Saturday, November 14, 2009

Exchange Server 2010: Previous exchange server Coexistence

Exchange server 2010 have the option for coexisting with the previous version of Exchange server 2003 and 2007 in the same forest. It is not possible to have exchange 2000 or exchange 5.5 with the exchange 2010 in the same exchange organization. Integrating Exchange server 2010 into the existing exchange 2003 or 2007 is called the transition scenario, where as new deployment of exchange server 2003 in new active directory forest and then transferring/migrating the records across the forest is called migration scenario.

Hope the above is informative.

Thanks
Logan
971552596187

Message Routing in Exchange 2007 vs. Exchange 2003 Multisite Environment:

The message routing architecture in multi site environment is always an interesting one to explore. We all know the role of routing groups and also routing group connector in exchange2003, this has been revised in fact completely modified in exchange 2007. Routing group and connectors concept has been removed in the exchange 2003. Lets us consider the below scenario for example,

Site1 – Amsterdam Main Office – subnet 10.10.0.0/16

Site2 – Auckland Branch Office – subnet 10.11.0.0/16

We can domain controller in both sites for user authentication and other domain info. We can also have DNS in both sites. So with the help of the site link (WAN link), we will be able to enable the replication b/w the sites. Now, coming to the messaging part, we have only option to use the routing group and connector for message transport b/w the sites. Since active directory sites and Exchange server routing groups are independent one, i.e. not compatible with each other.

Exchange 2007 has the new feature that Hub transport server role has been built in a manner that it will use the active directory sites for the message routing. In this case, transport hub server in Amsterdam will use the active directory site link to route the message to the hub transport server in Auckland and vice versa.

I end up here; you people can explore more in this for more detail. Hope the above is informative.

Thanks
Logan
9841499143 | Logu_microsoft@hotmail.com


Wednesday, November 4, 2009

Exchange server 2010’s new features:

Hope, everyone are excited and waiting for the release of the exchange 2010. The below are some of the new features of the exchange 2010. I tried to put in simpler terms and have not described in detail, the idea is to have an overview of the exchange 2010 product. I have covered only the few important and major changes, apart from this there are still many other changes have been done. Please visit Microsoft site for more details.

1. DAG – Database Availability Group.
2. Improved Outlook Web Access called as outlook web app which has features like search options, favorites, attaching message to message, etc.
3. Edit option for user properties like username, telephone number in OWA.
4. ECP called Exchange control panel for organization level changes like user, group and distribution list creation/changes.
5. No More LCR and SCR clustering technology of exchange 2007 are removed and replaced by new Database Availability group.
6. Server Cluster failover technique also removed because still the so many system administrator are not comfortable in doing it. The Microsoft has come up with the effective and ease alternative for this.
7. No more storage groups term available in exchange 2010, so only database is the predominant one and other database files, transaction log and database type(JET) are same as of the exchange 2007.
8. SIS – Single Instance Storage is no longer available in exchange, means that traditional model has been changed. I.e. when you send a mail of 1 MB to 10 different recipients, the db potentially grows 10 MB. So obviously consumes for storage requirement but the performance on the database I/O has been improved drastically.
9. Database page file size has been increased from 4KB to 8KB, improving the I/O on the disk file system.
10. No more 32 bit processor support for testing also.
11. Microsoft is also gradually moving to the cloud technology. Microsoft Online Services helps to host the mailbox also. It can be 100% hosted or 100% in premise or can be also mixed environment.
12. Powershell V2 more powerful, also has a new feature called IDE Interactive Development Environment using which you can built a script and also run the output with the small output window. The option for remote management of exchange is also possible with Windows Remote Management, which is included with the Powershell V2.
13. Send mail GUI option available in the EMC for testing mail flow.
14. Active Directory Rights Management enables to have the control of the message after sending to the recipients like disabling the forward option of the confidential messages.
15. Cross premises routing is possible.
16. Enhanced disclaimer with HTML code, pictures, hyperlinks, etc is available.
17. In exchange 2007, after delivering the message from hub transport server to next hop, it will be deleted. The same in exchange 2010, the message will be deleted only after the successful receipt of the message from the next hop, in case of non-receipt, it will try to redeliver the message. This type reliable routing model is called as Shadow Redundancy Routing Model.
18. Role Based Access Model for implementing the permission for the administrative accounts.
19. Personnel archive folder option or can be called as Archive PST with all live mailbox.
20. Improved Unified messaging roles with some exciting new features like Voicemail preview, integration with SMS test message, additional language support, etc.

