How to block mobile devices connected to internal Wi-Fi networks on Lync 2013

How to block mobile devices connected to internal Wi-Fi networks on Lync 2013.
we don't have lyncdiscoverinternal.contoso.com and lyncdiscover.contoso.com in internal DNS record, all mobile users are connecting from Internet, and we want it to be that way.
So if I create the lyncdiscoverinternal.contoso.com record for Windows desktop clients autodiscover, how do I block internal mobile users from connecting to Lync??
Praveen | MCSE Messaging 2003

Hi Praveen,
Based on my experience, one way to achieve this purpose you need to use the Reverse Proxy that is integrate with a Firewall (e.g. TMG 2010 , F5, etc…).
Please have a look at the following picture.
In Lync Server 2013,
both the internal Mobility Service URL and the external Mobility Service URL are associated with the external Web Services FQDN.
 From the above picture, if you use a reverse proxy that is
separate from the firewall, then the hairpin will be created,
 and cause the mobile client which connected to the internal Wifi will be able to
 access the external interface of the Reverse Proxy.
In this situation, the mobile client which from Internet will not be effected.
Best regards,
Eric
Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]

Similar Messages

  • How to download Mobile Device Service?

    Okay, so i downloaded the new IOS.5 the other day for the ipad. Then today i thought i download it onto my ipod as well. Didnt connect, i did the whole thing with the Control panel, repairing Apple Device Service and all. Then I accidentally deleted the thing :S! Anyone know how to download Mobile Device Service again...? And yes, i tried to re install iTunes - a million times to be exact -.-! please help? im about to cry! i cant live without my music.

    The iPod and iTunes didnt connect* Please help me ? I need my iPod to be back and working by tomorrow, music is like my life, I cant go the day without it.... Please? if you can help me then you would be a real life saver!

  • How often do Mobile devices "Check in"

    Does anyone the answer to the following questions:
    1. How often do mobile devices enrolled in Intune (integrated into SCCM 2012) check in for new policy/apps?
    2. Does this vary by device type? (i.e. does iOS check in x many hours versus Android)
    3. Are there any other trigger points that force a mobile client to check in?
    Just trying to understand what the typical delivery time is for an Intune managed device to receive a newly deployed app or setting, and if there is anyway to force a client to check in (from the client itself).
    Thanks!

    Hi William,
    According to official documentation, the sync interval is 8 hours for all platforms:
    http://technet.microsoft.com/en-us/library/dn376523.aspx
    However, on the internet various blogs report:
    Windows Phone 8 by default connects every 8 hours. You can force/initiate the sync from the enrollment UI (settings -> workspace)
    Windows 8.1 connects every 24 hours. You can force by running "Run MDMAgent.exe" from an elevated Command Prompt.
    iOS by default connects every 24-36 hours. It is rumoured (didn't test it myself) you can force a policy/app sync by installing an app from the company portal app. You can later de-install the app if you want. By installing the app, the company portall
    app is forced to connect to Intune and will get new policies and apps at the same time.
    The WP8 sync force works for sure. i use this option all the time during Intune deployments.
    If you found this post helpful, please “Vote as Helpful”.
    If it answered your question, please “Mark as Answer”.
    Christian Gude | www.itexperience.net

