<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blog.devicewire.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Devicewire Community</title><link>http://blog.devicewire.com/blogs//blogs/default.aspx</link><description>Online forum for devicewire.com</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61129.2)</generator><item><title>Unable to use Exchange 2003 Outlook Web Access on Windows Vista PCs</title><link>http://blog.devicewire.com/blogs/devicewire/archive/2008/07/20/unable-to-use-exchange-2003-outlook-web-access-on-windows-vista-pcs.aspx</link><pubDate>Sun, 20 Jul 2008 11:25:00 GMT</pubDate><guid isPermaLink="false">df238d37-d6e2-4966-96cd-299e643337d6:868</guid><dc:creator>jamesl</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;I thought that I would fire off a quick blog post about this issue as it happened to me recently: a number of users reported that they could not reply to email messages, or compose new messages, when accessing Outlook Web Access (OWA) from PCs running Windows Vista. They were able to log in and read messages, but when trying to send a message, the text-entry box was unavailable.&lt;/p&gt;&lt;p&gt;The issue was definitely related specifically to the conbination of Vista and IE7, rather than IE7-specific, as IE7 on a Windows XP machine was not affected, and running Firefox on Windows Vista was also not affected. &lt;/p&gt;&lt;p&gt;A bit of Google action revealed that the issue is down to the fact that support for DHTML (Dynamic HTML - HyperText Markup Language) has been retired on Windows Vista, and a patch must be applied to the Exchange 2003 Server to effectively re-write the HTML code behind the OWA web site.&lt;/p&gt;&lt;p&gt;The patch can be downloaded from the Microsoft web site here:&lt;/p&gt;&lt;p&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=5bc06e8a-08eb-4976-bc68-a03ebe3a2552&amp;amp;DisplayLang=en&lt;/p&gt;&lt;p&gt;The pre-requisites listed for the patch include Exchange 2003 Service Pack 2. Our Exchange Server has service pack 2 installed - as testified to by the fact that we have been enjoying push email service for a number of years now.&lt;/p&gt;&lt;p&gt;Problem solved you would think. Apparently not.&lt;/p&gt;&lt;p&gt;When I went to install the patch I received an error message indicating that the patch could not be installed because service pack 2 was not installed on the server.&lt;/p&gt;&lt;p&gt;A bit more digging, and a lot of swearing at my screen, I came across an article indicating that there are 2 principal versions of service pack 2 for Exchange currently in circulation - one of them is known as the 'technology preview release' and was made available to TechNet subscribers prior to being released generally through Microsoft Update. The patch did not like the fact that I had the preview release, even though the funcitonality is exactly the same.&lt;/p&gt;&lt;p&gt;To find out if you are running the preview release, or the full release, open Registry Editor and browse to:&lt;/p&gt;&lt;p&gt;HKEY_Local_Machine\Software\Microsoft\Exchange\ServicePackBuild\ &lt;/p&gt;&lt;p&gt;If the value reads 1DC7 then you have the preview, if it reads 1DD6 then you have the full release.&lt;/p&gt;&lt;p&gt;The solution was to download and reinstall Exchange Server Pack 2 over the top of the existing installation. Once installed the patch then installed also...and Vista users can now use OWA properly.&lt;br&gt;&lt;/p&gt;&lt;img src="http://blog.devicewire.com/aggbug.aspx?PostID=868" width="1" height="1"&gt;</description></item><item><title>Using the Apple iPhone with Microsoft Exchange</title><link>http://blog.devicewire.com/blogs/devicewire/archive/2008/07/14/using-the-apple-iphone-with-microsoft-exchange.aspx</link><pubDate>Mon, 14 Jul 2008 10:16:00 GMT</pubDate><guid isPermaLink="false">df238d37-d6e2-4966-96cd-299e643337d6:867</guid><dc:creator>jamesl</dc:creator><slash:comments>0</slash:comments><description>&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;b&gt;&lt;span style="font-family:Arial;"&gt;&lt;font size="3"&gt;&lt;br&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;br&gt;Version 2.0 of the iPhone software (available for download for owners of the original iPhone, but effectively the software developed for the release of the 3G iPhone), includes a licensed version of Server ActiveSync: the Microsoft protocol that allows both Windows Mobile-based and non Windows Mobile-based devices to synchronise email, contacts, calendar and tasks folders with a Microsoft Exchange mailbox, via any Internet connection, via “direct push”.&lt;br&gt;&amp;nbsp;&lt;br&gt;Also included in this release of the software is the ability to enforce the use of a password on the iPhone from the Exchange Server via a Mailbox Policy rule (Exchange 2007 only), as well as the ability to remotely ‘wipe’ the contents of an iPhone and restore it to a factory default state. A remote wipe operation can be triggered either via Outlook Web Access, via the Mobile Web Administration Tool (Exchange 2003) or via the Exchange Management Console (Exchange 2007).&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/iphone/iphone001.jpg" height="457" width="622"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;NOTE – it can take up to 1 hour for each 8GB of memory to be erased, it is recommended that the device be connected to a power supply during this process. If the device turns itself off due to low power, the process will continue when the device is powered back on again.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Users can also access the Exchange Global Address List from the iPhone and have email addresses completed automatically as they are entered when composing a new email message.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;There are some features that are not supported, however, such as it is not possible to turn on an Out Of Office message from the iPhone, nor is it possible to move items between mail folders.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Task synchronization is also not supported.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;b&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Activating the iPhone&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Provided that you have an activated SIM correctly inserted in the iPhone, you cannot use the device until you have first connected it to a PC that has iTunes installed. At the time of writing version 7.7 is the current version of iTunes available.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;iTunes will then run the user through a wizard which will activate the device for service (the same also applies to the iPod Touch).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;If the iPhone is being rolled out across a business, this means that the administrator must decide whether to install iTunes on each iPhone user’s PC, or activate all devices themselves on their own PC with iTunes installed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;NOTE – iTunes is only required for the activation process. Once activated, iTunes is not required to enable the device to access corporate systems, only to synchronise music, photos and videos.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;iTunes is required, however, to install applications and software updates onto the device.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;The direct push capability of Microsoft Exchange Server is only available via a cellular data connection. Although the iPod Touch can access Exchange via a WiFi connection to the Internet, this is a ‘pull’ connection rather than ‘push’.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;NOTE – if your organization does not use Mircosoft Exchange, it is still possible to use the iPhone and iPod Touch with POP and IMAP-based email servers. Calendar and Contact entries can also be synchronized with the Address Book and iCal applications on MacOS and with Microsoft Outlook on a Windows PC via iTunes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;b&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Configuring Devices&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;If you are only deploying a small number of devices, it may be preferable to allow users to configure their own devices. However, should a large number of devices be deployed, there are tools available to help.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;The use of configuration profiles allows for a number of settings to be quickly and easily deployed to a large number of devices.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;A configuration profile is an XML document that contains settings on Email, WiFi connections, VPN settings, certificates and security policy settings.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Profiles are distributed to devices either via email, as an attachment, or via a web link.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Configuration Profiles are created using the iPhone Configuration Utility, available for free download from the Apple web site:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;a href="http://www.apple.com/support/downloads/iphoneconfigurationutility10formacosx.html"&gt;&lt;font color="#800080"&gt;http://www.apple.com/support/downloads/iphoneconfigurationutility10formacosx.html&lt;/font&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;(MacOS only)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Or alternatively, a web-based version can be downloaded which can run on either MacOS or Wndows:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;a href="http://www.apple.com/support/iphone/enterprise/"&gt;&lt;font color="#800080"&gt;http://www.apple.com/support/iphone/enterprise/&lt;/font&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Once installed, the web site is accessed by browsing to &lt;a href="http://localhost:3000/"&gt;http://localhost:3000&lt;/a&gt;, log in with ‘admin’ for both username and password.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;The interface for the utility looks like this:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/iphone/iphone002.jpg" style="width:1088px;height:855px;" height="855" width="1088"&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;A full explanation of the Configuration Utility can be downloaded from the Apple web site:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;a href="http://support.apple.com/manuals/en_US/Enterprise_Deployment_Guide.pdf"&gt;&lt;font color="#800080"&gt;http://support.apple.com/manuals/en_US/Enterprise_Deployment_Guide.pdf&lt;/font&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;The General tab allows you enter a name and identifying information for the Profile.