Hope the above is informative.

Thanks

Logan

Logu_microsoft@hotmail.com | 971552596187




Sunday, October 25, 2009

Configuring LCR – Local Continuous Replication:

Hi friends,

This article briefs the configuring LCR in the exchange 2007 server. As it name implies, the local continuous replication is the new feature in the exchange 2007 and it has the local copy of the database just like a mirror. Either you can do either in GUI or powershell, here I have explained in the powershell

Design the structure first, for example will have the below for our configuration,

SG1 – storage group name, SG1DB1 – database

Source system path (disk1): c:\SG1

Source log path (disk1): c:\SG1\log

Source edb path (disk1): c:\SG1\DB

Destination system path (disk2): D:\SG1LCR

Destination system path (disk2): D:\SG1LCR\log

Destination system path (disk2): D:\SG1LCR\DB

1. Enabling Database copy,

#Enable-DatabaseCopy –identity ‘servername\sg1\sg1db1’ –CopyEdbFilePath ‘D:\SG1LCR\DB\SG1DB1.edb’

2. Enabling Storage group copy,

#Enable-StorageGroupCopy –identity sg1 –CopyLogFolderPath ‘D:\SG1LCR\log’ -CopySystemFolderPath ‘D:\SG1LCR\DB’

3. To check the status of the replication,

#Get-StorageGroupCopyStatus

The LCR Configuration has been completed now; you can check the logs which are copied from the source to the destination and also any new generated logs will automatically seed to the destination location as we defined above.

Restore from the LCR copy:

Let us assume that if something goes wrong with the source database, we are in a position to restore from the replica. So, let’s see how to do the restore,

1. Dismount the database - #dismount-database sg1db1

2. Restore from replica - #Restore-StorageGroupCopy –identity ‘servername\sg1’

3. Mount the database back - #mount-database sg1db1

4. Now, the point to be noted is old LCR configuration of SG1DB1 is no more enabled. Please enable the LCR for this Storage group again and also clear the old logs so that it will start seeding from the source from the first.

Hope the above is useful.

Thanks

Logan

971-552596187 logu_microsoft@hotmail.com

Difference types of Mailbox in Exchange 2007:

Unlike previous version of exchange, the general mailbox has been classified into four types. But there are few difference b/w each type.

1. User Mailbox – for traditional user mailbox.

2. Room Mailbox – for meeting rooms

3. Equipment Mailbox – for equipments like projector, TV, etc. It is just like creating AD accounts for such objects.

4. Linked Mailbox – Hosting mailbox for users in separate forest.

In the above, the core mailbox attributes are same except few are different.

1. Basic notification GUI symbol is different for each object.

2. Resource mailbox (i.e., both room and equipment mailbox) are by default will be in the disabled state.

3. In OWA à Options, we have the “resource setting” only for the resource mailbox.

4. In creating a calendar meeting either in outlook or OWA, we have the scheduling assistant for configuring the meeting in which, “Select room” option will there and will list the entire room mailbox available in the organisation.

5. Also while adding attendees in the address bar, in the address book window; we will have the classified option as “default global address list” and “All rooms”. The latter is specifically designed to list the room mailbox alone.

6. On the attribute side, Isresource attribute of a mailbox will be set as “True” for the resource mailbox and “False ” for the user mailbox. The attribute resourcetype attribute will be set as “room” and “equipment” respectively.

Useful Powershell command:

To get the resource mailbox,

#get-mailbox where-object { $_.isresource –eq ‘true’ }

To get the resource mailbox related attribute,

#get-mailbox where-object { $_.isresource –eq ‘true’ } fl res*

To convert user mailbox to resource mailbox

#set-mailbox mailboxname –type room

Hope the above is useful.

Thanks

Logan

971-552596187 logu_microsoft@hotmail.com

Exchange server 2007 Services.

This article explains the different type of services, its description. Since exchange 2007 has so many new features, changes and different mailing architecture when compared to earlier exchange versions. We know that exchange server 2007 has five different server roles which has its specific services. In this article, I am going to concentrate only on the exchange specific services, though there are many dependent services like WWW, RPC, WMI and etc.

Common Services on all Server roles:

The below services are present in all five server roles,

1. Microsoft Exchange Active Directory Topology Service: This is the core exchange services which communicate with AD often. This service uses DSACCESS component for accessing the active directory. Since, AD tightly integrated with Exchange, all server roles will have this service up running.
2. Microsoft Exchange Monitoring Service: This service is responsible for collecting all kind of diagnostic logs from the exchange application.

Services in Mailbox server role:

1. Microsoft Exchange information store: This is the service related to core exchange databases. It is the main services in the Mailbox server role and this is services is not dependent to other exchange services.
2. Microsoft Exchange Mail Submission: This service maintains the mail queue for transferring mails from mailbox server to hub transport server. Used to notify a Hub Transport server located in the Mailbox server's Active Directory site that messages are ready for retrieval from a sender's outbox. This service is also responsible for relaying and other tasks like Transport rules, Message Records Management etc.
3. Microsoft Exchange mailbox assistants: Provides functionality for Calendar Attendant, Resource Booking Attendant, Out of Office Assistant, and Managed Folder Mailbox Assistant.
4. Microsoft Exchange Replication Service: This service responsible for the replication of database information in the LCR and SCR cluster environment. This does the log shipping/seeding b/w the cluster peers.
5. Microsoft Exchange Search Indexer: This service is responsible for indexing the mail content in the database which in turn helps in improving the faster access/searching of the mail contents.
6. Microsoft Exchange Service Host: Configures the RPC virtual directory in Internet Information Services (IIS), and registry data for Valid Ports, NSPI Interface Protocol Sequences, and Allow Anonymous for Outlook Anywhere. It basically acts as a host for holding exchange related services like IIS.
7. Microsoft Exchange System Attendant: This service is responsible for following components. It provides maintaining, monitoring and directory lookup services functionality.
• DSAccess (DSAccess.dll) – Provides Exchange Active Directory Access
• DSProxy (DSProxy.dll) – Provides Directory Service Lookup for older Outlook clients
• Server Monitor Component - Monitoring server resources
• Mailbox Manager Component - Managing mailboxes
• Metabase update service - Replicating settings from Active Directory to the IIS metabase
• System Attendant Component - Verifies computer account configuration
8. Microsoft Exchange Transport Log Search: Provides message tracking and transport log searching. It is basically used for querying of transport log remotely.
9. Microsoft Search (Exchange): Provides full-text indexing of mailbox data content. This is a Microsoft Exchange-customized version of Microsoft Search.

Services in CAS Servers:

1. Microsoft Exchange File Distribution: Used to distribute offline address book and custom Unified Messaging prompts.
2. Microsoft Exchange IMAP4: Responsible for Internet Message Access Protocol IMAP4 Clients connections.
3. Microsoft Exchange POP3: Responsible for Post Office Protocol POP3 Client connections.
4. Microsoft Exchange Service Host: Configures the RPC virtual directory in Internet Information Services (IIS), and registry data for Valid Ports, NSPI Interface Protocol Sequences, and Allow Anonymous for Outlook Anywhere. It basically acts as a host for holding exchange related services like IIS.

Services in Hub transport Servers:

1. Microsoft Exchange Anti-Spam Update: Used to automatically download anti-spam filter updates from Microsoft Update.
2. Microsoft Exchange Edgesync: Connects to ADAM instance on subscribed Edge Transport servers over secure Lightweight Directory Access Protocol (LDAP) channel to synchronize data between a Hub Transport server and an Edge Transport server.
3. Microsoft Exchange Transport: This is the new SMTP service in exchange 2007, which don’t rely on Windows server SMTP services as like in previous version of the exchange. It is the core transport stacks which process the routing of messages.
4. Microsoft Exchange Transport Log Search: Provides message tracking and transport log searching. It is basically used for querying of transport log remotely.