  • Lync mobile device connection issue

    Hello everybody,
    I'm implementing Lync Mobility and remote access in our organization. Remote access is workig fine. But mobile devices cannot connecting to Lync Server 2010. My topology is : 
    Reverse Proxy Server(IIS7 works fine) <--> Front End Server <--> Back End Server
    pool : pool1.lynctest.local
    internal web srvc : lyncinternalweb.lynctest.local
    external web srvc : lyncweb.lynctest.domain.com
    All internal and external DNS records created. Deployed internal CA and external internal web service certificates issued from internal CA. Also installed all root certificates on mobile devices and other remote machines. Below is log from android device.
    20 Mar 2014 10:53:27 INFO APPLICATION:SignIn. signInAsUserState=0, actualSessionState=0
    20 Mar 2014 10:53:27 INFO APPLICATION:Sending AutoDiscovery request (in sign-in sequence)
    20 Mar 2014 10:53:27 INFO TRANSPORT:setUsernamePasswordCredential changing credential: 
    20 Mar 2014 10:53:27 INFO TRANSPORT:Credential information: credType (1) signInName ([email protected]) domain () username ([email protected]) password.empty() (0) compatibleServiceIds(1)
    20 Mar 2014 10:53:27 INFO APPLICATION:Serialized sipuri= intUcwa= extUcwa= intADRoot= extADRoot= location=1 networkType=1
    20 Mar 2014 10:53:27 INFO APPLICATION:Storing 2 out-of-sync components took 49ms
    20 Mar 2014 10:53:27 INFO APPLICATION:Timer cancelled. OnResume = 0
    20 Mar 2014 10:53:27 INFO APPLICATION:Discover UCWA urls from https://lyncdiscover.lynctest.golomtbank.com & https://lyncdiscover.lynctest.golomtbank.com for sip:[email protected]
    20 Mar 2014 10:53:27 INFO APPLICATION:Extracted lynctest.golomtbank.com from sip:[email protected]
    20 Mar 2014 10:53:27 INFO APPLICATION:Starting Auto Discovery with urls https://lyncdiscover.lynctest.golomtbank.com?sipuri=sip:[email protected] and https://lyncdiscover.lynctest.golomtbank.com?sipuri=sip:[email protected]
    20 Mar 2014 10:53:27 INFO TRANSPORT:getSpecificCredential returning the following credential for credType (1) serviceId (4)
    20 Mar 2014 10:53:27 INFO TRANSPORT:Credential information: credType (1) signInName () domain () username () password.empty() (1) compatibleServiceIds(0)
    20 Mar 2014 10:53:27 INFO TRANSPORT:Added Request(UcwaAutoDiscoveryRequest) to Request Processor queue
    20 Mar 2014 10:53:27 INFO APPLICATION:Submitting new req. <unknown>
    20 Mar 2014 10:53:27 INFO TRANSPORT:Sent Request(UcwaAutoDiscoveryRequest) to Request Processor
    20 Mar 2014 10:53:27 INFO APPLICATION:Submitting Unauthenticated AutoDiscovery request to https://lyncdiscover.lynctest.golomtbank.com?sipuri=sip:[email protected]
    20 Mar 2014 10:53:27 INFO APPLICATION:CLogonSession::setNewActualState() state=1
    20 Mar 2014 10:53:27 INFO UcClientStateManager: New UI State: ActualState = IsSigningIn DesiredState = BeSignedOut  DataAvailable = false
    20 Mar 2014 10:53:27 INFO TRANSPORT:<SentRequest>
    20 Mar 2014 10:53:27 INFO TRANSPORT:To:https://lyncdiscover.lynctest.golomtbank.com?sipuri=sip:[email protected]
    20 Mar 2014 10:53:27 INFO TRANSPORT:HttpHeader:Accept application/vnd.microsoft.rtc.autodiscover+xml;v=1
    20 Mar 2014 10:53:27 INFO TRANSPORT:
    20 Mar 2014 10:53:27 INFO TRANSPORT:</SentRequest>
    20 Mar 2014 10:53:27 INFO TRANSPORT:Sending request(UcwaAutoDiscoveryRequest) to server type = 0
    20 Mar 2014 10:53:27 VERBOSE HttpConnection: post request: https://lyncdiscover.lynctest.golomtbank.com?sipuri=sip:[email protected]
    20 Mar 2014 10:53:27 VERBOSE HttpConnection: send request: https://lyncdiscover.lynctest.golomtbank.com?sipuri=sip:[email protected]
    20 Mar 2014 10:53:27 INFO APPLICATION:LogonSession::signIn() succeeded
    20 Mar 2014 10:53:27 INFO UcClientStateManager: New UI State: ActualState = IsSigningIn DesiredState = BeSignedIn  DataAvailable = false
    20 Mar 2014 10:53:27 VERBOSE ActivityMonitor: Activity Create: com.microsoft.office.lync.ui.options.SigningInActivity
    20 Mar 2014 10:53:27 VERBOSE ActivityMonitor: Activity Start: com.microsoft.office.lync.ui.options.SigningInActivity
    20 Mar 2014 10:53:27 VERBOSE ActivityMonitor: Activity Stop: com.microsoft.office.lync.ui.options.CredentialsActivity
    20 Mar 2014 10:53:27 VERBOSE ActivityMonitor: Activity Destroy: com.microsoft.office.lync.ui.options.CredentialsActivity
    20 Mar 2014 10:55:33 INFO APPLICATION:Called signOut() in state 1
    20 Mar 2014 10:55:33 INFO APPLICATION:Cancelling all requests
    20 Mar 2014 10:55:33 INFO APPLICATION:Serialized sipuri=sip:[email protected] intUcwa= extUcwa= intADRoot= extADRoot= location=1 networkType=1
    20 Mar 2014 10:55:33 INFO APPLICATION:Storing 2 out-of-sync components took 31ms
    20 Mar 2014 10:55:33 INFO APPLICATION:Timer cancelled. OnResume = 0
    20 Mar 2014 10:55:33 INFO APPLICATION:CLogonSession canceling all requests
    20 Mar 2014 10:55:33 INFO APPLICATION:CLogonSession::setNewActualState() state=0
    20 Mar 2014 10:55:33 INFO UcClientStateManager: New UI State: ActualState = IsSignedOut DesiredState = BeSignedOut  DataAvailable = false
    20 Mar 2014 10:55:34 INFO APPLICATION:Timer cancelled. OnResume = 0
    20 Mar 2014 10:55:34 INFO APPLICATION:Storing 1 out-of-sync Object Models took 22ms
    20 Mar 2014 10:55:34 VERBOSE ActivityMonitor: Activity Create: com.microsoft.office.lync.ui.options.CredentialsActivity
    20 Mar 2014 10:55:34 VERBOSE ActivityMonitor: Activity Start: com.microsoft.office.lync.ui.options.CredentialsActivity
    20 Mar 2014 10:55:34 VERBOSE ActivityMonitor: Activity Stop: com.microsoft.office.lync.ui.options.SigningInActivity
    20 Mar 2014 10:55:34 VERBOSE ActivityMonitor: Activity Destroy: com.microsoft.office.lync.ui.options.SigningInActivity
    20 Mar 2014 10:55:41 VERBOSE ActivityMonitor: Activity Create: com.microsoft.office.lync.ui.options.CredentialsOptionsActivity
    20 Mar 2014 10:55:41 VERBOSE ActivityMonitor: Activity Start: com.microsoft.office.lync.ui.options.CredentialsOptionsActivity
    20 Mar 2014 10:55:41 VERBOSE ActivityMonitor: Activity Stop: com.microsoft.office.lync.ui.options.CredentialsActivity
    20 Mar 2014 10:55:42 INFO APPLICATION:CMcxDataSynchronizer now in mode 1
    20 Mar 2014 10:55:42 INFO APPLICATION:Mode 1 scheduled to timeout in 30.000000s
    20 Mar 2014 10:55:42 INFO APPLICATION:No SendUpdate schedule action. timerStarted=0, timerNeedsToRun=0, channelState=0, timerAction=0
    20 Mar 2014 10:55:42 VERBOSE ActivityMonitor: Activity Create: com.microsoft.office.lync.ui.options.AboutActivity
    20 Mar 2014 10:55:42 VERBOSE ActivityMonitor: Activity Start: com.microsoft.office.lync.ui.options.AboutActivity
    20 Mar 2014 10:55:43 VERBOSE ActivityMonitor: Activity Stop: com.microsoft.office.lync.ui.options.CredentialsOptionsActivity
    Also I tested web services by web browser and they seem fine. I cannot find what's wrong with this. Please help me dears.
    Thank you

    The ports will be visible in the Netstat result after a connection has been setup by a mobile device.
    For details, you can check http://www.lync-blog.nl/?p=671&lang=en
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make
    sure that you completely understand the risk before retrieving any suggestions from the above link.
    Please follow the follow blog to troubleshoot external Lync Mobility connectivity issue step by step:
    http://blogs.technet.com/b/nexthop/archive/2012/02/21/troubleshooting-external-lync-mobility-connectivity-issues-step-by-step.aspx
    Lisa Zheng
    TechNet Community Support

  • How to hide mobile device status on iPhone 6?

    How do I hide my "on mobile device" status on the iPhone 6?  I do not see "my info" anywhere as the other posts suggest.  Also, I already removed my phone number from my profile.  Thanks!

    Hello chemahmud,
    It sounds like you have Grayscale turned on. If you go to Settings > General > Accessibility and toggle off Grayscale. Once you do that you should have color back.
    Invert Colors and Grayscale
    http://help.apple.com/iphone/8/#/iph3e2e1fb0
    Regards,
    -Norm G.  

  • How to Block LAP1242 AG connect WLC

    Hi Friends,
    Did you meet this issues that the remote site (US) AP 1242 always connect to our site(ASIA) WLC 5508 (maybe some DHCP configure caused when troubleshooting, right nowDHCP back to normal. only enable vendor and option 43 for 1262 and 3602, no option 43 for 1242), but now we cannot block these AP1242 to join our site 5508 WLC. even I reset the 1242 AP to default configure from WLC GUI and CLI , but it's still there in a mins.
    Since in our site Core SW, Router cannot find these AP mac address, and also those AP not the IP address in the WLC GUI and CLI . SO we don't know where it is?  can you pls help?

    Well that is how to block APs from joining:). If you know these APs have to join a specific WLC, then create a dhcp option 43 for these APs or temporarily create a DNS entry for these APs to join the WLC it is suppose to. You can't just block these APs from joining if you have mo ility between the WLCs and or if your using option 43 and or DNS that helps these APs join the WLC. So now what your stuck with is making these join the right WLC. When you do that, then remove all your option 43 from dhcp and disable the DNS so none of the APs will be able to join the wrong WLC.
    Sent from Cisco Technical Support iPhone App

  • TS4006 i had my iphone 4s stolen , how can block the device or wipe out its content?

    I had my iphone 4 s stolen, how can i block the device or wipe out its content?

    If the phone is offline there is no way to track it or send a message to it.  You can place it in lost mode to lock it and send it a message (see http://help.apple.com/icloud/#/mmfc0f0165), but this will not take place until the phone goes back online, if it ever does.  If it does, you will get an email informing you.
    You might want to read this: http://support.apple.com/kb/HT5668.

  • How to share mobile wireless connection from Win XP to mac?

    Hi,
    I have two comupters,one mac and one PC (win XP). I am trying to share the mobile wireless broadband from my PC to the mac. I set up the sharing from mac to PC successfully quite a while ago, but now I need to work extensively on mac. So I tried to set up the sharing in the other around and nothing worked at all. Here is what I did.
    1. I enabled the sharing of the mobile wireless connection on PC.
    2. I tried to set up a small/home network, but it didn't work on Mac as the windows softwares can't be run on mac
    3. I also tried to set up a peer-to-peer connection from PC to Mac which also didn't work.
    Does anyone how to do the sharing from PC to Mac? Thanks a lot!

    Okay, firstly some routers or mdoems come with 2 ports on the back so you can connect two different computers so simply plug them both in
    if not, then i advise you buy a router which allows you to add numerous computers to the same network via wires or add numerous computers wirelessly
    i have one computer connect to my netgear router -wired
    i have one computer wirelessly connected with a Netgear USB wireless reciever
    then i got my laptop which is connected via wireless
    i have xbox live which i connect to the internet via my laptops wireless connection, this can be done with any pc or laptop aswell
    what you do is
    wireless networks - where it showws any detected networks
    change advanced options - on the side
    advanced tab
    then allow other computers to use this computers internet connection
    simple as
    all you do is plug in your other pc or whatever

  • How to view other devices connected to router

    I can see how many devices are connected to my router at any one time, but how do I see which devices are connected?
    Thanks!

    For the E1000 V2 the only way to know what devices are connected to your network is thru the DHCP clients table only. It will show you the mac address or ip address of the devices that are currently connected to the network. If you are using the cisco connect software it will only show you the number of devices connected but will not be able to give you detailed information. If you check parental controls, it will allow you to select computers only since those are the only devices recognized by the software.

  • How can I manually verify autodiscovery configuration for on premise environment from Lync 2013 desktop client?

