All, please refer to this link for all the above issues:
http://blogs.technet.com/scmdm/archive/2008/08/19/troubleshooting-device-connection-to-the-device-management-server.aspxFollow the guidance there _after_ you've run BPA (
http://technet.microsoft.com/en-us/scmdm/cc304591.aspx), have verified that there are no routing issues (esp to/from the VPN Pool to the subnet where the DM is located), and that the correct firewall ports are open.
Oh yeah, and don't forget to read the copious and extremely useful info in the doc library (Planning Guide, Deployment Guide, Firewalls, Globals. Link here:
http://technet.microsoft.com/en-us/library/cc135653.aspx).
This info is referenced in a number of threads, but I'm posting it on its own so it's easier for people to find.
best, Pat.
Mobility Architect, Enterprise Mobile