<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: System Center Mobile Device Manager 2008 &#8211; Installing a Gateway Server</title>
	<atom:link href="http://mobilitydojo.net/2008/10/01/system-center-mobile-device-manager-2008-installing-a-gateway-server/feed/" rel="self" type="application/rss+xml" />
	<link>http://mobilitydojo.net/2008/10/01/system-center-mobile-device-manager-2008-installing-a-gateway-server/</link>
	<description>place of the mobility way</description>
	<lastBuildDate>Fri, 10 Feb 2012 08:29:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: goDog</title>
		<link>http://mobilitydojo.net/2008/10/01/system-center-mobile-device-manager-2008-installing-a-gateway-server/comment-page-2/#comment-8591</link>
		<dc:creator>goDog</dc:creator>
		<pubDate>Wed, 27 Jan 2010 07:17:50 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=228#comment-8591</guid>
		<description>Hey Andreas, 

I really need you opinion about a case, can you write to me? I will explain it all, please write to godog@supercable.net.ve. It about SCMDM, just an  opinion.

Thanks a lot!</description>
		<content:encoded><![CDATA[<p>Hey Andreas, </p>
<p>I really need you opinion about a case, can you write to me? I will explain it all, please write to <a href="mailto:godog@supercable.net.ve">godog@supercable.net.ve</a>. It about SCMDM, just an  opinion.</p>
<p>Thanks a lot!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/10/01/system-center-mobile-device-manager-2008-installing-a-gateway-server/comment-page-2/#comment-7456</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Sun, 29 Nov 2009 13:56:03 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=228#comment-7456</guid>
		<description>SCMDM is only supported on Windows Server 2003, not 2008 (or was that just a typo?)
I assume you&#039;re installing SCMDM SP1? Have you performed all necessary ADConfig steps? (Check http://mobilitydojo.net/2008/12/30/scmdm-multiple-instance-deployment-part-1/ for the details.)
The error indicates that the templates either haven&#039;t been created properly, or they aren&#039;t enabled. Have you modified the templates, for instance upped the key length to 2048 or similar?</description>
		<content:encoded><![CDATA[<p>SCMDM is only supported on Windows Server 2003, not 2008 (or was that just a typo?)<br />
I assume you&#8217;re installing SCMDM SP1? Have you performed all necessary ADConfig steps? (Check <a href="http://mobilitydojo.net/2008/12/30/scmdm-multiple-instance-deployment-part-1/" rel="nofollow">http://mobilitydojo.net/2008/12/30/scmdm-multiple-instance-deployment-part-1/</a> for the details.)<br />
The error indicates that the templates either haven&#8217;t been created properly, or they aren&#8217;t enabled. Have you modified the templates, for instance upped the key length to 2048 or similar?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Clark</title>
		<link>http://mobilitydojo.net/2008/10/01/system-center-mobile-device-manager-2008-installing-a-gateway-server/comment-page-2/#comment-7441</link>
		<dc:creator>Michael Clark</dc:creator>
		<pubDate>Sat, 28 Nov 2009 21:21:59 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=228#comment-7441</guid>
		<description>Im having a nightmare with this at the moment.  I just cant seem to create the Gateway Certificate, or request one from the root CA.

The CA is an x86 Server 2003 Enterprise server and all the other MDM servers are running x64 Server 2008 Std.

The error I an getting is:

Certificate not issued (Denied) Denied by Policy Module  0x80094800, The request was for a certificate template that is not supported by the Certificate Services policy: scmdmwebserver(Instance_Name). The requested certificate template is not supported by this CA. 0x80094800 (-2146875392)
Certificate Request Processor: The requested certificate template is not supported by this CA. 0x80094800 (-2146875392)
Denied by Policy Module  0x80094800, The request was for a certificate template that is not supported by the Certificate Services policy: scmdmwebserver(Instance_Name).

I am pulling my hair out trying to figure this out.  Anyone have any ideas?</description>
		<content:encoded><![CDATA[<p>Im having a nightmare with this at the moment.  I just cant seem to create the Gateway Certificate, or request one from the root CA.</p>
<p>The CA is an x86 Server 2003 Enterprise server and all the other MDM servers are running x64 Server 2008 Std.</p>
<p>The error I an getting is:</p>
<p>Certificate not issued (Denied) Denied by Policy Module  0&#215;80094800, The request was for a certificate template that is not supported by the Certificate Services policy: scmdmwebserver(Instance_Name). The requested certificate template is not supported by this CA. 0&#215;80094800 (-2146875392)<br />
Certificate Request Processor: The requested certificate template is not supported by this CA. 0&#215;80094800 (-2146875392)<br />
Denied by Policy Module  0&#215;80094800, The request was for a certificate template that is not supported by the Certificate Services policy: scmdmwebserver(Instance_Name).</p>
<p>I am pulling my hair out trying to figure this out.  Anyone have any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/10/01/system-center-mobile-device-manager-2008-installing-a-gateway-server/comment-page-2/#comment-4893</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Mon, 17 Aug 2009 10:17:23 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=228#comment-4893</guid>
		<description>WiFi can be a pain sometimes.