Services in Edge Transport Servers:

1. Microsoft Exchange ADAM: Connects to ADAM instance on subscribed Edge Transport servers over secure Lightweight Directory Access Protocol (LDAP) channel to synchronize data between a Hub Transport server and an Edge Transport server.
2. Microsoft Exchange Anti-Spam Update: Used to automatically download anti-spam filter updates from Microsoft Update.
3. Microsoft Exchange Credential Service: Monitors credential changes in ADAM and installs the changes on the Edge Transport server.
4. Microsoft Exchange Transport: This is the new SMTP service in exchange 2007, which don’t rely on Windows server SMTP services as like in previous version of the exchange. It is the core transport stacks which process the routing of messages.
5. Microsoft Exchange Transport Log Search: Provides message tracking and transport log searching. It is basically used for querying of transport log remotely.

Services in Unified Messaging Servers:

1. Microsoft Exchange Unified Messaging: Provides Unified Messaging features, such as the storing of inbound faxes and voice mail messages in a user's mailbox, and access to that mailbox via Outlook Voice Access.
2. Microsoft Exchange Speech Engine: Provides speech processing services for Unified Messaging.

Hope the above is informative.

Thanks
Logan

971-552596187 logu_microsoft@hotmail.com

Types of clustering in exchange 2007:

This article explains the different types of clustering technology available with the exchange 2007 server. The exchange 2007 version has some new exciting features in terms of the high availability. It has four types of clustering and which has its own level of fault tolerance and availability. I have also added the diagram for better understanding.

1. Single copy clusters(SCC):

# This cluster type is similar to the one as in previous exchange versions. In fact it is exactly similar to the one in exchange 2003.

# Uses a single copy of database is shared between the nodes of the cluster.

# The database copy is stored in the SAN Storage device and also at any point of time the database will be owned by single node.

# Fault tolerance – There is chance of SOP i.e., Single point of failure. SCC environment works great if a node/server fails, but still Database failure in the SAN will cause the damage.




2. Local Continuous Replication (LCR):

# This is the new feature of exchange 2007.

# LCR is a single server solution which creates and maintains a copy of the database in the same server just like a mirroring concept.

# This cluster type provides usual log shipping, log replaying and can be switched to the mirror copy by manual action in case of any database issues.

# One prerequisite for implementing LCR is that Storage Group can contain only one database. So if you need to implement multiple databases you automatically need to implement multiple Storage Groups.

# This overcomes the drawbacks of single point of failure for database crashes, but it doesn’t help in server failure.

# Automatic failover will not happen, in case of database failure or any issue.


3.Cluster Continuous Replication (CCR):

# This is the new feature of exchange 2007. It is the best and highly improved version of clustering solution

# This cluster type is non-shared one, fault tolerant in terms of server and database front, high availability and site resilience. CCR is very different from clustering in previous exchange versions.

# CCR is a multi server solution which creates and maintains a copy of the database in the second servers in a failover cluster.

# CCR will automatically failover in case of any server related issues and also database related failures. So no need of manual switch action as in LCR.


4. Standby Continuous replication (SCR):

# This is the new feature introduced in exchange 2007 SP1.

# SCR is a clustered solution that is used to have the standby copies of the clustered server databases. As by its name, we can call as standby recovery servers.

# SCR uses the same log shipping and replay technology used by LCR and CCR. It is just getting seeded by and from either CCR or LCR cluster server.

# This is ideal for the situation like you need to recover from the complete site failure. We can call this for disaster recovery.


Hope the above is informative.

Thanks

Logan

971-552596187 logu_microsoft@hotmail.com

Wednesday, September 30, 2009

Recipient limit feature in exchange server 2003 and 2007

This article explains the working of recipient limit feature in both exchange 2003 and 2007 server versions. Many people will have a questions on how the distribution list recipient is counted ?, in fact there is change in the working of recipient limits in exchange 2007 compared to the older exchange 2003 version.

In Exchange 2003:
In processing of email message, the recipient limits are applied after the expansion of the recipients. The expansion is nothing but the designated expansion server will expand all group lists, it will have the individual and non-duplicated recipient entries. So, if a user is having a recipient cap set to 50, when a user try to send a mail to a distribution list of 60 members, the result only the first 50 users of the expanded list will receive the mail, for the rest it will through the respective NDR.

In Exchange 2007:
But, in exchange 2007, the recipient limits are applied in the hub transport server role before the expansion of the recipient limits. In simpler words, expanded DL members are not counted in turn it will be counted as a single recipient. So, if a user is having a recipient cap set to 50, when a user try to send a mail to a distribution list of 60 members, the result all the users will be able to receive the mails henceforth it just count DL as a single recipient.

