Forum Discussion
Lync 2010 Mobility Sign-in not working from external
Hi All
Hoping someone out there can help me out with this issue...
I have a Lync 2010 deployment using the LTM to load balance traffic to the FE servers as per the Lync Server 2010 (2012_03_15) deployment guide. We haven't deployed Director Servers.
Using autodiscover, mobile clients coming in over 3G (or any external network) attempt to connect to https://lyncexternal.myDomain.com. I can see the traffic coming in via the F5's and hitting the FE servers as expected. However! The client can't log in - the user is presented the message " Can't sign in. Check your account information and try again" - the account information is correct. Looking at the Diagnostic Log from the mobile app, I see a 401 response from my Front End Lync Server with "Access is denied due to invalid credentials" - again, the account information is correct.
I can successfully connect to the mobile app on our internal wifi network, using exactly the same cred's and still using autodiscover - however this traffic doesn't go via the F5, it is direct to one of the FE servers (for testing - same results if the wifi traffic is passed via the F5).
Has anyone encountered this issue before? Any assistance would be greatly appreciated
thanks!
Jordan
16 Replies
- mikeshimkus_111Historic F5 AccountHi Jordan, are you using LTM as a reverse proxy for external Mobility connections, or ISA/TMG?
- jordjw_46323
Nimbostratus
Hi Mike - jordjw_46323
Nimbostratus
Hi Mike - mikeshimkus_111Historic F5 AccountI don't have any experience with Juniper, but since the Mobility traffic has to pass through the RP, I wonder if whatever auth it's passing to the FE is incorrect.
- jordjw_46323
Nimbostratus
We see the same behaviour if we point internal traffic to the LTM VIP - clients are unable to sign in, and the log files show 401's from the FE severs. - mikeshimkus_111Historic F5 AccountIf you are deploying Mobility externally at all, you are supposed to have both internal and external clients go through the external reverse proxy: http://technet.microsoft.com/en-us/library/hh690030.aspx
- jordjw_46323
Nimbostratus
Hi Mike - jordjw_46323
Nimbostratus
Hi Mike - mikeshimkus_111Historic F5 AccountI think you're on the right track. Do you have the external lyncdiscover.yourdomain.com DNS host name added as a subject alternative name in the certs being used on both the reverse proxy and internal 4443 VIP?
- jordjw_46323
Nimbostratus
Hi Mike
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com