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;The Passcode Settings tab allows the administrator to define an on-device password usage policy:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/iphone/iphone003.jpg" style="width:1088px;height:855px;" height="855" width="1088"&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;The maximum number of failed attempts field allows the administrator to define how many times the device password can be entered incorrectly before the device becomes unusable. By default, after six unsuccessful attempts the device imposes a time delay before a passcode can be entered again. The time delay increases with each failed attempt. After the eleventh failed attempt, the device is locked and must be reauthorised via iTunes.&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;The WiFi tab allows the administrator to define WiFi access points to be used by the device:&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/iphone/iphone004.jpg" style="width:1088px;height:855px;" height="855" width="1088"&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;The VPN tab contains information on Virtual Private Network connection settings:&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/iphone/iphone005.jpg" style="width:1088px;height:855px;" height="855" width="1088"&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;The Email Settings tab contains information on POP and IMAP-based email account settings:&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/iphone/iphone006.jpg" style="width:1088px;height:880px;" height="880" width="1088"&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;The Exchange tab is where the settings relating to Server ActiveSync are entered:&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/iphone/iphone007.jpg" style="width:1088px;height:880px;" height="880" width="1088"&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;You will notice the lack of a field to enter Domain information. This should be included in the Username field in the from&amp;nbsp;"domain\username".&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;The Credentials tab is used to publish certificates to the device. CER, DER, CRT, P12 and PFX certificates types are supported.&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;The Advanced tab allows the administrator to define cellular access point settings:&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/iphone/iphone008.jpg" style="width:1088px;height:880px;" height="880" width="1088"&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;Once the profile has been configured within the Utility, it can be Exported, which will create a ".mobileconfig" file (which can then be uploaded to a web site), or emailed as an attachment. &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&lt;b&gt;Configuring the device manually&lt;/b&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;Alternatively, the Exchange Server settings can be entered into the device manually. To add an Exchange account, go to Settings &amp;gt; Mail, Contacts, Calendars and then tap Add Account. On the Add Account screen, select Microsoft&amp;nbsp;Exchange:&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/iphone/iphone009.jpg" style="width:186px;height:277px;" height="277" width="186"&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;Enter the relevant details. Again, there is no field to enter domain information as on other ActiveSync devices, so this information should be entered in the username field in the from "domain\username":&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/iphone/iphone010.jpg" style="width:185px;height:274px;" height="274" width="185"&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;When all of the fields have been completed, during the first synchronisation with the server, the password policy on the server will be checked, and if the device does not conform to it, the user will be prompted to enter a password.&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;By default all mail, contact and calendar information will then be synced with the device.&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;You can select which information you wish to synchronise under Settings &amp;gt; Mail, Contacts and Calendars.&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;NOTE - setting up a Server ActiveSync account on the device will cause all existing information on the device to be overwritten and it will no longer be possible to synchronise mail, contact and calendar information&amp;nbsp;with a desktop PC via iTunes (music, video and photo transfer will not be affected).&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;o:p&gt;It IS possible to add additional POP and IMAP email accounts to the device, but only one Exchange mail account.&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;img src="http://blog.devicewire.com/aggbug.aspx?PostID=867" width="1" height="1"&gt;</description></item><item><title>Nokia Intellisync Mobile Suite 9.1 Device Management for Linux</title><link>http://blog.devicewire.com/blogs/devicewire/archive/2008/07/13/nokia-intellisync-mobile-suite-9-1-device-management-for-linux.aspx</link><pubDate>Sun, 13 Jul 2008 07:59:00 GMT</pubDate><guid isPermaLink="false">df238d37-d6e2-4966-96cd-299e643337d6:866</guid><dc:creator>jamesl</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;The history of Nokia's Intellisync Mobile Suite product is a long and complicated one. Even to do this day if I say 'Intellisync' to someone, they are often reminded of the PDA synchronisation software developed by PumaTech, which was an ActiveSync-like application for EPOC devices. Do not be confused.&lt;br&gt;&amp;nbsp;&lt;br&gt;The Intellisync Mobile Suite was formerly developed by a company named Intellisync, before they were purchased by Nokia a few years ago. Prior to being developed by Intellisync, the product was developed (and named) by a company called Synchrologic, before being bought by Intellisync. It was this company that also developed the Pumatech software, but it was in no way related to their remote email / device management solution.&lt;br&gt;&amp;nbsp;&lt;br&gt;Intellisync has long been the leader of the remote email and device management pack. It is a little known fact that whilst RIM manufacture Blackberry handsets, they actually paid Intellisync to develop the BES software for them - I don't know what the situation is now that Intellisync is owned by Nokia, but the more eagle-eyed of you administrators may have noticed a RIM tab within the properties of the Intellisync Server Administration Console: this is because the server can indeed be used with RIM Blackberry devices, unfortunately you need a special license key to unlock this functionality which the odds of you getting are slim (I've never managed to get one anyway).&lt;br&gt;&amp;nbsp;&lt;br&gt;The release of updates to the product, as this blog will attest, is frequent. However, while most of my posts refer to the updates that have been released and the new functionality included, I thought with this release it may be an idea to recap, and list all of the functionality.....as it's pretty impressive!&lt;br&gt;&amp;nbsp;&lt;br&gt;Before I can do that, a little more history is required.&lt;br&gt;&amp;nbsp;&lt;br&gt;The Intellisync Mobile Suite product is so called because it actually comprises 4 products:&lt;br&gt;&amp;nbsp;&lt;br&gt;&amp;nbsp;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wireless Email&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File Sync&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Data Sync&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Systems Management&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;br&gt;&amp;nbsp;&lt;br&gt;Each product is modular, meaning that each module can be used independently of the others. The Wireless Email component enables remote wireless full PIM synchronisation with Microsoft Exchange, Lotus Domino or Novell Groupwise from a Windows, Windows Mobile, Palm, Symbian, Java or BREW-based device. The File Sync component enables the synchronisation of files (documents and applications) with client devices. The Data Sync component enables remote synchronisation with SQL, Oracle or other database back-end infrastructure. The Systems Management component enables full remote device management, including inventory collection, remote device wipe, password enforcement, hardware control, etc.&lt;br&gt;&amp;nbsp;&lt;br&gt;Until being purchased by Nokia, Intellisync Mobile Suite could only be installed on a Windows Server-based platform. The installer would install all components, but which of those components you has access to was determined by your installation license key.&lt;br&gt;&amp;nbsp;&lt;br&gt;Nokia's numbering scheme for this product has, to my mind, become a little confused this year. This is not helped by the fact that the product has effectively been split into Windows and Linux-based versions.&lt;br&gt;&amp;nbsp;&lt;br&gt;There is a reason for this: Nokia had their own device management product, which was Linux-based, called Nokia Device Manager. This was developed for the Nokia Comunicator range of devices and offered a limited range of features, but which was OMADM compliant (had the ability to provision device settings via the SS7 GSM control channel via control SMS messages). There was a lot of good stuff in this product that Nokia wanted to keep, but saw a very good product in Intellisync also, so they bought Intellisync, and ported the Systems Management component of the product (which was Windows based) to Linux. They then set about combining the functionality of the Nokia product and the Intellisync product into one single offering. However whilst doing this, they have also continued developing the rest of the 3 components, which are still Windows-based.&lt;br&gt;&amp;nbsp;&lt;br&gt;With me so far?&lt;br&gt;&amp;nbsp;&lt;br&gt;So currently we have Intellisync 9.0, which is Windows-based and offers the full range of functionality, and also Intellisync 9.1 which is Linux-based, and only offers the device management functionality.&lt;br&gt;It is important to note that the 9.1 Linux release is “multi-tenant” capable, so clearly designed to manage the devices of multiple user groups (those groups not necessarily being within the same company).&lt;br&gt;Despite the new 9.x version numbers, both 9.0 for Windows and 9.1 or Linux are listed by Nokia as being maintenance releases for the 8.x of the releases for both Windows and Linux.&lt;br&gt;&amp;nbsp;&lt;br&gt;Confused! .com&lt;br&gt;&amp;nbsp;&lt;br&gt;In this post I will list all of the features available in both versions currently. Please note that this list is by no means exhaustive – I merely thought it would be wise to include the most impressive features of the solution, which are numerous. In a future post I will seek to align these capabilities with the competition in a matrix-style chart.&lt;br&gt;&amp;nbsp;&lt;br&gt;Client devices&lt;br&gt;&amp;nbsp;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Mobile&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Symbian&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Palm&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Java&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; BREW&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;br&gt;Wireless Email&lt;br&gt;&amp;nbsp;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Support for Microsoft Exchange, Lotus Domino, Novell Groupwise, LDAP / POP / IMAP Servers&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; True IP push of mailbox data&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SMS “wake-up” support for offline clients&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Global Address List sync support&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Synchronisation support for Inbox, Outbox, Sent Items, Drafts, Tasks, Notes, Contacts and Calendar folders&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Support for configuration of attachment size limits, and allowed attachment file types&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Support for filtering of pushed data based on sender, recipient, urgency status&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Web-based access to PIM data&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;br&gt;File Sync&lt;br&gt;&amp;nbsp;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inventory collection capability of client devices – hardware and software assets&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Push or synchronisation of applications, documents, patches, or indeed any digital file to client device&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Support for VBScript-based intelligence, allowing for if, and, or level script execution&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Device-level or file-level device backup&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Intranet or other web site client packaging capability for offline on-device viewing&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;br&gt;Systems Management&lt;br&gt;&amp;nbsp;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OTA client installation support (support for SMS trigger)&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Remote device wipe – capability to specify full hard reset, PIM data deletion or specific file deletion, based on entry of correct password or administrative command&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Password enforcement policy – ability to force users to use passwords on their device&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Remote Control of devices via web browser&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Remote uninstallation of undesired applications&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Remote disabling of client hardware elements – Bluetooth, WiFi, IR, SD memory, USB Modem, SMS functionality&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Phone number “whitelisting”&lt;br&gt;&lt;br&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OMA DM support for Nokia VoIP, VPN, Security device settings&lt;br&gt;&lt;br&gt;&amp;nbsp;&lt;br&gt;Data Sync&lt;br&gt;&amp;nbsp;&lt;br&gt;This aspect of the solution’s capability is beyond the scope of this article&lt;br&gt;&amp;nbsp;&lt;br&gt;&amp;nbsp;&lt;br&gt;Profiles&lt;br&gt;&amp;nbsp;&lt;br&gt;All of the above settings can be defined on a per-user or a per-group basis by the administrator.&lt;br&gt;&amp;nbsp;&lt;br&gt;&amp;nbsp;&lt;br&gt;For more detailed information, read the following articles in the Forum:&lt;br&gt;&amp;nbsp;&lt;br&gt;Intellisync Administrator Guide (Windows)&lt;br&gt;&amp;nbsp;&lt;br&gt;http://forum.devicewire.com/forums/thread/545.aspx&lt;br&gt;&amp;nbsp;&lt;br&gt;Intellisync Administrator Guide (Linux)&lt;br&gt;&amp;nbsp;&lt;br&gt;http://forum.devicewire.com/forums/thread/669.aspx&lt;br&gt;&amp;nbsp;&lt;br&gt;&amp;nbsp;&lt;br&gt;The key improvements that have been included in the 9.1 release of the Linux version of the device management application, which I have not listed above, are for the Windows Mobile platform.&lt;/p&gt;&lt;p&gt;Ability to configure Server ActiveSync settings on Windows Mobile-based PDAs:&lt;/p&gt;&lt;p&gt;Within the list of device management Publications available for Pocket PC and Smartphone devices (Asset Collection, Backup, Software Install) is a new option for Device Configuration, with sub-options for Server ActiveSync and Generic.&lt;/p&gt;&lt;p&gt;Selecting Server ActiveSync enables the administrator to enter details of Exchange Server address, domain, username, password, Email, Contact, Calendar and Task settings:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/nims_9_1_linux/nims_9_027.jpg" height="831" width="1148"&gt;Once published on the server and the relevant users or groups or subscribed, synchronising with the server from the client device will configure a server activesync connection automatically. &lt;br&gt;&lt;/p&gt;&lt;p&gt;The 'Generic' option is even more powerful: this allows the administrator to send raw XML code to the client device, and have it 'parsed' by the Intellisync client:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/nims_9_1_linux/nims_9_028.jpg" height="831" width="1148"&gt;This means that it is possible to remotely add registry entries to the Windows Mobile device, and as some of you will be aware, EVERYTHING is configured on Windows Mobile devices via the registry: GPRS/3G connection settings, WiFi access points, etc etc.&lt;/p&gt;&lt;p&gt;For example, the following XML code:&lt;/p&gt;&lt;p&gt;&amp;lt;wap-provisioningdoc&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;nocharacteristic type="CM_Networks" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;nocharacteristic type="CM_GPRSEntries" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;nocharacteristic type="CM_ProxyEntries" /&amp;gt; &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="CM_Networks"&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="Contract MMS"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{F750E26F-81D9-4379-8567-318C129CA736}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="Contract Internet"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{FF445A54-ADF8-4fab-86B7-E31482BEE8BE}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&amp;lt;characteristic type="Contract WAP"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;parm name="DestId" value="{B8D6BA64-F7BB-47be-BC57-4D882CA709C2}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&amp;lt;characteristic type="My Work Network"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{18AD9FBD-F716-ACB6-FD8A-1965DB95B814}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="Work"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{A1182988-0D73-439E-87AD-2A5B369F808B}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="Secure WAP Network"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{F28D1F74-72BE-4394-A4A7-4E296219390C}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="The WAP Network"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{7022E968-5A97-4051-BC1C-C578E2FBA5D9}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="The Internet"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{436EF144-B4FB-4863-A041-8F905A62C572}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp; &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="CM_GPRSEntries"&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="MMS"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{F750E26F-81D9-4379-8567-318C129CA736}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Enabled" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="UserName" value="wap" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Password" value="wap" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Domain" value="" /&amp;gt; &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="DevSpecificCellular"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="BearerInfoValid" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoValid" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoProtocolType" value="2" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoL2ProtocolType" value="PPP" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoAccessPointName" value="wap.vodafone.co.uk" /&amp;gt;&amp;nbsp; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoDataCompression" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoHeaderCompression" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp; &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="Contract Internet"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{FF445A54-ADF8-4fab-86B7-E31482BEE8BE}" /&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;parm name="AlwaysOn" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;parm name="Enabled" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="UserName" value="web" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Password" value="web" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Domain" value="" /&amp;gt; &lt;br&gt;&amp;nbsp; &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="DevSpecificCellular"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="BearerInfoValid" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoValid" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoProtocolType" value="2" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoL2ProtocolType" value="PPP" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoAccessPointName" value="internet" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoDataCompression" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoHeaderCompression" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&amp;lt;characteristic type="Contract WAP"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{B8D6BA64-F7BB-47be-BC57-4D882CA709C2}" /&amp;gt; &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;parm name="Enabled" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="UserName" value="wap" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Password" value="wap" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Domain" value="" /&amp;gt;&lt;br&gt;&amp;nbsp; &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="DevSpecificCellular"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="BearerInfoValid" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoValid" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoProtocolType" value="2" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoL2ProtocolType" value="PPP" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoAccessPointName" value="wap.vodafone.co.uk" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoDataCompression" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GPRSInfoHeaderCompression" value="1" /&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="CM_ProxyEntries"&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="NULL-HTTP-{FF445A54-ADF8-4fab-86B7-E31482BEE8BE}"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="SrcId" value="{FF445A54-ADF8-4fab-86B7-E31482BEE8BE}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{436EF144-B4FB-4863-A041-8F905A62C572}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Proxy" value="" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Type" value="0" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Enable" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="null-corp-{FF445A54-ADF8-4fab-86B7-E31482BEE8BE}"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="SrcId" value="{FF445A54-ADF8-4fab-86B7-E31482BEE8BE}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{A1182988-0D73-439E-87AD-2A5B369F808B}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Type" value="0" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Enable" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="WAP-{B8D6BA64-F7BB-47be-BC57-4D882CA709C2}"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="SrcId" value="{B8D6BA64-F7BB-47be-BC57-4D882CA709C2}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{7022E968-5A97-4051-BC1C-C578E2FBA5D9}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Proxy" value="212.183.137.012:8799" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Enable" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Type" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp; &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="WAP-secure-{B8D6BA64-F7BB-47be-BC57-4D882CA709C2}"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="SrcId" value="{B8D6BA64-F7BB-47be-BC57-4D882CA709C2}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="DestId" value="{F28D1F74-72BE-4394-A4A7-4E296219390C}" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Proxy" value="212.183.137.012:8799" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Enable" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Type" value="1" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="CM_Planner"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;nocharacteristic type="PreferredConnections" /&amp;gt; &lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="PreferredConnections"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="{436EF144-B4FB-4863-A041-8F905A62C572}" value="Contract Internet" /&amp;gt;&amp;lt;parm name="{7022E968-5A97-4051-BC1C-C578E2FBA5D9}" value="Contract WAP" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="{F28D1F74-72BE-4394-A4A7-4E296219390C}" value="Contract WAP" /&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="Registry"&amp;gt;&lt;br&gt;&amp;nbsp;&amp;lt;characteristic type="HKLM\SOFTWARE\ArcSoft\ArcSoft MMS UA\Config\UI"&amp;gt;&lt;br&gt;&amp;nbsp;&amp;lt;parm name="ConnectviaMatchById" value="1" datatype="integer" /&amp;gt;&lt;br&gt;&amp;nbsp;&amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="HKLM\Software\ArcSoft\ArcSoft MMS UA\Config\mm1\MMSCSetting\SampleMMSC"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="WAP1DefaultSize" value="102400" datatype="integer" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="WAP2DefaultSize" value="307200" datatype="integer" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="ConnectionVia" value="{F750E26F-81D9-4379-8567-318C129CA736}" datatype="string" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Name" value="Contract MMS" datatype="string" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="Gateway" value="212.183.137.012" datatype="string" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="MmscURI" value="http://mms.vodafone.co.uk/servlets/mms" datatype="string" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="GatewayPort" value="8799" datatype="integer" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="SendDefault" value="307200" datatype="integer" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="RecvDefault" value="512000" datatype="integer" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="WAPType" value="1" datatype="integer" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="HKLM\Software\ArcSoft\ArcSoft MMS UA\Config\mm1"&amp;gt;&lt;br&gt;&amp;nbsp;&amp;lt;parm name="DefaultSetting" datatype="string" value="SampleMMSC" /&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="TotalSettings" value="1" datatype="integer" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="HKLM\Software\ArcSoft\ArcSoft MMS UA\Config\UI\SizeLimit"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="SendCount" value="3" datatype="integer" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="SendLimit1" value="30720" datatype="integer" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="SendLimit2" value="102400" datatype="integer" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;parm name="SendLimit3" value="307200" datatype="integer" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="HKCU\Software\Windows\CurrentVersion\5.0\Internet Settings"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="EnableAutoDetect" value="1" datatype="integer" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;characteristic type="HKLM\Software\Microsoft\Internet Explorer\AboutURLs"&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;parm name="home" value="http://live.vodafone.com" datatype="string" /&amp;gt; &lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;/characteristic&amp;gt;&lt;br&gt;&amp;nbsp; &amp;lt;/wap-provisioningdoc&amp;gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Sets up a device for Vodafone UK MMS service.&lt;/p&gt;&lt;p&gt;Once you know the correct registry keys to configure, virtually any aspect of a device's configuration can be set via XML. A full explanation of this process is available in the Microsoft product documentation for Windows Mobile, available here:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;ftp://ca:welcome@ftp.hughsymons.com/Hugh%20Symons%20Telecom%20-%20Reseller%20Area/Microsoft/Windows%20Mobile/Crossbow_Documentation_Oct2006.chm &lt;br&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;This then, renders the device management solution very powerful indeed. It is always a mystery to me that considering Microsoft develop the client operating system, they are not able to offer this sort of functionality themselves, but both Exchange 2007 and System Center Mobile Device Manager 2008 are nowhere near being able to offer this level of capability.&lt;/p&gt;&lt;p&gt;In my last blog post on this subject I included the release notes for the version 9.1, which included a section on Wireless Email. I noted that I was curious to see how Nokia had managed to include this functionality in the Linux-based version of the software. It transpires that the wireless email funcitonality that has been included is only for use with an IMAP or Novell Groupwise server:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/nims_9_1_linux/nims_9_003.jpg" height="932" width="1105"&gt;Inside sources tell me that a fully functional release of Intellisync, including all of the functionality in both the Windows and Linux versions (including full Exchange wireless email support as well as the OMADM capability for Symbian handsets) will be available in version 10 of the software, which will be Windows-based only.&lt;/p&gt;&lt;p&gt;But you didn't hear that from me! &lt;br&gt;&lt;/p&gt;&lt;img src="http://blog.devicewire.com/aggbug.aspx?PostID=866" width="1" height="1"&gt;</description></item><item><title>How do Virtual Private Networks (VPNs) work?</title><link>http://blog.devicewire.com/blogs/devicewire/archive/2008/07/06/how-do-virtual-private-networks-vpns-work.aspx</link><pubDate>Sun, 06 Jul 2008 09:20:00 GMT</pubDate><guid isPermaLink="false">df238d37-d6e2-4966-96cd-299e643337d6:861</guid><dc:creator>jamesl</dc:creator><slash:comments>0</slash:comments><description>






&lt;div class="Section1"&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;VPN, or Virtual Private Network, technology is used to extend
private networks beyond the boundaries of their physical cabling – to securely
connect geographically separated networks using an unsecure medium, such as the
Internet. Today VPN technology is being increasingly used to allow workers to
connect to local network resources while away from the office. As I examined in
my post on virtualisation (&lt;a href="http://blog.devicewire.com/blogs/devicewire/archive/2008/06/12/virtualisation-what-s-it-all-about.aspx"&gt;http://blog.devicewire.com/blogs/devicewire/archive/2008/06/12/virtualisation-what-s-it-all-about.aspx&lt;/a&gt;),
the “stuff” that happens in the background to make this possible is transparent
to the user: the user enjoys the same experience whether they are in the office
or not.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Whilst this technology is not new, problems often arise when trying
to establish VPN connections from mobile devices, because of a lack of
understanding of what happens in the middle, between the user and the office.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;In this article I will look more closely at this technical “stuff” –
the different means by which data can be intercepted, the mechanisms by which
data is secured, and common problems experienced, especially when establishing
VPN connections from mobile devices, and their solutions.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;This subject is inherently technical in nature and ideally you
should have an understanding of the basic principles of TCP/IP. If you need a
quick refresher course, have a read of my earlier blog post, “How does TCP/IP
work?”, here:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;a href="http://blog.devicewire.com/blogs/devicewire/archive/2008/06/21/tcp-ip-an-introduction.aspx"&gt;http://blog.devicewire.com/blogs/devicewire/archive/2008/06/21/tcp-ip-an-introduction.aspx&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Virtual Private Network technology makes it possible to securely
