Forum Discussion

Kris_01_158159's avatar
Kris_01_158159
Icon for Nimbostratus rankNimbostratus
Jun 13, 2014

F5 activesync issue with Windows 8 phones

Hi,

 

Hoping somebody can give guidance on this particular issue where we have rolled out F5 deployment for ActiveSync and Exchange services. This issue only appears for Windows 8 or Windows phones in general where it continuely prompts for password input after a reboot or simply if there is a drop in mobile network and comes back then the password is required.

 

Is there something we can do in the F5 config, or where should I be looking to remedy this issue.

 

Works well for other handsets including IOS and android, no issues.

 

Hope there is solution to resolve this as we have quite a huge windows phone user population whether it be a simple tweak with the F5 or tweak with exchange.

 

We use simple basic http authentication, i thought maybe its do with session persistence or session handling for non browser clients perhaps ?

 

Kind help is much appreciated.

 

8 Replies

  • kunjan's avatar
    kunjan
    Icon for Nimbostratus rankNimbostratus

    You can enable debug for accesscontrol APM and see in the logs where it is failing. Activesync uses iRules. So I guess need to take look at that as well and the logs in the /var/log/ltm

     

  • mikeshimkus_111's avatar
    mikeshimkus_111
    Historic F5 Account

    Hi Kris, can you provide some more info:

     

    1) Which version of BIG-IP, Exchange and Windows Server are you using?

     

    2) If you are using BIG-IP v11 or later, did you use the iApp to deploy and if so, which version of the iApp template are you using? If not, did you use the latest version of the Exchange deployment guide?

     

    3) Are you using APM or AVR/Analytics?

     

    4) Do you still get the auth prompts if you bypass the BIG-IP and connect directly to the Client Access server?

     

    thanks

     

    Mike

     

    • Kris_01_158159's avatar
      Kris_01_158159
      Icon for Nimbostratus rankNimbostratus
      Hi Mike, BIG-IP VE - 11.5.0 Exchange 2010 Windows Server 2008 R2 Yes we used a custom iApp to deploy " f5.microsoft_exchange_2010_cas.2012_06_08". We are using APM. 4 question is tricky to test, i cannot verify that. But if we click cancel and synchronize on the windows phones, it remembers the password and works ok , which is odd. As i said, its no issues with Android or IOS, just main issue is with windows phones when reboot or out of reach with mobile network. Thanks Mike
  • mikeshimkus_111's avatar
    mikeshimkus_111
    Historic F5 Account

    We recommend upgrading to v1.3.0 of the iApp. It's available at downloads.f5.com.

     

    If you still have the issue after deploying with the latest iApp, you should set the APM access and SSO logs to debug in the System menu and tail /var/log/apm while a Windows 8 phone client tries to connect. If you post the output here I can have a look.

     

  • Hi Mike,

     

    Performed some captures of the apm and sso logs (these were both enabled in system/config/options) and ran some tail queries as suggested.

     

    See below output on gist for the username "domainuser"

     

    https://gist.github.com/anonymous/b18dcd0195bae355ce32

     

    • Kevin_Davies_40's avatar
      Kevin_Davies_40
      Icon for Nacreous rankNacreous
      Kris, Goto to gist.github.com, paste it there, past link here :-) Might be better formatted that way.
    • Kris_01_158159's avatar
      Kris_01_158159
      Icon for Nimbostratus rankNimbostratus
      HI Kevin/Mike, https://gist.github.com/anonymous/b18dcd0195bae355ce32 Thanks
    • mikeshimkus_111's avatar
      mikeshimkus_111
      Historic F5 Account
      It looks like you're using a Basic SSO for auth to the Client Access servers. This should be NTLM. You definitely need to upgrade to v1.3.0 of the iApp. It uses the APM Exchange profile that was introduced in v11.4, which is getting updated on a regular basis, unlike the _sys_APM iRule that we used in previous versions.