Jump to content

Recommended Posts

Posted

using the remote aconnectivity analyzer we are getting a succesful with warnings on both the connectivity and autodiscover, the only warning that it is moaning about is the ssl cert, which i belive is a common thing

 

 

when trying to create a migration endpoint mapper within office 365 (EAC) we keep getting an error around "We couldn't detect your server settings. Please enter them. The migration service failed to detect the migration endpoint using the Autodiscover service. Consider using the Exchange Remote Connectivity Analyzer ‎(https://testexchangeconnectivity.com)‎ to diagnose the connectivity issues."

 

however we know that from the test it is working, the RPC ports on the domain controllers are all open and i can telnet internally to them Port 6004, the exchange server which is visible to the world has the correct ports open, i have been on a phone call to sophos (2 Hours) and we are seeing traffic hit the firewall for the server however we cant be sure that its microsoft becasue there is alot but i have been on this website

 

https://docs.microsoft.com/en-us/office365/enterprise/urls-and-ip-address-ranges

 

and added to the already list of growing ip address to our firewall exception list, i have added error detalil that we get from when trying to connect from office 365 to exchange via power shell this is the command we used

 

PS C:\WINDOWS\system32> Test-MigrationServerAvailability -Credentials $pscred -ExchangeOutlookAnywhere -ExchangeServer xxxxx -RPCProxyServer xxxx.xxxx.xxx.sch.uk -Authentication Basic -EmailAddress pupil

test@xxxxx

 

any ideas or suggestions are always welcomed :)

 

its an exchange 2007 server on a w2k3 box

 

RunspaceId : f4923c86-9c82-426f-ac28-73fe889a812f

Result : Failed

Message : We weren't able to connect to the remote server. Please verify that the migration endpoint settings are correct and your certificate is valid, and then try again. Consider using the Exchange Remote

Connectivity Analyzer (https://testexchangeconnectivity.com) to diagnose the connectivity issues.

SupportsCutover : False

ErrorDetail : at Microsoft.Exchange.Migration.MigrationNspiClient.GetNewDSA(ExchangeOutlookAnywhereEndpoint endpoint, String user) at

Microsoft.Exchange.Management.Migration.MigrationService.Endpoint.TestMigrationServerAvailability.InternalProcessExchangeOutlookAnywhere(IMigrationDataProvider

dataProvider)||FailedToDiscoverRpcEndpointTransientException|We weren't able to connect to the remote server. Please verify that the migration endpoint settings are correct and your certificate is valid,

and then try again. Consider using the Exchange Remote Connectivity Analyzer (https://testexchangeconnectivity.com) to diagnose the connectivity issues. --> Error 0x6ba (The RPC server is unavailable) from cli_RfrGetNewDSA EEInfo: ComputerName: EEInfo: ProcessID: 112972 EEInfo: Generation Time: 13/02/2020 16:32:52

 

EEInfo: Generating component: 2 EEInfo: Status: 0x000006BA EEInfo: Detection location:1710 EEInfo: Flags: 0 EEInfo: NumberOfParameters: 1 EEInfo: prm[0]: Long: 0 (0x00000000) EEInfo: ComputerName: EEInfo: ProcessID: 112972 EEInfo: Generation Time: 13/02/2020 16:32:52 EEInfo:Generating component: 13 EEInfo: Status: 0x000006BA EEInfo: Detection location: 1352 EEInfo: Flags: 0 EEInfo: NumberOfParameters: 1 EEInfo: prm[0]: Long: -1073606646 (0xFFFFFFFFC002100A) EEInfo:ComputerName: EEInfo: ProcessID: 112972 EEInfo: Generation Time: 13/02/2020 16:32:52 EEInfo: Generating component: 14

 

EEInfo: Status: 0xC002100A EEInfo: Detection location: 1380 EEInfo: Flags: 0 EEInfo: NumberOfParameters: 2 EEInfo: prm[0]: Long: 12175 (0x00002F8F) EEInfo: prm[1]: UnicodeString: /rpc/rpcproxy.dll?wpexc01.westpark.local:6002 EEInfo: ComputerName: EEInfo: ProcessID: 112972 EEInfo: Generation Time: 13/02/2020 16:32:52 EEInfo: Generating component: 14 EEInfo: Status: 0x00010000 EEInfo: Detection location: 1385 EEInfo: Flags: 0

 

EEInfo: NumberOfParameters: 1 EEInfo: prm[0]: Long: -2147483648 (0xFFFFFFFF80000000) EEInfo: ComputerName: EEInfo: ProcessID: 112972 EEInfo: Generation Time: 13/02/2020 16:32:52 EEInfo: Generating component: 13 EEInfo: Status: 0x0000000E EEInfo: Detection location: 3001 EEInfo: Flags: 0 EEInfo: NumberOfParameters: 1 EEInfo: prm[0]: Long: 12180 (0x00002F94) |ServerUnavailableException: Error 0x6ba (The RPC server is unavailable) fromcli_RfrGetNewDSA