send data over an unsecured network. Data is encrypted at the source and sent
over the unsecure network, such as the Internet, and decrypted again at the
receiving end. Should any of the data be intercepted while in transit, it will
not be readable by any unintended recipient. This method of securely sending
data over an unsecure network is known as &lt;b&gt;&lt;i&gt;tunnelling&lt;/i&gt;&lt;/b&gt;.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Before I look at the components involved in a VPN connection and how
security is guaranteed, I will first look at the areas of concern a network
administrator faces when assessing the security of their network.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;The need for security&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Without security measures and controls in place, data may be subject
to “attack”. Some attacks can be “passive” (meaning that data is merely
monitored), others can be “active” (meaning that the data is deliberately
altered with intent to corrupt the data itself, or even attack the entire
target network). Attacks can take one of a number of forms:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;span&gt;Eavesdropping&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span&gt; – the majority of network communications occur in an unsecured
manner, or in “cleartext”. Should an attacker gain access to the network, they
would be able to read any traffic crossing that network. This practice is
referred to as “sniffing” or “snooping”. This is the most common form of attack
and is the reason why encryption technology is being deployed even on small,
local networks.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;span&gt;Data Modification&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span&gt; – once an attacker has gained access to a network, that person
would then be able not only to read data, but modify it in transit between
sender and receiver (increasing the quantity specified in an electronic
purchase, for example). This is also referred as a ‘man-in-the-middle attack’.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;span&gt;Identity / IP Address Spoofing&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span&gt; – on an IP-based network, a computer is identified by its IP
address, and the resources that computer is permitted access to is based on its
IP address. Should an attacker be able to make their computer appear to have a
‘trusted’ IP address, it would be able to access any resources that a computer
genuinely possessing that address would be able to.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;span&gt;Password-based attacks&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span&gt; – the password is the simplest form of authentication. Most systems
do not encrypt passwords as they are sent across the local network. Should an
eavesdropper gain access to a network they would be able to intercept password
information, and from that moment gain access to network resources as a trusted
user.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;span&gt;Denial-of-service attack&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span&gt; – a DoS attack involves flooding the network with so much traffic
that it eventually crashes. The target of a DoS attack could equally be a
network, a single machine on that network, or even a specific service running
on that single machine.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;Defence mechanisms&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;A VPN connection implements security in two ways – &lt;b&gt;&lt;i&gt;authentication&lt;/i&gt;&lt;/b&gt;
and &lt;b&gt;&lt;i&gt;encryption&lt;/i&gt;&lt;/b&gt;.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Authentication ensures that the data originates from the source
which it claims to come from.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Encryption prevents anyone from reading or copying data as it
travels across the network. Data encryption is used to protect data from
unauthorised users by encoding the content. For more information on how data is
encrypted, read my earlier blog post, “How do digital certificates work?” –
here:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;a href="http://blog.devicewire.com/blogs/devicewire/archive/2008/06/22/how-do-digital-certificates-work.aspx"&gt;http://blog.devicewire.com/blogs/devicewire/archive/2008/06/22/how-do-digital-certificates-work.aspx&lt;/a&gt;
&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;VPN Infrastructure&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;There are 2 principle elements involved in a VPN connection. The
remote network deploys a VPN Server which acts as a gateway between the
internal network and the public Internet.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;The remote user, or branch office, will have a VPN client which will
encrypt data sent to and decrypt data received from the VPN server. The client
may be a physical piece of hardware or a software application.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Typically the VPN server will be located behind a firewall in a
perimeter network. The ports that will need to be opened on the firewall will
vary depending on the VPN “tunnelling” protocol being used. The three most
common VPN protocols are:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraphCxSpFirst" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span&gt;PPTP&lt;/span&gt;&lt;/b&gt;&lt;span&gt; (Point to
Point Tunnelling Protocol)&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraphCxSpMiddle" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span&gt;L2TP&lt;/span&gt;&lt;/b&gt;&lt;span&gt; (Layer 2
Tunnelling Protocol)&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraphCxSpLast" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span&gt;IPSec &lt;/span&gt;&lt;/b&gt;&lt;span&gt;(Internet
Protocol Security)&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;I will examine these protocols in more detail, but essentially they
work in the same way. TCP will split the data to be transmitted into individual
&lt;i&gt;packets&lt;/i&gt;, consisting of a data &lt;i&gt;payload &lt;/i&gt;and &lt;i&gt;header&lt;/i&gt;
information, containing sequencing and error correction details. IP will then
add further information to the TCP packet containing addressing information of
both the sending and receiving machines.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;The VPN protocol will take the TCP packet and add further
information to it. The entire packet is encrypted, making it unreadable to any
machine that does not have the decryption key. Further sequencing and error
correction data is added, and then the IP header is attached so that the VPN
packet can be routed across the network. Due to the large amount of additional
data that is added to the packet, VPN connections are correspondingly slower
than plaintext communications.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;PPTP is the earliest of the three VPN protocols. It provides data
security by encrypting the contents of the packet, but it does not provide data
authentication by verifying the identity of the sender, nor does it verify the
integrity of the data to ensure that it has not been modified in transit, either
accidentally or deliberately.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;L2TP addresses these weaknesses firstly by adding a &lt;i&gt;message
digest&lt;/i&gt; to each packet to ensure that the data has not been modified in
transit. It also guarantees the identity of the sender by digitally signing
each packet with a certificate.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;IPSec is the most commonly-used VPN protocol today and I will
examine this in more detail. IPSec works in a similar manner to L2TP in terms
of providing authentication and verification, but the strength of the
encryption mechanism used is stronger – asymmetric (or public key) encryption
being used.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Again, if you need a refresher on what terms like message digest and
public key encryption mean, then a good place to start would be here:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;a href="http://blog.devicewire.com/blogs/devicewire/archive/2008/06/22/how-do-digital-certificates-work.aspx"&gt;http://blog.devicewire.com/blogs/devicewire/archive/2008/06/22/how-do-digital-certificates-work.aspx&lt;/a&gt;
&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;IPSec&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Internet Protocol Security (IPSec), is an end-to-end protocol,
meaning that only the sending and receiving systems need to be able to support
it – the encrypted data can pass through routers and other machines on the
interlying networks without them needing to also support it.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Using IPSec, data is encrypted at the Transport Layer, which means
that data is encrypted before it gets to the Network Layer. Any machines
through which the encrypted packets will travel will examine the address
information on the packet, see that it is not intended for that network and
pass it on, the packet only being decrypted again when it reaches the Transport
Layer on the target machine. This is what is meant by end-to-end.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;As with TCP, IPSec itself is actually a number of protocols. The
protocol that handles the encryption of the TCP data packets is called the &lt;b&gt;Encapsulating
Security Payload (ESP)&lt;/b&gt; Protocol.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Individual packets are encrypted using a different encryption key,
and each encrypted packet is appended with a message digest, or checksum, so
that should any of the data be altered en route, the digest will no longer
match the contents of the payload (a message digest works by essentially taking
the value of all of the 1s in the payload and applying a mathematical function
to it, then saving that resulting value. Should the data change, the value of
the 1s will change and the resulting value of the mathematical function will
also change).&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Individual encryption keys are used so that should an attacker
manage to intercept a large amount of traffic all encrypted using the same key,
they will not be able to calculate the key from that traffic, and potentially
encrypt their own data using that key. This is known as &lt;i&gt;anti-replay&lt;/i&gt;.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;The checksum value is stored in the &lt;b&gt;Authentication Header&lt;/b&gt;.
