Connecting to OWA/Exchange from Android/iPhone only works outside firewall. Internal wifi = can't find external server

3

We can only connect to ActiveSync on our exchange server from the outside world (using our external IP address). This is true for iPhone, Android, and OWA (outlook web access).

Once we connect one of these devices to our INTERNAL wifi network, ActiveSync can no longer work because the device cannot see the external IP once it's on our internal network. We have to reference the internal IP to gain access (highly undesirable as you can imagine).

I know the issue, but I don't know what this is called or what needs to be done on the router to "forward" the requests internally. Is this called "internal IP remapping" or something? I can't find any settings on our RV042 cisco gateway to configure to "map" the external IP back to the internal IP of the exchange server.

Any assitance is helpful :)

degenerate

Posted 2012-08-22T19:41:31.330

Reputation: 365

Answers

2

Not sure why you are restricted to using an IP but most companies use a domain name to connect phones to their Exchange server. Thus Public servers will resolve Webmail.yourdomain.com to your external IP and then you just need add an entry on your DNS server under forward lookup zones for webmail.yourdomain.com to resolve to the internal IP.

Supercereal

Posted 2012-08-22T19:41:31.330

Reputation: 8 643

Thanks, this worked. Since our Server 2003 is our DNS server, I was able to go into DNS management and add a new zone and A RECORD for webmail.OURDOMAIN.com which pointed to itself (the 2003 server IP). Immediately the internal computers could access the server using the alias. – degenerate – 2012-08-24T18:45:18.597

1

Using DNS should solve this problem. Instead of entering the IP into the phone, use a DNS entry like "mail.YOURCOMPANY.com"

Wherever the dns A records are stored for your domain (godaddy, dnsmadeeasy, networksolutions, etc), you can easily add an A Record for a subdomain that will point to your external IP.

ABashore

Posted 2012-08-22T19:41:31.330

Reputation: 535

Thanks for the assisted answer; Kyle pointed me to forward lookup zones which was what I really needed. – degenerate – 2012-08-24T18:46:04.743