Hello,
First of all the configuration is:
Two leg TMG 2010 fully patched behind a Checkpoint Firewall where the nat translations takes place. One leg is in the DMZ and the other in the internal LAN.
In the internal LAN is our exchange 2010 (also fully patched) with all the roles on it.
Second the problem:
I can get ActiveSync working, on the device I get username or password is incorrect. I know for sure that it is correct! When I look withhttps://www.testexchangeconnectivity.com I get on the last check an error:
--------------------
Connectivity Test Failed
Test Details
ExRCA is testing Exchange ActiveSync.
The Exchange ActiveSync test failed.
Test Steps
Attempting to resolve the host name mail.domein.nl in DNS.
The host name resolved successfully.
Additional Details
Testing TCP port 443 on host mail.domein.nl to ensure it's listening and open.
The port was opened successfully.
Testing the SSL certificate to make sure it's valid.
The certificate passed all validation requirements.
Test Steps
Checking the IIS configuration for client certificate authentication.
Client certificate authentication wasn't detected.
Additional Details
Testing HTTP Authentication Methods for URL
https://mail.domein.nl/Microsoft-Server-ActiveSync/.
The HTTP authentication methods are correct.
Additional Details
An ActiveSync session is being attempted with the server.
Errors were encountered while testing the Exchange ActiveSync session.
Test Steps
Attempting to send the OPTIONS command to the server.
Testing of the OPTIONS command failed. For more information, see Additional Details.
Additional Details
An HTTP 500 response was returned from IIS7.
----------------------
When I look in the IIS log, I see the following error:
--------------------
IIS log:
2013-02-04 07:51:06 10.1.1.33 OPTIONS /Microsoft-Server-ActiveSync/default.eas &Log=V0_Cpo19672_Fet20015_Error:System.InvalidCastException_ 443 domein\gebruiker 10.1.1.233 Microsoft-Server-ActiveSync/12.0+(TestExchangeConnectivity.com) 500 0 0 20046
-----------------------
I have googled and googled but I can get my fingers on...