Are you enforcing that VPN must be connected? VPN should work over WiFi, but maybe there&#039;s a conflict. Does it work connecting an enrolled device to the WiFi if VPN is disabled? And if you are able to get WiFi working, would it then be possible to connect the VPN tunnel manually afterwards?</description>
		<content:encoded><![CDATA[<p>WiFi can be a pain sometimes.</p>
<p>Are you enforcing that VPN must be connected? VPN should work over WiFi, but maybe there&#8217;s a conflict. Does it work connecting an enrolled device to the WiFi if VPN is disabled? And if you are able to get WiFi working, would it then be possible to connect the VPN tunnel manually afterwards?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: roee</title>
		<link>http://mobilitydojo.net/2008/10/01/system-center-mobile-device-manager-2008-installing-a-gateway-server/comment-page-2/#comment-4880</link>
		<dc:creator>roee</dc:creator>
		<pubDate>Sun, 16 Aug 2009 10:22:06 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=228#comment-4880</guid>
		<description>DHCP issues : 

Hey, I followed your guide, and in the end of the day I have a lab with working enrollment, management and Gateway server.

My devices connect via wifi to the external interface of the gateway, and to the external interface of the enrollment server.

The enrollment process works great, the device (Samsung omnia ) asks for a reboot, and then troubles start   

For some reason, which I cannot figure out, the device cannot join our wifi network. After some wireshark research is seems that there is something wrong with the DHCP or with the WIFI settings… 
I can see DHCP offers but the client doesn’t take it. If I assign ip address manually, I can connect, and the client tries to connect to the gateway. However, even in this scenario, it cannot resolve the gateway&#039;s ip address. Looking in wireshark I can see netbios requests (the client is trying to resolve the gateway&#039;s address), which is strange since I have manually configure the dns server&#039;s address in the client&#039;s settings. Moreover, I cannot surf the web using  these settings (the ip address statically set ), and I cannot see any dns requests from the client.
Any help will be very appreciated.
Thanks 
Roee</description>
		<content:encoded><![CDATA[<p>DHCP issues : </p>
<p>Hey, I followed your guide, and in the end of the day I have a lab with working enrollment, management and Gateway server.</p>
<p>My devices connect via wifi to the external interface of the gateway, and to the external interface of the enrollment server.</p>
<p>The enrollment process works great, the device (Samsung omnia ) asks for a reboot, and then troubles start   </p>
<p>For some reason, which I cannot figure out, the device cannot join our wifi network. After some wireshark research is seems that there is something wrong with the DHCP or with the WIFI settings…<br />
I can see DHCP offers but the client doesn’t take it. If I assign ip address manually, I can connect, and the client tries to connect to the gateway. However, even in this scenario, it cannot resolve the gateway&#8217;s ip address. Looking in wireshark I can see netbios requests (the client is trying to resolve the gateway&#8217;s address), which is strange since I have manually configure the dns server&#8217;s address in the client&#8217;s settings. Moreover, I cannot surf the web using  these settings (the ip address statically set ), and I cannot see any dns requests from the client.<br />
Any help will be very appreciated.<br />
Thanks<br />
Roee</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/10/01/system-center-mobile-device-manager-2008-installing-a-gateway-server/comment-page-2/#comment-4404</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Fri, 31 Jul 2009 20:55:24 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=228#comment-4404</guid>
		<description>This confirms that the device is able to establish the VPN tunnel, and communications between the device and gateway is ok.

Now, of course your firewall could be blocking ping requests for a reason, but I still think the routing is something to look into as well.

At this point I&#039;d check the routes on the gateway server, and probably fire up Wireshark or Network Monitor to try and trace the traffic to see what happens. It can be quite tricky, but you are probably dealing with a configuration issue in your infrastructure.</description>
		<content:encoded><![CDATA[<p>This confirms that the device is able to establish the VPN tunnel, and communications between the device and gateway is ok.</p>
<p>Now, of course your firewall could be blocking ping requests for a reason, but I still think the routing is something to look into as well.</p>
<p>At this point I&#8217;d check the routes on the gateway server, and probably fire up Wireshark or Network Monitor to try and trace the traffic to see what happens. It can be quite tricky, but you are probably dealing with a configuration issue in your infrastructure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spencer</title>
		<link>http://mobilitydojo.net/2008/10/01/system-center-mobile-device-manager-2008-installing-a-gateway-server/comment-page-2/#comment-4394</link>
		<dc:creator>Spencer</dc:creator>
		<pubDate>Fri, 31 Jul 2009 09:45:20 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=228#comment-4394</guid>
		<description>Hi,

1. The event view on my GW shows that the device was assigned 192.168.20.4 (based on the network subnets for the ipsec remote address assignment

2.I was unable to ping this Ip from my gateway server (external facing is 172.16.12.11 , internal was 192.168.165,15)

3.I was also not able to ping my gateway server from my device.