    I have very limited access to an environment (basically just user access). I am documenting the Lync 2013 cilent for this environment. I was provisioned a limited SIP enabled account for testing. Autodiscovery from the Lync 2010 client works, but not from
    the 2013 client. I can connect (with some issues) from either 2010 client (autodiscovery) and 2013 client (manually configuring the server). So I want to verify if the Autodiscover is configured correctly to work with the 2013 client or not and if the reason
    it fails for me is due to something wrong with my account or if this will happen with other users?
    I have checked the lyncdiscoverinternal.domain.com and it resolves and is reachable. I can navigate to https :// lyncdiscoverinternal.domain.com/Autodiscover/AutodiscoverService.svc/root/domain and it returns the information I would think it should
    including hrefs to Internal/Autodiscover, Internal/AuthBroker, External/Autodiscover, External/AuthBroker, Internal/Mcx & External/Mcx as well as fqdns for SipClientExternalAccess, SipClientInternalAccess, SipServerExternalAccess & SipServerInternalAccess.
    The AuthBrokers urls return what I believe is the expected RemoteService Service pages. The Mcx urls return what I believe is the expected McxService2 Service pages. The SipClientInternalAccess & SipServerInternalAccess fqdns are both resolvable and
    reachable. The Autodiscover urls return hrefs for Domain and User. Those Domain urls return the same information as the initial root/domain url and the user url (which I believe is the one that is actually opened by lync during the autodiscover process) returns
    what I believe is an expected 401 - Unauthorized: Access is denied due to invalid credentials page.
    If I explicitly configure the Lync 2013 client to use the fqdn listed for SipClientInternalAccess, the client will log me in. However on Automatic configuration, it fails to log me in.
    One other note is that when I watch with Wireshark, I observed that it is getting another internal server fqdn from somewhere. We'll just say that the SipClientInternalAccess fqdn is lyncABC.domain.internal. When looking at Wireshark and the DNS requests,
    I'm also seeing a lync2013ABC.domain.internal that does resolve and is reachable and can also be used as the explicitly listed server in the Lync 2013 client and it will log in. However, that fqdn is not listed in any of the root or domain url replies. So
    I'm not sure where it is coming from or how to check that.
    Is there any additional information anywhere that can tell me exactly what the behavior of the 2013 client is when trying to find the server to authenticate to and how I can reproduce any missing steps manually to determine what it is identifying as the
    login server (if any) since it is obviously not the trying the one listed as SipClientInternalAccess?
    Thanks,
    Richard

    Hi Richard,
    To narrow down the issue, you could refer to the following steps first.
    1. Delete the Lync client 2013 user profile and registry key.
    User profile:
    %userprofile%\AppData\Local\Microsoft\Office\15.0\Lync\[email protected]
    Registry Key:
    HKCU\Software\Microsoft\Office\15.0\Lync\[email protected]
    Certificate:
    a. Open Windows Certificate Manager. To do this, press Windows + R, type certmgr.msc, and then click OK.
    b. Expand Personal, and then expand Certificates.
    c. Look for a certificate that's issued by Communications Server and delete it.
    2. Upgrade Lync client to the latest update.
    3. Check the DNS records(A records and SRV records) again.
    Best regards,
    Eric

  • My Time Capsule is not allowing other wifi  device to connect. Even my PC which is plugged to the Time capsule. How to let all device connect and my PC too?

    My Time Capsule is not allowing other device to connect. My Mac Air did the setup and connection and it is. Now Iphone and Ipad are seeing the network but are unable to connect. Same with my desktop PC connected to the time capsule and not able to reach the net. How to fix this?

    My Time Capsule is not allowing other device to connect. My Mac Air did the setup and connection and it is. Now Iphone and Ipad are seeing the network but are unable to connect. Same with my desktop PC connected to the time capsule and not able to reach the net. How to fix this?

  • How to find Mobile device OS name and version using Flex?

    is there anyway to get device information like OS name and version using flex 4.5.1 or 4.6 SDK. i am developing a project in Flex which needs to identify the end user mobile platform like Android, iOS.. and its version like Android means 2.1,2.2,etc..
    Anyone can help me on this?

    I don't know that there is a proprietary driver. In fact, I'm sure there isn't because I never installed one. I figured there was some code file somewhere that dealt with keyboards. Yes, I have dealt with the developer, they say to tell Apple there is a problem. I have been putting it off and waiting to update since 10.6.3, so the problem is getting a little old. Do I even know there is a problem? I'm not sure what this means. I do know that when I update my operating system past 10.6.2 my keyboard no longer works, and I have to use a stock Apple keyboard to run a time machine reinstall. Why else would I be going through this?

  • How to block mobile broadband permanently to avoid data charges

    i love the wifi on this phone, but i occasionally accidentally get data charges. i have data roaming off, but it sometimes still goes through. what do i do???

    You can either call customer service and have data blocked, but sometimes they will do it wrong and block picture/video messages as well. How i did it was that I logged into myverizon on my home computer and there is an option on the bottom to "change features" under the section labeled plan, click on that. Then on the right side of the screen there is link under the "related actions" section that says "Manage Service Blocks" click that. Finally select "block all data features" and click update. Your done and can now use your phone without fearing data charges and yes you can still use WIFI.

  • How to use GPS device connected to USB to Serial TTL connector

    Hi,
    In case Lesson 3, I found the code to open UART as follows.
          uart = DeviceManager.open(UART_DEVICE_ID);
    This is the case that ttyAMA0 is used.
    I would like to use USB to Serial TTL connector.
    Could you let me know into what I need to change the code above?
    Thanks,
    Marvin

    Hi Marvin,
    assuming new device has name like "/dev/ttyUSB0" you can use following code
    UARTConfig cfg = new UARTConfig("ttyUSB0", DeviceConfig.DEFAULT,  115200, UARTConfig.DATABITS_8, UARTConfig.PARITY_NONE, UARTConfig.STOPBITS_1, UARTConfig.FLOWCONTROL_NONE);
    UART gps = DeviceManager.open(UART.class, cfg);
    /Sergey

  • Saturday evening my i phone 4S stolen i wanted to block my device how to block it please help i did not have its IMEI number please help

    Hi Everone i need your help.
    Saturday evening my iphone 4S device stolen.now its show unavailable am going to lodge a complaint in near police station but the asked for IMEI number that i does not remember so what will i do it is possible to track it? if not so please tell me how to block the device?
    Regards,

    You can use the Find My iPhone feature on iCloud.com. That would need to have your 4s updated to iOS 6 and up to be able to track it and/or clear it. There are a thousand combinations to unlock the simple 4-pin password, so you still have time left to find your iPhone. For more information on how to use Find My iPhone, go to:
    http://www.apple.com/icloud/find-my-iphone.html
    http://support.apple.com/kb/PH2700
    OR
    http://support.apple.com/kb/PH2701?viewlocale=en_US

Maybe you are looking for

  • An Error has occured:The plugin 65534 does not exist in the CMS (FWM 02017)

    Hi, I get the error when I click on Parameter option while rescheduling Crystal Reports from Infoview. I can schedule the reports successfully, the error is only while rescheduling. The error is as follows: An error has occurred: The plugin -65534 do

  • Firefox opens all links in the current tab.

    firefox used to open links from google in the same tab while having links like gyazo links or anything like that open in a new tab. similar to how google chrome does it. then i reset firefox and now when i try to open links it opens them in the curre

  • Custom icon in Windows Add/Remove Programs list

    Hi all, I am developing a software with Labview 2011/2012. When I am creating an installer for my application I am configuring icon section and I can see my icon in windows All programs section. And I want to see this icon also in windows Control Pan

  • Can I create a calendar in French rather than in my default English?

    I want to create a 2009 calendar to send to a French-speaking friend. It would be nice if I could produce one that displays the names of the months etc in her own language. Is there a straight-forward way to create an iPhoto calendar in French instea

  • Flash Crashing Browsers: EXC_BAD_ACCESS (SIGBUS)

    Hi everyone, I've been having problems with Flash crashing both Firefox and Safari for some time now. I've archived and installed, erased and installed, installed OnyX and "cleaned" per a now closed thread here on the same topic... my last resort is