This is an additional header which is added to the normal TCP packet before IP
adds its own address headers. The Authentication header does not need to be
used with ESP, it can be used by itself. The Authentication Header does not
encrypt the data, but it does secure it against modification.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Other values are also stored in the Authentication Header:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;i&gt;&lt;span&gt;Next Header&lt;/span&gt;&lt;/i&gt;&lt;span&gt; –
this field indicates the transport protocol used (TCP, UDP, etc) so that the
encrypted packet is submitted to the correct transport protocol on the
receiving machine.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;i&gt;&lt;span&gt;Length&lt;/span&gt;&lt;/i&gt;&lt;span&gt; –
indicates the length in bytes of the Authentication Header.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;i&gt;&lt;span&gt;Security Parameters Index (SPI)&lt;/span&gt;&lt;/i&gt;&lt;span&gt; – indicates whether ESP is being used or not.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;i&gt;&lt;span&gt;Sequence Number&lt;/span&gt;&lt;/i&gt;&lt;span&gt; –
indicates the packets position within the data stream and also contains another
message digest to guarantee the uniqueness of that packet.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;i&gt;&lt;span&gt;Authentication Data&lt;/span&gt;&lt;/i&gt;&lt;span&gt; – this is where the message digest for data payload is stored.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;Security Association&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;When two computers using IPSec “handshake” (agree the parameters to
be used for the connection), before any data is sent or received they must
first establish a Security Association (SA). This “agreement” defines the
encryption key to be used as well as the security protocol (ESP, AH, or both,
for example) and a security identifier (in case each or even both of the
machines are already involved in other IPSec-based communications with other
machines).&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Once agreed, the SA will have a specific lifetime, after which time
the process will be repeated to agree a new association using a new encryption
key (an anti-replay technique).&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Once connected, the VPN client is effectively connected to the
remote network. As such it is assigned an IP address on that remote network, a
non-routable IP address which the VPN software sends over the Internet
connection for reception by the VPN server.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;This being the case, the VPN server will need to be able to assign
remote devices local IP addresses – ideally automatically via DHCP from a pool
of reserved addresses.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;Tunnelling&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;ESP can be used in two modes: &lt;b&gt;transport mode&lt;/b&gt; and &lt;b&gt;tunnelling
mode&lt;/b&gt;.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;In transport mode, only the data payload is encrypted. In tunnelling
mode, the data and also the IP Header is encrypted. When used in a VPN
solution, ESP operates in tunnelling mode. &lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;In tunnelling mode, the entire TCPIP packet is encrypted (not just
the TCP packet), digitally signed, and then a new IP header created, which is
unencrypted, so that the VPN packet can still be routed across the Internet.
When the packet arrives at the destination network, the receiving server
removes the IP header and the ESP header (decrypting it in the process), and
uses the original IP header information to route the packet across the local
network. It is this process that can sometimes cause problems when connecting
from certain devices, especially mobile devices, which I will now endeavour to
explain.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;Network Address Translation (NAT)&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Network Address Translation is a technology employed to address the
issue of a shortage of available “routable” IP addresses. Because there are not
sufficient routable IP addresses available for each machine connected to the
Internet to have one, local networks employ a non-routable addressing scheme
and have one machine, a gateway, with a network interface connected to the
Internet with a single routable IP addresses allocated to it. Using this single
address, many many machines can sit “behind” this gateway and enjoy Internet
access, without being directly connected to it. This process is known as
Network Address Translation. A typical example of this process may work as
follows:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span&gt;1.&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span&gt;A machine on the internal network requests a web
page from a web server on the Internet. The machine creates an HTTP request and
submits it to the network, which sends it to the NAT gateway router.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span&gt;2.&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span&gt;The router receives the request and sees that it
is destined for a machine not on the local network. The router saves the
machine’s non-routable IP address to an address translation table. It then
re-writes the IP header, replacing the source IP address with its own public IP
address and sends the request out across the Internet.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraph" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span&gt;3.&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span&gt;When the response comes back from the web
server, the router checks the address translation table, rewrites the IP header
of the incoming data, changing the destination address from its own to the
address of the machine on the internal network, and forwards it on.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span&gt;IPSec and NAT compatibility&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;If a TCPIP packet crosses a NAT gateway, it will have its source IP
address information changed. Because IPSec performs a data authentication check
on all incoming packets to ensure that they have not been altered in any way
while in transit, the changing of the source IP address by the NAT gateway will
cause the message digest to no longer match the data, and IPSec will “fail” the
packet and the connection will not be established.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;When connecting to the Internet from a mobile device, the mobile
network operator will employ a NAT gateway between the mobile network and the
Internet. For this reason, VPN connections from mobile devices will quite often
fail.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;Help is at hand&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;One solution to this problem is known as &lt;b&gt;NAT Traversal (NAT-T)&lt;/b&gt;.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;This technique addresses this problem by using &lt;b&gt;UDP&lt;/b&gt; as the
transport protocol, rather than TCP.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;UDP is the &lt;b&gt;User Datagram Protocol&lt;/b&gt;. It is a transport protocol
similar to TCP, but it does not employ error correction, it is used for
“unimportant” communications where data loss is not necessarily an issue.
Because UDP does not send acknowledgement messages back to the sending machine,
it does not include a sending IP address in the header, only a target IP
address. For this reason it is sometimes referred to as a “fire and forget”
protocol.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Using UDP to transport the encrypted the IPSec packet therefore does
not involve rewriting any of the packet’s data as it passes through the NAT
gateway. Instead, at the NAT gateway, a normal TCPIP header will be added for
routing across the Internet. At the receiving machine, the TCPIP header will be
removed at the network layer, and the unaltered UDP packet delivered to the
transport layer and the waiting IPSec protocol.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;This technique does require that both the VPN client software and
the VPN server both support NAT-T (also referred to as UDP Encapsulation), and
do agree on this protocol during the negotiation of the security association.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Fortunately, most mobile network operators are aware of this problem
and have implemented their own solutions. The public “Internet” access point
(APN) which most users will connect to for Internet access, will use NAT to
allow the large number of mobile users to connect to the Internet whilst only
requiring the operator to provide a small number of public IP addresses.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;For users who wish to establish a VPN connection, there are
alternative APNs available. Most operators will be able to offer two additional
APNs intended for VPN use: which one is relevant for you will depend on the
requirements of your VPN infrastructure.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Taking Vodafone as an example, the public APN is simply “internet”.
This will employ NAT to provide users with access to the Internet. “MyLAN” is a
separate access point intended for corporate VPN users. This APN will use NAT-T
to get around the issue of NAT and IPSec compatibility.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;On the Orange network, “orangeinternet” is the public Internet APN,
whereas “internetvpn” is intended for corporate VPN users.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;There is typically no cost to use these alternate APNs, but your SIM
card must be enabled for these services first by calling customer services and
requesting it.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;However, there is another potential issue which can cause a VPN
connection to fail. Typically, the “non-routable” IP addressing scheme used by
mobile network operators will allocate addresses to users in the range 10.x.x.x&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;This is fine if the local network in the office uses an addressing
scheme of, say, 172.16.x.x&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;This means that when connected to Vodafone 3G service, the mobile
device has an IP address of, say 10.0.0.1, and when connected to the VPN, the
“virtual network adapter” has an IP address of 172.16.199.1&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;The computer “knows” that any traffic destined for the 172.16.x.x
network needs to be sent to the VPN software which will encrypt it and route it
over the Internet connection (with a UDP header of 10.x.x.x being added to the
VPN packet).&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;However, if the network in the office also uses the 10.x.x.x address
range, the VPN software will be assigned a virtual address in this same range,
and the PC will then no longer be able to tell what traffic is intended for the
VPN and what is normal Internet traffic. In this situation it will most likely
try to route encrypted packets to the wrong destination and the connection will
fail.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;This being the case, most network operators therefore provide 2 VPN
APNs. These work in the same way, but simply use different addressing schemes
to address this issue. Which one you need depends on your addressing scheme at
work.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;So, if the Vodafone MyLAN APN uses addresses in the range 10.x.x.x,
MyLAN2 will use 172.16.x.x&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Similarly on the Orange network, internetvpn will use 10.x.x.x and
internetvpn2 will use 172.16.x.x&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;The third way&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Should your VPN infrastructure not support NAT-T, then the only
solution is to consistently connect from the same, &lt;i&gt;routable&lt;/i&gt; IP address,
ie have a public IP address associated with your mobile device (or more
correctly, the SIM card in the mobile device).&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;There are providers that can offer this service, although the
service is chargeable. One such company is Wireless Logic (&lt;a href="http://www.wirelesslogic.co.uk/"&gt;www.wirelesslogic.co.uk&lt;/a&gt;). &lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;Configuring the VPN Client&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;All versions of Windows since Windows 98 have had a VPN client
included as part of the operating system. These VPN clients are only designed
to connect to the Routing and Remote Access service on a Windows Server 2000 or
2003-based endpoint. Windows Mobile devices also have VPN capability, but these
are also only intended for use with a Windows Server at the other end. If a VPN
solution by any other company other than Microsoft has been deployed, such as
Cisco or Checkpoint, then the corresponding client software developed by that
company should be used on the remote device.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Most VPN client software will require 3 pieces of information when
configuring the connection:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="ListParagraphCxSpFirst" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span&gt;VPN Server Address&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="ListParagraphCxSpMiddle" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span&gt;Username&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="ListParagraphCxSpLast" style="margin-bottom:0.0001pt;text-indent:-18pt;"&gt;&lt;span style="font-family:Symbol;"&gt;·&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span&gt;Password&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;i&gt;&lt;span&gt;MacOS X Leopard:&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;



&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/vpn/vpn_1.jpg" height="392" width="580"&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;i&gt;&lt;span&gt;Windows XP:&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/vpn/vpn_3.jpg" height="394" width="504"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/vpn/vpn_4.jpg" height="392" width="503"&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/vpn/vpn_5.jpg" height="393" width="504"&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/vpn/vpn_6.jpg" height="394" width="505"&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/vpn/vpn_7.jpg" height="393" width="503"&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/vpn/vpn_8.jpg" height="392" width="503"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;i&gt;&lt;span&gt;Windows Mobile:&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/vpn/vpn_9.jpg" height="320" width="239"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/vpn/vpn_10.jpg" height="319" width="242"&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/vpn/vpn_11.jpg" height="319" width="239"&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/vpn/vpn_12.jpg" height="319" width="240"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;All VPNs clients will install a virtual network adapter as part of
the installation process.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;Troubleshooting&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;When troubleshooting VPN connections it is important not to forget
the basics. At a simple level, should the VPN client report that it is not able
to contact the remote server, or something along those lines, verify that the
device does have a connection to the Internet and can browse web pages.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;If you do have a connection to the Internet, but the VPN client is
not able to contact the VPN server, it may be a DNS issue – try entering the IP
address of the VPN server rather than the friendly name.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;If you are able to connect to the VPN server, but once connected you
are not able to access any network resources, this may be an IP issue – the VPN
server must be able to allocate remote clients valid IP addresses via DHCP.
This may also be a DNS issue – once connected try connecting to the IP address
of a file server rather than its friendly name, for example. Your network
administrator will be able to provide the details to use.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;To conclude&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;VPNs are massively complicated, but not impossible to set up
successfully provided that you understand the requirements, potential pitfalls
and their workarounds. The biggest hurdle is often just finding out what it is
that you have. Once you know what your equipment supports then the available
options are clear.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;As a bootnote, and for completeness, I should probably mention that
not all VPNs are necessarily secured. A Virtual Private Network could be a
Virtual LAN (VLAN) – which is a technique whereby the same physical network
infrastructure (cabling and switches) is used to host separate networks using
different addressing schemes and which are not “aware” of each other, but over
which communications are not secured.&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;img src="http://blog.devicewire.com/aggbug.aspx?PostID=861" width="1" height="1"&gt;</description></item><item><title>Nokia release Intellisync Mobile Suite Device Management 9.1 for Linux</title><link>http://blog.devicewire.com/blogs/devicewire/archive/2008/07/05/nokia-release-intellisync-mobile-suite-device-management-9-1-for-linux.aspx</link><pubDate>Sat, 05 Jul 2008 06:59:00 GMT</pubDate><guid isPermaLink="false">df238d37-d6e2-4966-96cd-299e643337d6:860</guid><dc:creator>jamesl</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Following the release of Intellisync Mobile Suite 9.0 for Windows a few weeks ago, version 9.1 for Linux is now available.&lt;/p&gt;&lt;p&gt;Although being called specifically 'IMS Device Management', the release notes do state that both the DM and also the Wireless Email components of the solution are included in this version.&lt;br&gt;&lt;/p&gt;&lt;p&gt;The list of new features in the release notes also include:&lt;/p&gt;&lt;p&gt;Improved performance and scalability&lt;/p&gt;&lt;p&gt;Clustering support for OMA DM Connections&lt;/p&gt;&lt;p&gt;Alternative SMS Channel for DM Provisioning and Notification Messages&lt;/p&gt;&lt;p&gt;New Service Administrator Role for Tenant Administration&lt;/p&gt;&lt;p&gt;Additional Configuration Options to IMS Client Sync Window&lt;/p&gt;&lt;p&gt;Hosting Administrator Managed Tenant Publication Templates&lt;/p&gt;&lt;p&gt;Orphaned Backup File Purge&lt;/p&gt;&lt;p&gt;More Comprehensive Web Services Interface for IMS DM&lt;/p&gt;&lt;p&gt;OMA DM Support for Siemens VOIP Application&lt;/p&gt;&lt;p&gt;Remote Control for UIQ Devices&lt;/p&gt;&lt;p&gt;WebAdmin Support for Delivering ActiveSync Settings to Windows Mobile Devices&lt;/p&gt;&lt;p&gt;WebAdmin Support for Delivering GPRS and WLAN IAP Settings to Windows Mobile Devices&lt;/p&gt;&lt;p&gt;Callback/Notification Interface&lt;/p&gt;&lt;p&gt;Confiugurable HTTP/HTTPS Ports for WebAdmin Connections&lt;/p&gt;&lt;p&gt;Symbian Client Backup/Restore Checkpoint Restart&lt;/p&gt;&lt;p&gt;FOTA (that's Firmware Over The Air) Support for Nokia S40 and S60 Devices &lt;/p&gt;&lt;p&gt;Additional Attributes for LDAP&lt;/p&gt;&lt;p&gt;Email Support for POP/IMAP &amp;amp; Corporate Email Connector (ECE)&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I am particularly intrigued to see how they managed to implement the Wireless Email component on a Linux platform. Watch this space for a full review. &lt;br&gt;&lt;/p&gt;&lt;img src="http://blog.devicewire.com/aggbug.aspx?PostID=860" width="1" height="1"&gt;</description></item><item><title>Microsoft Small Business Server 2008 Preview available</title><link>http://blog.devicewire.com/blogs/devicewire/archive/2008/07/05/microsoft-small-business-server-2008-preview-available.aspx</link><pubDate>Sat, 05 Jul 2008 06:56:00 GMT</pubDate><guid isPermaLink="false">df238d37-d6e2-4966-96cd-299e643337d6:859</guid><dc:creator>jamesl</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Microsoft have released a technology preview (that's a beta to you and me!) of the next release of the Small Business Server product - SBS 2008.&lt;/p&gt;&lt;p&gt;The details of serial numbers and download links can be found here:&lt;/p&gt;&lt;p&gt;http://technet.microsoft.com/en-gb/evalcenter/cc184870.aspx &lt;br&gt;&lt;/p&gt;&lt;p&gt;It's a bit of a whopper: 4 DVD images can be downloaded from the following links:&lt;/p&gt;&lt;p&gt;&amp;nbsp;http://sbs.dlservice.microsoft.com/download/F/4/B/F4B32E45-EC2C-4C18-9BD2-58F5D1643A6E/SBS2008RC0_ENU_DVD1.iso&lt;br&gt;&lt;br&gt;http://sbs.dlservice.microsoft.com/download/F/4/B/F4B32E45-EC2C-4C18-9BD2-58F5D1643A6E/SBS2008RC0_ENU_DVD2.iso&lt;br&gt;&lt;br&gt;http://sbs.dlservice.microsoft.com/download/F/4/B/F4B32E45-EC2C-4C18-9BD2-58F5D1643A6E/SBS2008RC0_ENU_DVD3.iso&lt;br&gt;&lt;br&gt;http://sbs.dlservice.microsoft.com/download/F/4/B/F4B32E45-EC2C-4C18-9BD2-58F5D1643A6E/SBS2008RC0_ENU_DVD4.iso&lt;br&gt;&lt;br&gt;Be aware that the MINIMUM system requirements are 2GB of RAM and 60GB of hard disk space - I have had to move my iTunes Library just to get the minimum spec on my test machine!&lt;br&gt;&lt;/p&gt;&lt;img src="http://blog.devicewire.com/aggbug.aspx?PostID=859" width="1" height="1"&gt;</description></item><item><title>Everything you wanted to know about Server ActiveSync but were too afraid to ask</title><link>http://blog.devicewire.com/blogs/devicewire/archive/2008/06/29/everything-you-wanted-to-know-about-server-activesync-but-were-too-afraid-to-ask.aspx</link><pubDate>Sun, 29 Jun 2008 07:50:00 GMT</pubDate><guid isPermaLink="false">df238d37-d6e2-4966-96cd-299e643337d6:858</guid><dc:creator>jamesl</dc:creator><slash:comments>0</slash:comments><description>






&lt;div class="Section1"&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;For those of you who have been living under a rock recently, Server
ActiveSync is the Microsoft protocol which enables Windows Mobile-based devices
to communicate with an Exchange Server to remotely synchronise Email, Contact,
Calendar and Task information between the PDA and the user’s Exchange mailbox.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;This functionality has been around since the release of Pocket PC
2003, but it was the release of Windows Mobile 5 (AKU-2) that introduced ‘push’
capability. The current release at the time of writing, Windows Mobile 6.1, has
incorporated further improvements – such as the ability to access the Exchange
Global Address List (GAL) as well as enabling and disabling out of office
messages.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;The Server ActiveSync protocol has been licensed by Microsoft to
other handset manufacturers, including Nokia and Apple among others, enabling
the same functionality on non-Microsoft-based platforms: a clever move as it
allows the user a wider-range of handset whilst requiring the corporate IT
department to deploy Microsoft Exchange at the back end (which obviously
requires a Microsoft operating system to run on).&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;But how does it work? In this article I will look briefly at how the
client device is configured, what needs to be enabled on the back-end server
infrastructure as well as common problems and their resolutions. Finally, I
will look at Server ActiveSync’s big brother, which not all of you may know
about: Outlook Anywhere.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;Configuring the Windows Mobile Client&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;In this example I have used a Pocket PC device, but the process is
very similar on a Smartphone device.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;From the Today Screen, tap and Start and select Programs&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/server_activesync/001.jpg" height="472" width="315"&gt;&amp;nbsp; &lt;img src="http://www.hughsymonstelecom.co.uk/Files/server_activesync/002.jpg" height="471" width="302"&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;From the list of available programs, launch ActiveSync. The
following screen will be displayed:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/server_activesync/003.jpg" height="469" width="304"&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Select the option to set up your device to sync with an Exchange
Server. The following screen will be displayed:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/server_activesync/004.jpg" height="468" width="302"&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;You will be prompted to enter your email address, from which the
wizard will attempt to determine the correct server settings to use
automatically (if your PDA is running version 6.1 of the Windows Mobile software),
I will look at this process in more detail later. If you know the correct
settings to use, untick the option to ‘Attempt to determine Exchange Server
settings automatically’ and tap Next. The following screen will be displayed:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/server_activesync/005.jpg" height="466" width="302"&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Enter the address of the Exchange Server. This will be the same
address used by Outlook Web Access (OWA) – if you check your mail via a web
browser ever, this will be the address to use. If you don’t know the address to
use, your network administrator will be able to tell you.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Usually you should use leave the option to use an SSL connection
ticked, unless specifically told by your network administrator. Tap Next, the
following screen will be displayed:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/server_activesync/006.jpg" height="467" width="301"&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Enter your username, password and domain details. These details will
be the same that you use to log into your desktop or laptop PC in the office,
if you have one. Again, if you don’t know the details, your network
administrator will give you the correct settings to use. Tap Next, the
following screen will be displayed:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/server_activesync/007.jpg" height="469" width="303"&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Select the folders in your mailbox that you want to synchronise and
click Finish.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;You’re all set. Provided that you have a connection to the Internet,
the contents of your Exchange mailbox will now be synchronised to your PDA
automatically.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;i&gt;&lt;span&gt;Automatically determining the server address&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;If you leave the option to determine the Exchange Server address
automatically, the wizard will attempt to perform an MX lookup on the domain
entered in the email address, and from that ascertain the mail server details
for the domain.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;To explain, the domain in an email address is the bit after the @
sign. So, for example, if I enter my email address of
‘james.liddiard@devicewire.com’, the domain is ‘devicewire.com’.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;If you browse to &lt;a href="http://www.devicewire.com/"&gt;www.devicewire.com&lt;/a&gt;
from a web browser on your PC, your PC does not know what devicewire.com is,
instead it consults a DNS server. DNS is the domain name system, and is
essentially a very large table that maps ‘friendly names’ to IP addresses,
which PCs can understand. Therefore, by browsing to &lt;a href="http://www.devicewire.com/"&gt;www.devicewire.com&lt;/a&gt;, I am really
connecting to 62.189.60.223&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;If I want to send an email to someone at devicewire.com, my email
application will also consult a DNS server to find out what the IP address is
of the devicewire.com domain, but rather than performing a simple DNS lookup,
it will perform an MX lookup. MX stands for eMail eXchange and contains details
of the email server for a given domain.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;You can find out the MX record for a domain quite easily from any PC
connected to the Internet. Open a command window and enter a command of
‘nslookup’ and press Enter&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Now issue the command, ‘set type=mx’ and press Enter&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Now enter the domain and press Enter. This screenshot shows the
response for the devicewire.com domain:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/server_activesync/009.jpg" height="447" width="665"&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;This is the procedure that the Windows Mobile 6.1 wizard performs.
Once completed, the user is then still prompted to enter their username,
password and domain information, it is only the server address that is
determined by this procedure.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;This procedure will not succeed if the domain specified uses a mail
relay service, such as MessageLabs, as emails are not sent directly to the
target domain (as is the case with devicewire, as shown in the above
screenshot).&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;Addendum - the configuration of a Windows Mobile client can be achieved a lot more easily if the Microsoft System Center Mobile Device Manager 2008 solution is also deployed alongside Exchange. I looked at this solution in an earlier post, here:&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;http://blog.devicewire.com/blogs/devicewire/archive/2008/04/13/system-center-mobile-device-manager-2008.aspx &lt;br&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;"&gt;Configuring the Exchange Server&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;In order to achieve Push functionality with a Server
ActiveSync-capable client, the Exchange Server must be running Exchange 2003
Service Pack 2 or later.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;By default, the Server ActiveSync push functionality is enabled already. On a server running Exchange 2003 SP2, the functionality is enabled and disabled
within the Exchange System Manager:&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&lt;img src="http://www.hughsymonstelecom.co.uk/Files/server_activesync/008.jpg" height="565" width="639"&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;Expand the Global Settings and open the properties for Mobile
Services. Ensure that the option to Ensure Direct Push over HTTP(s) is enabled.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.0001pt;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-bottom:0.000