Clearly the handset was unable to communicate with gateway server. Also to take note is i am using hostedit file to force the handset to know gateway.scmdm.local to be known as 172.16.12.11. Pretty confusing for me :(</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>1. The event view on my GW shows that the device was assigned 192.168.20.4 (based on the network subnets for the ipsec remote address assignment</p>
<p>2.I was unable to ping this Ip from my gateway server (external facing is 172.16.12.11 , internal was 192.168.165,15)</p>
<p>3.I was also not able to ping my gateway server from my device.</p>
<p>Clearly the handset was unable to communicate with gateway server. Also to take note is i am using hostedit file to force the handset to know gateway.scmdm.local to be known as 172.16.12.11. Pretty confusing for me <img src='http://mobilitydojo.net/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/10/01/system-center-mobile-device-manager-2008-installing-a-gateway-server/comment-page-2/#comment-4363</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Wed, 29 Jul 2009 13:11:47 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=228#comment-4363</guid>
		<description>It&#039;s progress, but yeah, this is a tricky one in some scenarios. Since you&#039;ve got the VPN tunnel established communication between the device and the gateway server should be ok.

However it seems your device is not able to communicate with the device management server. Most likely reasons are routing and/or firewall issues.

I assume that the servers themselves are ok, show no errors, and that the gateway is receiving config from the DM server.

- Check the Event Viewer on the GW to see if an IP address was assigned to the device.
- Check if you are able to ping this IP from your servers.
- Check if you can ping your server from your device (vxUtil works great for this purpose).
- If this is ok try opening https://DM-SERVER:8443/TEE/Handler.ashx from your device. (Should be prompted for a certificate.)

Your router needs to be able to recognize the subnet the device is part of, so you need to verify there is a route both to and from this subnet.</description>
		<content:encoded><![CDATA[<p>It&#8217;s progress, but yeah, this is a tricky one in some scenarios. Since you&#8217;ve got the VPN tunnel established communication between the device and the gateway server should be ok.</p>
<p>However it seems your device is not able to communicate with the device management server. Most likely reasons are routing and/or firewall issues.</p>
<p>I assume that the servers themselves are ok, show no errors, and that the gateway is receiving config from the DM server.</p>
<p>- Check the Event Viewer on the GW to see if an IP address was assigned to the device.<br />
- Check if you are able to ping this IP from your servers.<br />
- Check if you can ping your server from your device (vxUtil works great for this purpose).<br />
- If this is ok try opening <a href="https://DM-SERVER:8443/TEE/Handler.ashx" rel="nofollow">https://DM-SERVER:8443/TEE/Handler.ashx</a> from your device. (Should be prompted for a certificate.)</p>
<p>Your router needs to be able to recognize the subnet the device is part of, so you need to verify there is a route both to and from this subnet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spencer</title>
		<link>http://mobilitydojo.net/2008/10/01/system-center-mobile-device-manager-2008-installing-a-gateway-server/comment-page-2/#comment-4361</link>
		<dc:creator>Spencer</dc:creator>
		<pubDate>Wed, 29 Jul 2009 11:31:42 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=228#comment-4361</guid>
		<description>Hi,

I managed to establish mobile vpn as show on the tick icon of my device. 

However besides establish that, i was not able to obtain schedule wipe or push down of any policies. I tried using mdm connect now tool, other then establishing the session id, the last connection status will show unknown. 

If u need any other information. I will be glad to furnish you with it

Thanks a lot dude</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I managed to establish mobile vpn as show on the tick icon of my device. </p>
<p>However besides establish that, i was not able to obtain schedule wipe or push down of any policies. I tried using mdm connect now tool, other then establishing the session id, the last connection status will show unknown. </p>
<p>If u need any other information. I will be glad to furnish you with it</p>
<p>Thanks a lot dude</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/10/01/system-center-mobile-device-manager-2008-installing-a-gateway-server/comment-page-2/#comment-2650</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Tue, 26 May 2009 12:12:43 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=228#comment-2650</guid>
		<description>Ok, your basic network config sounds good. Not sure if the device still might have NAT issues. As already mentioned SP1 improves on the situation server side, but there&#039;s also some devices that have a buggy client. I can&#039;t remember which build (of Windows Mobile) is required for the most bug-free experience.

But I assume that schedule wipe and policies work like they should? If not there&#039;s most likely a routing issue.

There is no &quot;instant policy&quot;. Since SCMDM is designed to scale up to thousands of devices there&#039;s some issues with trying to apply policies to plenty of devices at a time. Though I agree it would be nice to have the feature nonetheless as long as one know how to use it. (Maybe for a new release of SCMDM - don&#039;t know...)</description>
		<content:encoded><![CDATA[<p>Ok, your basic network config sounds good. Not sure if the device still might have NAT issues. As already mentioned SP1 improves on the situation server side, but there&#8217;s also some devices that have a buggy client. I can&#8217;t remember which build (of Windows Mobile) is required for the most bug-free experience.</p>
<p>But I assume that schedule wipe and policies work like they should? If not there&#8217;s most likely a routing issue.</p>
<p>There is no &#8220;instant policy&#8221;. Since SCMDM is designed to scale up to thousands of devices there&#8217;s some issues with trying to apply policies to plenty of devices at a time. Though I agree it would be nice to have the feature nonetheless as long as one know how to use it. (Maybe for a new release of SCMDM &#8211; don&#8217;t know&#8230;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

