server 2007 reports

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts