Home > Microsoft Exchange Tips > Exchange Server Administration Tips > Protect Exchange ActiveSync from premature firewall connection timeouts
Exchange Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

EXCHANGE SERVER ADMINISTRATION TIPS

Protect Exchange ActiveSync from premature firewall connection timeouts


Serdar Yegulalp
09.07.2006
Rating: --- (out of 5)


Exchange Server tips, tutorials and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


One form of firewall attack involves wasting server-side resources by opening and holding open many connections to the same server. To prevent this type of attack, many administrators close firewall connections after a predetermined period of inactivity. The exact timeout varies and can be adjusted, but it's usually somewhere between 10 and 20 minutes for an HTTP connection.

Unfortunately, this form of intrusion defense can cause problems for Exchange Server ActiveSync's direct push technology.

Exchange Server listens for a ping from every mobile device that's connecting to it via ActiveSync direct push, and uses a default of nine minutes for this interval. Some firewalls or proxies will close an inactive HTTP connection after less time than that, which means that the mobile device won't get a response back from the Exchange server.

There are two ways to get around this problem if your firewall or proxy is forcing HTTP connections to time out prematurely.

First, you can change the timeout value on the firewall or proxy. This will vary between makes and models of firewalls/proxies, of course, but there is almost always a way to do this.

If it isn't possible or practical to change the timeout value, the Exchange 2003 server handling ActiveSync connections can be configured to use different heartbeat intervals:

  1. Open the registry on the computer hosting Exchange Server and navigate to the key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MasSync\Parameters.

  2. Add two DWORD values: MinHeartbeatInterval and MaxHeartbeatInterval.

    Both values are calibrated in seconds, and the defaults are 60 and 2700, respectively. The latter value should be set to just below the HTTP timeout threshold, and the former can be anywhere from 1 to MaxHeartbeatInterval. If you want to revert to the default hard-coded values, simply delete these keys.

  3. Restart the IIS Admin Service to make the changes take effect.

About the author: Serdar Yegulalp is editor of the Windows Power Users Newsletter.

Do you have comments on this tip? Let us know.

Related information from SearchExchange.com:

  • Tip: Why HTTP can hurt Exchange ActiveSync attachments
  • Tip: The Exchange Server ActiveSync Web Administration Tool
  • Tip: Exchange ActiveSync and front-end DNS aliases
  • Reference Center: Exchange Server mobile and wireless tips
  • Reference Center: Exchange Server firewall tips and resources

    Please let others know how useful this tip was via the rating scale below. Do you have a useful Exchange Server or Microsoft Outlook tip, timesaver or workaround to share? Submit it to SearchExchange.com. If we publish it, we'll send you a nifty thank-you gift.

    Rate this Tip
    To rate tips, you must be a member of SearchExchange.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    Exchange Server Administration Tips
    Exchange Server 2007 hardware planning for continuous replication
    Benefits of SAN-based storage in Microsoft Exchange Server 2007
    How to generate HTML reports with the Exchange Management Shell (EMS)
    Hosted Exchange Server adoption to infiltrate the enterprise
    Using ActiveSync without a front-end Exchange server
    Use the Exchange Management Shell Set command to block senders
    Why boot an Exchange server from a storage area network (SAN)?
    How to test Exchange Management Shell commands
    Grant or deny permissions to access a user's Exchange 2007 mailbox
    Control query results with Exchange Management Shell's Format command

    Mobile Devices
    Configure a mobile device to receive POP3 email from Exchange Server
    Email sent to a PDA doesn't get saved in Exchange Server mailbox
    Synchronizing Apple iPhone email with Microsoft Exchange Server
    Use the free Windows Mobile emulator to test mobility on Exchange
    Using ActiveSync without a front-end Exchange server
    Why Exchange ActiveSync fails with NAT firewalls
    Is it time to upgrade users' Windows Mobile devices?
    Deploying ISA Server as a firewall for Exchange Server mobile devices
    Adjust your firewall to avoid Exchange 2007 Direct Push failures
    How to solve common ActiveSync error messages

    ISA Server and Firewalls for Microsoft Exchange Server
    Why Exchange ActiveSync fails with NAT firewalls
    Deploying ISA Server as a firewall for Exchange Server mobile devices
    Adjust your firewall to avoid Exchange 2007 Direct Push failures
    OWA stops working from external network connection
    Enhance OWA logon security using Microsoft ISA Server
    Firewall problems with Exchange Server 2007 email attachments
    How and why to disable certain ESMTP verbs
    Creating an ethical firewall in Exchange Server 2007
    Beware of firewalls that block Exchange Server's SMTP/POP3 communications
    How HTTP verbs can 'hang' Outlook Web Access

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    reverse proxy server  (SearchExchange.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

  • HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsWebcastsWhite PapersIT Downloads
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts