<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://consultingblogs.emc.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Neil Chapman's Blog</title><link>http://consultingblogs.emc.com/neilchapman/default.aspx</link><description>All things Mobile...</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP3 (Build: 20423.1)</generator><item><title>HTC Hermes customisation tool can turn on HSDPA</title><link>http://consultingblogs.emc.com/neilchapman/archive/2006/08/18/4373.aspx</link><pubDate>Fri, 18 Aug 2006 08:46:00 GMT</pubDate><guid isPermaLink="false">e847c0e7-38d9-45c0-b593-56747303e088:4373</guid><dc:creator>neil.chapman</dc:creator><slash:comments>0</slash:comments><comments>http://consultingblogs.emc.com/neilchapman/comments/4373.aspx</comments><wfw:commentRss>http://consultingblogs.emc.com/neilchapman/commentrss.aspx?PostID=4373</wfw:commentRss><description>&lt;P&gt;A colleague of mine pointed this out to me this morning:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://msmobiles.com/news.php/5480.html"&gt;http://msmobiles.com/news.php/5480.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It's a tweaking interface to configure the HTC hermes (Orange SPV M3100, HTC TyTN, T-Mobile MDA Vario II). It can't change everything, but has some interesting features. Apparently, download without registration is not possible which is not great, and the site registration process is in german.&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;The most interesting features of this tweaker&amp;nbsp;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;switching on HSDPA (that is by default switched off in some models of HTC Hermes, for example for Vodafone and O2) 
&lt;LI&gt;showing GPS icon in settings 
&lt;LI&gt;showing wireless plugin (that shows provider, Bluetooth and Wi-Fi status information) 
&lt;LI&gt;disabling skin of the phone 
&lt;LI&gt;removing wireless tray icon 
&lt;LI&gt;disabling SMS sent notification 
&lt;LI&gt;improving quality of stereo audio over Bluetooth (A2DP) &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;I'll grab it&amp;nbsp;today and see if it can deliver on it's promises. Get it from &lt;A href="http://fit4cat.de/thread.php?postid=59#post59"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Neil&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://consultingblogs.emc.com/aggbug.aspx?PostID=4373" width="1" height="1"&gt;</description></item><item><title>Quick review of the HTC MTeoR</title><link>http://consultingblogs.emc.com/neilchapman/archive/2006/08/14/4341.aspx</link><pubDate>Mon, 14 Aug 2006 13:36:00 GMT</pubDate><guid isPermaLink="false">e847c0e7-38d9-45c0-b593-56747303e088:4341</guid><dc:creator>neil.chapman</dc:creator><slash:comments>0</slash:comments><comments>http://consultingblogs.emc.com/neilchapman/comments/4341.aspx</comments><wfw:commentRss>http://consultingblogs.emc.com/neilchapman/commentrss.aspx?PostID=4341</wfw:commentRss><description>&lt;P&gt;I recently obtained and started using the HTC's MTeoR, one of the first devices to be sold under the HTC brand. &lt;/P&gt;
&lt;P&gt;&lt;IMG height=228 src="http://europe.htc.com/z/img/content/htcmteor_141x228.jpg" width=141&gt;&lt;/P&gt;
&lt;P&gt;As this had 3G, and&amp;nbsp;was very slim,&amp;nbsp;I thought this was the Windows Mobile smartphone I had been waiting for. In almost all respects it was. I think this is&amp;nbsp;my favourite&amp;nbsp;smartphone form factor so far. The buttons are easy to use, the screen clear, and I like the fact that it has a jog wheel on the side. (Although I would have preferred it on the right, not the left) The external audio speaker wasn't as good as the speaker on the I-mate SP5, but was usable,&amp;nbsp;and the joystick&amp;nbsp;was much better than any I'd used before.&lt;/P&gt;
&lt;P&gt;Unfortunatley,&amp;nbsp;a couple&amp;nbsp;of things&amp;nbsp;let it down. The battery life is poor. Even compared to other Windows Mobile 5 smartphones it doesn't hold up, I had to charge it twice daily, once in the morning, and once again at night to keep it from turning off. I tested another MTeoR device and had the same issues.&lt;/P&gt;
&lt;P&gt;Having 3G on any small mobile device&amp;nbsp;will lead to power&amp;nbsp;being an issue, but even so, it was worse that I expected. I turned off up to date server activesync and bluetooth, but this didn't seem to help much.&lt;/P&gt;
&lt;P&gt;Also, why did they remove the video calling? If&amp;nbsp;you pay the extra cost of 3G device, surely you'd want all the bells and whistles?&amp;nbsp;Something else I&amp;nbsp;would of liked to see is an&amp;nbsp;audiojack. I guess HTC believe that we'll all be using bluetooth if we want to charge the device while talking on it in the car or listening to music.&lt;/P&gt;
&lt;P&gt;A colleague&amp;nbsp;of mine disabled 3G on his SIM card, and this seemed to improve his battery life while the device only used GPRS.&lt;/P&gt;
&lt;P&gt;In short, this would be my device of choice if the&amp;nbsp;power could last a bit longer.&lt;/P&gt;
&lt;P&gt;Neil&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://consultingblogs.emc.com/aggbug.aspx?PostID=4341" width="1" height="1"&gt;</description></item><item><title>Wireless 802.1x authentication on Windows Mobile 5 (Part 2)</title><link>http://consultingblogs.emc.com/neilchapman/archive/2006/08/11/4333.aspx</link><pubDate>Fri, 11 Aug 2006 15:14:00 GMT</pubDate><guid isPermaLink="false">e847c0e7-38d9-45c0-b593-56747303e088:4333</guid><dc:creator>neil.chapman</dc:creator><slash:comments>5</slash:comments><comments>http://consultingblogs.emc.com/neilchapman/comments/4333.aspx</comments><wfw:commentRss>http://consultingblogs.emc.com/neilchapman/commentrss.aspx?PostID=4333</wfw:commentRss><description>&lt;P class=MsoNormal&gt;I now have some more information about using 802.1x WiFi with WM5. Keep in mind I haven't looked at third party 802.1x clients at this stage, just the WM5 default client.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;I posted in my last blog that I couldn't understand why a username/domain prompt appeared on the device when trying to authenticate to Radius using EAP-TLS. For example, when using an XP machine with EAP-TLS, I just have to provide the personal certificate, and don't have to input anything. &lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;Ok, so why do I get the username / domain prompt with WM 5 EAP-TLS? The answer is this:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;The WM5 device 802.1x client does not associate a certificate to a SSID connection until connecting for the first time.&lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;This means that even though you select a certificate in the client EAP-TLS setup before connecting, the client still doesn't use this certificate for authentication.&lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;The username/domain prompt is the mechanism for creating this association.&lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;If you have multiple personal certificates on your device, this is when the right cert is used for the right SSID for 802.1x authentication.&lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;The reg key that is set when this association is created is:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;HKCU\Comm\EAPOL\Config\&amp;lt;SSID&amp;gt;\Identity (REG_SZ) - &amp;lt;Domain\Username&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;My initial thoughts on all this are that I understand why the WM5 client does the check, but is this really needed if you have only one personal certificate? What else is it going to pick? &lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;Once again, if you have successfully rolled out EAP-&lt;/SPAN&gt;&lt;SPAN&gt;TLS&lt;/SPAN&gt;&lt;SPAN&gt; at all using any 802.1x client on WM5, I'd like to hear from you.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Cheers, &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Neil&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://consultingblogs.emc.com/aggbug.aspx?PostID=4333" width="1" height="1"&gt;</description></item><item><title>Wireless 802.1x authentication on Windows Mobile 5</title><link>http://consultingblogs.emc.com/neilchapman/archive/2006/08/10/4330.aspx</link><pubDate>Thu, 10 Aug 2006 12:44:00 GMT</pubDate><guid isPermaLink="false">e847c0e7-38d9-45c0-b593-56747303e088:4330</guid><dc:creator>neil.chapman</dc:creator><slash:comments>2</slash:comments><comments>http://consultingblogs.emc.com/neilchapman/comments/4330.aspx</comments><wfw:commentRss>http://consultingblogs.emc.com/neilchapman/commentrss.aspx?PostID=4330</wfw:commentRss><description>&lt;P class=MsoNormal&gt;I'd like to pass on some of the experience I've had with Windows Mobile 5 and getting it running on 802.1x Wi-Fi authentication standards in the enterprise, particularly using EAP-TLS.&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;An example situation for an enterprise is this:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;There is an existing Wireless infrastructure with several hundred access points.&lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;A Windows PKI infrastructure is already in place.&lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;The certificate Authority does not use standard templates.&lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;XP Notebooks are already running on WPA, EAP-TLS for authentication to the Wireless network.&lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;They enrol the certificates through Windows group policy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;Microsoft's IAS is used for the Radius authentication, and is connected to the AD with the user accounts.&lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;The challenge is this:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;&lt;o:p&gt;&lt;/o:p&gt;Deploy several thousand Windows Mobile 5 devices &lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;Get them using WPA, EAP-TLS authentication with personal certificates to meet security policy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal&gt;Make the whole process easy to use for a non-technical end user.&lt;o:p&gt;&lt;/o:p&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;So, I do some digging around to see what other companies have done for large scale Windows Mobile device Wi-Fi authentication, and all I can find is WEP keys and WPA - PSK. This avenue wasn't giving me much guidance, so I concentrated on testing the limits of what Windows Mobile 5 could do.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;The main issues I came across:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;1. Getting a personal certificate onto the device.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;Firstly, let be clear about two things, Firstly, WM5 devices do not support Machine certificates. I know they have a hidden cert store that looks like it might be able to, or it looks like we may be able to attach a machine ID to the personal cert and use this in auth....but don't bother, it won't work. Secondly, using the WM 5 devices' web browser to enrol a personal certificate on the CA will also not work. The browser just can't support the ActiveX controls required.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;A lot of WM5 devices come with enrollers for personal certificates, but most don't seem to cope with custom certificate templates. (DELL wrote one that did thou) So, the only way around this is to go back to the manufacture and ask, or write your own. I opted for writing my own, as the code is available on Microsoft's website. As the enroller also requires a network connection to the CA to get the cert, we had a choice. We could A) Connect it to a pc that can get to the CA through Activesync&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;C) Authenticate the device using WEP or WPA-PSK to a "provisioning" Wi-Fi VLAN that has access to a CA. B) Forget the enroller, copy the cert over manually from a PC or smart card and use a third party utility to install the cert. Your choice should depend on how you're going to deploy the devices. Some management software can also put the cert on the device for you, but once again requires network connectivity. &lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;2. Getting a userid / domain request when EAP-TLS authenticates to IAS.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;When I use EAP-TLS on an XP laptop, the wireless access point passes the request back to the IAS radius server, and uses the username and issuer fields on the certificate to authenticate the connection. The laptop uses doesn't have to do anything.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;On the windows mobile 5 device, the wireless access point passes the request back to the IAS radius server, and then I get a request on the device to enter the username and domain. I enter in these credentials, and away I go. I still don't understand why I have to enter these details when an XP certificate authenticates without interaction&amp;nbsp;using EAP-TLS. This might have been OK, until I roamed to another AP. I get asked for authentication again!!?!! I cannot understand or explain this behaviour, and couldn't fix it. It may be related to the brand of AP, some IAS tweak, but it's not something I could find in the time I had. PEAP-MSCHAPv2 also behaved identically.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;What does all this mean? From my perspective, EAP-TLS is very hard work, with very little information out there for support on WM5 devices.&amp;nbsp;You could always try&amp;nbsp;PEAP-MSCHAPv2, but I still got the authentication box pop up when I roamed.&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;If you've managed to deploy EAP-TLS successfully, please let me know by contacting me through this blog.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;Neil&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://consultingblogs.emc.com/aggbug.aspx?PostID=4330" width="1" height="1"&gt;</description></item><item><title>WiMAX - When will I see it, and what will it do for me?</title><link>http://consultingblogs.emc.com/neilchapman/archive/2006/07/05/4181.aspx</link><pubDate>Wed, 05 Jul 2006 14:04:00 GMT</pubDate><guid isPermaLink="false">e847c0e7-38d9-45c0-b593-56747303e088:4181</guid><dc:creator>neil.chapman</dc:creator><slash:comments>0</slash:comments><comments>http://consultingblogs.emc.com/neilchapman/comments/4181.aspx</comments><wfw:commentRss>http://consultingblogs.emc.com/neilchapman/commentrss.aspx?PostID=4181</wfw:commentRss><description>&lt;P&gt;I've been keeping an eye on WiMAX&amp;nbsp;(IEEE 802.16) and the impact it&amp;nbsp;will have.&amp;nbsp;After reading&amp;nbsp;several articles like "&lt;A href="http://www.theregister.co.uk/2006/07/03/uk-wimax-outlook/"&gt;WiMAX in the UK. Here's why it won't fly&lt;/A&gt;." on the register, I tried to find out more about the&amp;nbsp;technologies' future&amp;nbsp;while attending the European Mobility Summit in London.&lt;/P&gt;
&lt;P&gt;A&amp;nbsp;chap&amp;nbsp;called Tom Foale from &lt;A href="http://www.urbanwimax.co.uk/"&gt;Urban WiMAX &lt;/A&gt;was a dicussion panel speaker. Urban WiMAX will be the first&amp;nbsp;to offer WiMAX business servics in the UK&amp;nbsp;from November.&lt;/P&gt;
&lt;P&gt;Tom gave an honest if bleak picture,&amp;nbsp;citing the many issues his company has had in the UK implementing the technology.&amp;nbsp;This ranged from&amp;nbsp;limited licensed frequency available, to decent WiMAX infrastructure hardware not being produced in a timely fashion. In short, there appeared to be&amp;nbsp;some fairly major quality issues that&amp;nbsp;will take a while to resolve.&lt;/P&gt;
&lt;P&gt;In the UK, we will&amp;nbsp;see Fixed WiMAX (802.16d) first, but won't see Mobile WiMAX (802.16e) working for some time.&amp;nbsp;Based on what I heard at the Mobility summit,&amp;nbsp;&amp;nbsp;mobile WiMAX on laptops won't appear&amp;nbsp;until late 2008, and&amp;nbsp;mobile WiMAX capable devices like smarthones and pocket pcs' possibly won't&amp;nbsp;be around&amp;nbsp;until 2010.&lt;/P&gt;
&lt;P&gt;Mobile WiMAX gives all the regular benifits of high speed broadband, but has the potential to be much more. For the enterprise, one main&amp;nbsp;issue with running&amp;nbsp;VOIP applications on mobile devices has&amp;nbsp;been&amp;nbsp;ensuring QoS&amp;nbsp;when relying on ad-hoc public domain&amp;nbsp;connectivity&amp;nbsp;to the&amp;nbsp;internet.&amp;nbsp;Due to the large geographical range, SLA's around eventual QoS and speed,&amp;nbsp;external and internal VOIP telephony solutions&amp;nbsp;and the cost savings they bring may finally be possible&amp;nbsp;for&amp;nbsp;enterprise business in city locations. This will probably not be a serious offering until 2008/9 however, and&amp;nbsp;trying to compete for business&amp;nbsp;against the traditional&amp;nbsp;network&amp;nbsp;operators won't be easy, especially when they are still trying to claw back revenue from their&amp;nbsp;3G&amp;nbsp;implementations.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In summary, WiMAX Mobile, which&amp;nbsp;has&amp;nbsp;the true&amp;nbsp;benifits of WiMAX&amp;nbsp;opposed to WiMAX Fixed,&amp;nbsp;is still a while off,&amp;nbsp;but has potential. However, I can&amp;nbsp;see&amp;nbsp;the technology&amp;nbsp;taking a long time to be a viable option for many in the enterprise, and the next "big" communication network technology is always just around the corner.&lt;/P&gt;
&lt;P&gt;Neil&lt;/P&gt;
&lt;P&gt;For more info on WiMAX and any definitions of the above, go &lt;A href="http://en.wikipedia.org/wiki/Wimax#Introduction"&gt;here&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;img src="http://consultingblogs.emc.com/aggbug.aspx?PostID=4181" width="1" height="1"&gt;</description></item><item><title>Activesync 4.1 - Activesync will not connect to the device on a USB connection</title><link>http://consultingblogs.emc.com/neilchapman/archive/2006/03/15/3091.aspx</link><pubDate>Wed, 15 Mar 2006 17:16:00 GMT</pubDate><guid isPermaLink="false">e847c0e7-38d9-45c0-b593-56747303e088:3091</guid><dc:creator>neil.chapman</dc:creator><slash:comments>5</slash:comments><comments>http://consultingblogs.emc.com/neilchapman/comments/3091.aspx</comments><wfw:commentRss>http://consultingblogs.emc.com/neilchapman/commentrss.aspx?PostID=3091</wfw:commentRss><description>&lt;P&gt;There is an issue with Activesync 4.1 and Windows XP I've seen a couple of time now, and I'd like to pass on a workaround. &lt;/P&gt;
&lt;P&gt;&lt;U&gt;The Issue&lt;/U&gt;: Activesync doesn't connect to your Windows Mobile device when you plug it in using a USB cable to your PC. You've checked the settings in activesync, they allow a USB connection, and the device is also set up to allow connection to a PC. &lt;/P&gt;
&lt;P&gt;If you look under network connections on your PC, a virtual network connection for the mobile device is created when you connect it with the USB cable. Activesync however, doesn't connect to your device.&lt;/P&gt;
&lt;P&gt;The Microsoft Mobile site then points out that you may have an issue with the Firewall on your pc. You test this by turning off the firewall for a moment, but you still can't connect with Activesync.&lt;/P&gt;
&lt;P&gt;&lt;U&gt;To resolve&lt;/U&gt;: Connect your device, then open network connections on your pc. Find the network connection created when you connected your device with the USB cable. It will be listed under the "LAN or high speed Internet" heading. It will be called "Local Area Connection x" (the x will be replaced by a number), and will usually be the last connection listed. &lt;/P&gt;
&lt;P&gt;Right click on this, and select properties. You should see in the Connect using area "Windows Mobile-based Device" In the box below this titled "This connection uses the following items", you will need to place a tick in all the boxes listed. This will re-bind the network protocols to your connection. Click OK to close the property window.&lt;/P&gt;
&lt;P&gt;From this point on, Activesync will kick into life when you connect your device, and you should only have to do this workaround once.&lt;/P&gt;
&lt;P&gt;Note: the problem will sometimes re-occur if you connect another device, or hard-reset your current one. I have noticed that the issue most likely occurs if you are running VPN software other than than the windows VPN on your pc.&lt;/P&gt;&lt;img src="http://consultingblogs.emc.com/aggbug.aspx?PostID=3091" width="1" height="1"&gt;</description></item><item><title>A better way to view Activesync logs.</title><link>http://consultingblogs.emc.com/neilchapman/archive/2006/02/16/2864.aspx</link><pubDate>Thu, 16 Feb 2006 10:56:00 GMT</pubDate><guid isPermaLink="false">e847c0e7-38d9-45c0-b593-56747303e088:2864</guid><dc:creator>neil.chapman</dc:creator><slash:comments>0</slash:comments><comments>http://consultingblogs.emc.com/neilchapman/comments/2864.aspx</comments><wfw:commentRss>http://consultingblogs.emc.com/neilchapman/commentrss.aspx?PostID=2864</wfw:commentRss><description>&lt;P&gt;I just tried&amp;nbsp;the&amp;nbsp;SQL script for getting a useful view of the activesync logs from here:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/exchange/archive/2006/02/14/419562.aspx"&gt;http://blogs.technet.com/exchange/archive/2006/02/14/419562.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It works well, I used the log parser command to output as CSV:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;LogParser.exe -i:IISW3C -o:CSV file:c:\drv\sql\HitsByUser.sql&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I recommend you try this tool, certainly gives a better picture of Activesync usage.&lt;/P&gt;&lt;img src="http://consultingblogs.emc.com/aggbug.aspx?PostID=2864" width="1" height="1"&gt;</description></item><item><title>Exchange Activesync Web Admin tool issue</title><link>http://consultingblogs.emc.com/neilchapman/archive/2006/02/13/2811.aspx</link><pubDate>Mon, 13 Feb 2006 11:58:00 GMT</pubDate><guid isPermaLink="false">e847c0e7-38d9-45c0-b593-56747303e088:2811</guid><dc:creator>neil.chapman</dc:creator><slash:comments>0</slash:comments><comments>http://consultingblogs.emc.com/neilchapman/comments/2811.aspx</comments><wfw:commentRss>http://consultingblogs.emc.com/neilchapman/commentrss.aspx?PostID=2811</wfw:commentRss><description>&lt;P&gt;&lt;STRONG&gt;Update 19/02/06&lt;/STRONG&gt; - The tool that can be downloaded from &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=e6851d23-d145-4dbf-a2cc-e0b4c6301453&amp;amp;DisplayLang=en"&gt;here&lt;/A&gt;&amp;nbsp;has resolved the domain traversal issue. The install bug with the default web IP needing to be reset to "all unassigned" remains.&lt;/P&gt;
&lt;P&gt;------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;The Exchange Server ActiveSync Web Administration Tool was released on the 7/12/05, to enable remote wipe of AKU2.0 (windows mobile 5 devices with the MSFP) phones and Pocket Pc's.&lt;/P&gt;
&lt;P&gt;If you read the release notes on the download page, you will see the statement:&lt;/P&gt;
&lt;P&gt;"To function properly, the tool must be used in conjunction with Exchange Server 2003 Service Pack 2 and compatible mobile devices. &lt;BR&gt;The current release of the Exchange ActiveSync Web Administration Tool must be installed in the same domain as the user accounts being managed."&lt;/P&gt;
&lt;P&gt;To further explain this, if you are an enterprise who puts mailboxes into a resource domain, and accounts in another resource domain, the tool cannot resolve the user accounts. The tool will only install on an exchange server, and placement of the tool in user accounts domain will still not solve the problem.&lt;/P&gt;
&lt;P&gt;The tool itself is a quick and easy install, which creates a virtual directory in IIS called MobileAdmin. An additional bug sometimes occurs if your default web site is set to use a specific IP address rather than "all unassigned". It will create an additional "default web site" instance. To remedy this, set the IP address of the default web site to "all unassigned", then change back when finished the install.&lt;/P&gt;
&lt;P&gt;An updated version of the Mobile admin tool (06.05.7775) was released on the 2/01/06, which also has the same issues.&lt;/P&gt;
&lt;P&gt;Microsoft has a fix, but you will need to contact them to get it for the moment.&lt;/P&gt;&lt;img src="http://consultingblogs.emc.com/aggbug.aspx?PostID=2811" width="1" height="1"&gt;</description></item><item><title>The Microsoft Mobile Device management Gap</title><link>http://consultingblogs.emc.com/neilchapman/archive/2006/02/07/2766.aspx</link><pubDate>Tue, 07 Feb 2006 16:34:00 GMT</pubDate><guid isPermaLink="false">e847c0e7-38d9-45c0-b593-56747303e088:2766</guid><dc:creator>neil.chapman</dc:creator><slash:comments>0</slash:comments><comments>http://consultingblogs.emc.com/neilchapman/comments/2766.aspx</comments><wfw:commentRss>http://consultingblogs.emc.com/neilchapman/commentrss.aspx?PostID=2766</wfw:commentRss><description>&lt;P&gt;Towards the end of Feb the AKU 2.0/2.2 release of Windows Mobile will be available, which will include the MSFP (Messaging and&amp;nbsp;Security Feature Pack). This gives some management functionality for Windows devices though Exchange 2003 SP2, but only the most important basics. The next version of Microsoft Systems Management Server (SMS) was to add further management features for Windows mobile devices. But there hasn't been much movement on this in some time.&lt;/P&gt;
&lt;P&gt;This leaves me in a position wondering exactly how Microsoft is going forward with their Mobile Device management strategy.&lt;/P&gt;
&lt;P&gt;The contenders:&lt;/P&gt;
&lt;P&gt;1. The next version of SMS. (or a plug in for SMS 2003)&lt;/P&gt;
&lt;P&gt;2. Exchange 12 Mobile Policy features are extended.&lt;/P&gt;
&lt;P&gt;3. A new server product altogether.&lt;/P&gt;
&lt;P&gt;My guess is that we will see a lot more emphasis on mobile management in Exchange 12, but we won't see the SMS offering for some time. This will still leave a gap for a full management solution for Windows devices. Third party vendors will fill this space for a while yet. &lt;/P&gt;
&lt;P&gt;The main problem this leaves is the increase of the TCO of using Windows Mobile devices, as a full in-house management solution will still involve third party software and implementation costs, not to mention increasing the complexity of the project. Device and management bundles are around from the big telecom vendors, but are still sadly lacking in the Windows Mobile device area, especially for Windows Mobile 5.&lt;/P&gt;
&lt;P&gt;Having seen Exchange SP2 in action, I think a main technical challenge across all three is how to integrate the Mobile device management interface into Domain Group Policy/ Active Directory/Existing Desktop Management system. This challenge is not just with Microsoft, but all mobile device management vendors. To achieve this first would be a huge differentiator.&lt;/P&gt;
&lt;P&gt;Watch this space....&lt;BR&gt;&lt;/P&gt;&lt;img src="http://consultingblogs.emc.com/aggbug.aspx?PostID=2766" width="1" height="1"&gt;</description></item><item><title>Exchange SP2 and feature pack issue with ISA 2000. </title><link>http://consultingblogs.emc.com/neilchapman/archive/2005/12/01/2445.aspx</link><pubDate>Thu, 01 Dec 2005 14:00:00 GMT</pubDate><guid isPermaLink="false">e847c0e7-38d9-45c0-b593-56747303e088:2445</guid><dc:creator>neil.chapman</dc:creator><slash:comments>0</slash:comments><comments>http://consultingblogs.emc.com/neilchapman/comments/2445.aspx</comments><wfw:commentRss>http://consultingblogs.emc.com/neilchapman/commentrss.aspx?PostID=2445</wfw:commentRss><description>&lt;P&gt;Thinking about implementing&amp;nbsp;Exchange SP2 with the new AKU 2.0 feature pack windows mobile 5 devices? &lt;/P&gt;
&lt;P&gt;If you use ISA 2000 to reverse proxy your Activesync requests, I've come across an issue where the Exchange server cannot apply the new policies to a WM5 MSFP device.&lt;/P&gt;
&lt;P&gt;In short, ISA 2000 has a bug in the way it deals with the OPTIONS verb, which is important for setting the SP2 management polices on the device when it connects.&lt;/P&gt;
&lt;P&gt;To fix this, you need to do this:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.microsoft.com/Default.aspx?ID=304340"&gt;http://support.microsoft.com/Default.aspx?ID=304340&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Neil&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://consultingblogs.emc.com/aggbug.aspx?PostID=2445" width="1" height="1"&gt;</description></item></channel></rss>
