User Guide

Chapter 1 Deploying iPhone and iPod touch 17
 Make sure the DNS for your network returns a single, externally-routable address to
the Exchange ActiveSync server for both intranet and Internet clients. This is required
so the device can use the same IP address for communicating with the server when
both types of connections are active.
 If you’re using a Microsoft ISA Server, create a web listener as well as an Exchange
web client access publishing rule. See Microsofts documentation for details.
 For all firewalls and network appliances, set the idle session timeout to 30 minutes.
For information about heartbeat and timeout intervals, refer to the Microsoft
Exchange documentation at
http://technet.microsoft.com/en-us/library/cc182270.aspx.
Exchange Account Setup
 Enable Exchange ActiveSync for specific users or groups using the Active Directory
service. These are enabled by default for all mobile devices at the organizational level
in Exchange Server 2003 and Exchange Server 2007. For Exchange Server 2007, see
Recipient Configuration in the Exchange Management Console.
 Configure mobile features, policies, and device security settings using the Exchange
System Manager. For Exchange Server 2007, this is done in the Exchange
Management Console.
 Download and install the Microsoft Exchange ActiveSync Mobile Administration Web
Tool, which is necessary to initiate a remote wipe. For Exchange Server 2007, remote
wipe can also be initiated using Outlook Web Access or the Exchange Management
Console.
WPA/WPA2 Enterprise Wi-Fi Networks
Support for WPA Enterprise and WPA2 Enterprise ensures that corporate wireless
networks are securely accessed on iPhone and iPod touch. WPA/WPA2 Enterprise uses
AES 128-bit encryption, a proven block-based encryption method that provides a high
level of assurance that corporate data remains protected.
With support for 802.1X authentication, iPhone and iPod touch can be integrated into a
broad range of RADIUS server environments. 802.1X wireless authentication methods
are supported and include EAP-TLS, EAP-TTLS, EAP-FAST, PEAPv0, PEAPv1, and LEAP.
WPA/WPA2 Enterprise Network Configuration
 Verify network appliances for compatibility and select an authentication type (EAP
type) supported by iPhone and iPod touch. Make sure that 802.1X is enabled on the
authentication server, and if necessary, install a server certificate and assign network
access permissions to users and groups.
 Configure wireless access points for 802.1X authentication and enter the
corresponding RADIUS server information.
 Test your 802.1X deployment with a Mac or a PC to make sure RADIUS authentication
is properly configured.