Hope the above is informative

Thanks
Logan
971-552596187
Logu_microsoft@hotmail.com

Saturday, August 22, 2009

Deploying Edge Transport Server Role:

This article gives you the step by step procedure for installing the Microsoft exchange server 2007 – edge server role and configuring the connection with the hub transport server. As we now, edge server role is used as the front end security wall with antispam and antivirus protections and not parted of domain, which is basically hosted in the DMZ zone.

1. Basic server check-up likes recommended hardware resources and server 2003/2008 OS, latest SP and appropriate patches.

2. N/w Card configuration – Two NIC cards, one for public/external and the other for private/internal.

3. Check the Name resolution between hub transport and the edge server. Also configure the edge server for the external name resolution.

Set-TransportServer -Identity ExEdge01 –ExternalDNSAdapterEnabled $false –ExternalDNSServers

Note : If the name resolution b/w hub and edge server doesn’t work, then the edge synchronisation fails.

4. Installing ADAM SP1 : Active Directory Application Mode SP1 is the one which acts as a tunnel passage for passing the limited AD related i.,e Domain related information from Hub transport server to the edge server.

5. Install Core edge exe : Run the setup.exe from the exchange installation disk, go for the custom type installation, select the edge server and complete the installation.

6. Check the Edge related configuration EMC, will find option like antispam, accepted domains and others, I will leave this up to you for exploring.

7. Since Exchange 2007 rollup 4 has some important updates, install the rollup 4 package also.

8. Restart the edge server after completing the above and run the command “test-servicehealth” to check all edge related services are up and running.

9. Ports to be opened : Edge server used custom ports for communication with the hub server. If firewall is placed in b/w hub server and edge server, the following ports have to be opened.

• LDAP 50389/tcp
• Secure LDAP 50636/tcp
• SMTP 25/tcp
• RDP 3389/tcp (optional)

10. Creating the edge subscription file in Edge server,

New-EdgeSubscription -FileName "C:\EdgeSubscriptionInfo.xml"

11. Copy the xml file to the Hub server.

12. Mapping the edge subscription file in Hub Server,

New-EdgeSubscription -filename "C:\EdgeSubscriptionInfo.xml" -CreateInternetSendConnector $true -site "Default-First-Site-Name"

13. By Default, the edge synchronisation happens at four hour intervals. For immediate sync,

Start-EdgeSynchronization

14. Edge server is ready, just verify connectors in Edge EMC console, will show the current hub server related connectors.

Hope the above is informative.

Thanks
Logan
Logu_microsoft@hotmail.com | 971552596187

Monday, August 17, 2009

Logon Event 528 Log:

This article explains about finding the user logon details using the normal event log and also how to interpret to event log details. In server side, environment it is always wise to have the user logon and logoff audits. If you check for the event log 528 under the security logs, you will find some of the positive hits. The typical 528 log entry will have the below information,

  • user name
  • domain
  • logon id
  • logon type
  • logon process
  • authenication package
  • workstation name


In Particular, logon type is the one which needs to be paid attention.

2

Interactive

User logged on to the computer's console.

3

Network

User logged on to the computer over the network (e.g., through a drive mapping). Note: On Win2K and later systems, event ID 528 doesn't log this logon type; for network logons, Win2K and later OS versions log event ID 540 with logon type 3.

4

Batch

Batch logon (commonly logged when a COM+ server component starts up).

5

Service

Service logon (required by user accounts configured as account for services).

7

Unlock

Workstation unlocked.

8

NetworkCleartext

Network logon, but with a clear-text password. By default, Windows doesn't allow clear-text password logons unless you explicitly enable them. (However, all versions of Microsoft IIS use clear-text passwords for Basic authentication.)

9

NewCredentials

User used alternative credentials to connect to a resource on the network or used the RunAs command to start programs under a different user account.

10

RemoteInteractive

User logged on to the computer remotely using Terminal Services or Remote Desktop.

11

CachedInteractive

Domain user logged on with cached credentials. Usually logged when a traveling user logs on to a notebook with his or her domain account but no domain controller (DC) is available. Note that event ID 537, not event ID 528, logs this event.

Using the above, we can find the exact mode of logon and also the user details.

Hope the above is useful.

Thanks

Logan

Logu_microsoft@hotmail.com | 971552596187