 

EEInfo: ComputerName: EEInfo: ProcessID: 112972 EEInfo: Generation Time: 13/02/2020 16:32:52 EEInfo: Generating component: 2 EEInfo: Status: 0x000006BA EEInfo: Detection location: 1710 EEInfo: Flags: 0 EEInfo: NumberOfParameters: 1 EEInfo: prm[0]: Long: 0 (0x00000000) EEInfo: ComputerName: EEInfo: ProcessID: 112972 EEInfo: Generation Time: 13/02/2020 16:32:52 EEInfo:Generating component: 13 EEInfo: Status: 0x000006BA EEInfo: Detection location: 1352 EEInfo: Flags: 0

 

EEInfo: NumberOfParameters: 1 EEInfo: prm[0]: Long: -1073606646 (0xFFFFFFFFC002100A) EEInfo:ComputerName: EEInfo: ProcessID: 112972 EEInfo: Generation Time: 13/02/2020 16:32:52 EEInfo: Generating component: 14 EEInfo: Status: 0xC002100A EEInfo: Detection location: 1380 EEInfo: Flags: 0 EEInfo: NumberOfParameters: 2 EEInfo: prm[0]: Long: 12175 (0x00002F8F) EEInfo: prm[1]: UnicodeString: /rpc/rpcproxy.dll?wpexc01.westpark.local:6002 EEInfo: ComputerName: EEInfo: ProcessID: 112972

 

EEInfo: Generation Time: 13/02/2020 16:32:52 EEInfo: Generating component: 14 EEInfo: Status: 0x00010000 EEInfo: Detection location: 1385 EEInfo: Flags: 0 EEInfo: NumberOfParameters: 1 EEInfo: prm[0]: Long: -2147483648 (0xFFFFFFFF80000000) EEInfo: ComputerName: EEInfo: ProcessID: 112972 EEInfo: Generation Time: 13/02/2020 16:32:52 EEInfo: Generating component: 13 EEInfo: Status: 0x0000000E EEInfo: Detection location: 3001 EEInfo: Flags: 0 EEInfo: NumberOfParameters: 1 EEInfo: prm[0]: Long: 12180 (0x00002F94) |

TestedEndpoint :

IsValid : True

Identity :

ObjectState : New

Posted

You can just whack in the server name and not have it autodetect.

 

May also be useful to add (say) your home broadband IP for a quick test to see if you can reach https://you.migration.endoiint/ews It must be a commercially recogmised cert and same as domain name

 

 

Are you letting port 443 directly through to exchange or is there something acting as a reverse proxy? If the latter I've seen some devices be too clever for their own good and block traffic as it doesn't look live an average web page.

Posted

sorted get alot of xml scripting however when trying to use the office 365 create end point still get an error...ill keep digging

 

You can just whack in the server name and not have it autodetect.

 

May also be useful to add (say) your home broadband IP for a quick test to see if you can reach https://you.migration.endoiint/ews It must be a commercially recogmised cert and same as domain name

 

 

Are you letting port 443 directly through to exchange or is there something acting as a reverse proxy? If the latter I've seen some devices be too clever for their own good and block traffic as it doesn't look live an average web page.

Posted

Ok, so that's positive as it implies we have connected thru to the webserver

 

In in Exchange admin centre in O365, Recipients the Migration, Three dots, Migration Endpoints + then exchange remote, the rest should be obvious - what happens?

Posted
Well it moans about being unable to connect and also moans about the ssl cert but I think that is a common error the exchange test connectivity report says passes so it should connect not sure what could be stopping the connection
Posted
Well the problem is that it still passes Adjustments.JPG

 

I’ve attached part of the rca report see what you make of it

 

We have successfully done an imap migration of a mailbox however in the test mailbox there was only 1 email that was sent to this mailbox ( newly created) and after migration we had 35 emails in this office 365 mailbox ??

 

The ssl is a san cert

Posted

So you've got

 

autodiscover.blah.sch.uk and something.blah.sch.uk in the san cert. What are you setting as the migration end point in O365 and what is the EWS external URL set to on prem ?

 

(also assume you have MRS enabled?)

Posted
So you've got

 

autodiscover.blah.sch.uk and something.blah.sch.uk in the san cert. What are you setting as the migration end point in O365 and what is the EWS external URL set to on prem ?

 

(also assume you have MRS enabled?)

 

I don’t how but somehow I knew you was going to say that as I came across this article last night thinking how does the endpoint migration actually work and I was reading this

 

 

https://docs.microsoft.com/en-us/exchange/architecture/mailbox-servers/mrs-proxy-endpoint?view=exchserver-2019

 

 

Now the only problem is that I don’t have a servers tab in my office 365 eac

Adjustments.JPG

Posted

The EWS external URL setting and MRS enablement setting are done on prem, where you do have a server tab in EA​ Scrub that, just noticed you have Exchange 2007

 

It's been almost a decade since I've touched Exchange 2007, but I recall you cannot setup hybrid direct to it, you need to have a Exchange 2013 box as the middleman

Posted

in our Office 365 admin center i can see all of my users that have been synced via Azure AD connect

 

however forsome reason we have had only a handfull around 136 mailboxes that have been created.

 

now we have alot more user accounts than that and we have been assigneing the licence however they not showing, i have tried moving the license and adding it back but it doesnt make any difference not sure what to make of it any suggestion?

Posted

The fact you can see 136 mailboxes is not a good thing, but be thankful it's only 136.

 

If you have not migrated any users, then All your users should appear in the O365 ECP as mail users in the contact pane. O365 knows they have a mailbox on premise because of a number of Exchange attributes in AD, thus will not create a mailbox in O365, license or no license.

 

If you are seeing users in the mailbox pane of O365 and they have a mailbox on prem, they now have two mailboxes.

Posted
The fact you can see 136 mailboxes is not a good thing, but be thankful it's only 136.

 

If you have not migrated any users, then All your users should appear in the O365 ECP as mail users in the contact pane. O365 knows they have a mailbox on premise because of a number of Exchange attributes in AD, thus will not create a mailbox in O365, license or no license.

 

If you are seeing users in the mailbox pane of O365 and they have a mailbox on prem, they now have two mailboxes.

 

ok....

 

does it matter they have an on prem and an mailbox within office 365,

 

would it be better from a migration point of view to remove the mailboxes that it has already created ? so which would stop any duplication / errors

 

we use salamander to create our user accounts for staff and pupils and we have noticed that when a member of staff joins it creates the mailbox within office 365 eac (mailbox tab) but not for pupils (i guess this is good thing lol from what your saying)

 

i was under the impresion that when a user account is within the office 365 admin center where you assing licence to use the office products when you enable the exchange online it should create a mailbox but based on what your saying about office 365 knowing that it has an on prem mailbox that feature does work in essance so the function is useless, till we migrate the accounts from on prem into cloud.

 

so if the mailboxes need to be remove moved how do i remove them https://docs.microsoft.com/en-us/powershell/module/exchange/mailboxes/remove-mailbox?view=exchange-ps ??

Posted

Having two mailboxes is a bad thing because people in O365 will send to the cloud mailbox and people on prem will send to the on-prem account - create a cloud mailbox direct in the tenant to test. You cannot migrate an on-prem mailbox where one exists.

 

Sorting it out is a little more complex, but at least now there is a command - https://docs.microsoft.com/en-gb/archive/blogs/timmcmic/office-365-correcting-users-who-have-had-a-mailbox-in-the-cloud-and-on-premises

 

 

 

What is your strategy going forward? My recommendation would be no hybrid, keep an Exchange server on premise, all mailboxes in the cloud. This removes a whole pile of directory and autodiscover complexity and get you to the 'add a license, get a mailbox' position.

 

Once the end game is settled, it's then a case of figuring out the interim model, but as it stands this would be hybrid to Exchange 2013, then using that to move mailboxes to the cloud, and provisioning is as-is till all across (plus figuring out why staff don't have exchange mailboxes created on premise instantly).

 

Alternatively you could consider no hybrid and use third party tooling to get the data across. Coexistance will be messier and you'd want to it do over a shorter period of time.

Posted (edited)
Having two mailboxes is a bad thing because people in O365 will send to the cloud mailbox and people on prem will send to the on-prem account - create a cloud mailbox direct in the tenant to test. You cannot migrate an on-prem mailbox where one exists.

 

the users that are in the EAC (mailbox tab) these mailbox are not in use and nor does the users associated with the mailbox know that they exist, i am going to check before i remove the exchange online licence,

 

i have built my new server to install exchange 2013 just finalizsing the pre-reqs for i start on AD side of things, i was speaking with virtue technology and they said that the office 365 hybrid tool would be the best way to go

 

 

thoughts ?

Edited by kevin_lane
Posted
Hybrid Configuration Wizard? Yes, that's the sensible route to a fullly fledged hybrid. There is a simpler 'agent' solution now that provides less functionality but is easier to setup, but I've never used in anger so cannot vouch for it.
Posted
thanks for getting back - apperciate your help , so i've installed exchange 2013 , and everything has gone through fine got no errors or any warnings, however when i went to open EAC on the new server i cant login and im doing some research and people are saying this something to do with a setting in adsi edit !! surely that cant be right is this a common issue ? do you know i get a http 500 error will keep looking
Posted
Nothing immediately comes to mind... other than ensuring your url end [h=1]ecp/?ExchClientVer=15[/h]Otherwises, I'd be resorting to google-fu with the error logs too :D

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...