Jump to content

Recommended Posts

Posted

Im running exchange 2010 standard and my plan for the near futrue is to add a second install of 2010 just for redundancy.

 

Is it pretty straight forward, anything I need to watch out for?

 

cheers

Posted

Depends how you are going to make them redundant really. As far as I know you can only have the mail boxes on one server.

 

Far better to virtualize the thing imo and take image backups as well as db's for redundancy.

  • 7 months later...
Posted

Ok well it seems now is the "near futrue"..

 

Exchange 2010 (non-SP1) is currently a Virtualbox VM sitting on a Linux Host.

 

Now I have a proper HyperV host, my plan is this:

 

Create a 2010 SP1 Exchange install, use the built in tool to move the exchange database store over to the new install, and use Systems Center Data Protection Manager to look after the backups of Exchange and the VMs (havent really looked into scdpm yet)

 

Does this sound an ok plan?

 

Should I leave the old Exchange VM running, for clustering or something?

Posted

I have 2 servers runing a DAG for redudancy and a front end server for OWA which are all VM's (hyper-v) was very easy to setup.

 

I used the ebook - Exchange 2010 A Practical Approach by Jaap Wesselius which got me started.

Posted
Im running exchange 2010 standard and my plan for the near futrue is to add a second install of 2010 just for redundancy.

Do you really need redundancy for emails? Some people think that they are running a corporate HQ rather than a school. Mind you, I see you are in Sydney so maybe your country is not broke like ours so doesn't have the bank manager or LEA breathing down your neck wanting justification for every expense.

 

A decent backup strategy and something (external service) to buffer incoming emails during outage should IMHO suffice. The only thing we have redundancy for is AD DC and some file shares to allow the classes to keep running. The rest the school is happy to wait on until it is fixed and recovered, probably next day. We only have two physical servers in the school. Cannot justify more.

Posted

All the virtual machines are in a hyper-v cluster so can be anything from one to three hosts, though I do keep them on a min of 2 separate hosts.

 

IMHO, any outage of a service is unacceptable be it for a sole trader working from his home computer to a large corp. Why should a school expect anything less regardless of the economic climate?

Posted (edited)
IMHO, any outage of a service is unacceptable be it for a sole trader working from his home computer to a large corp. Why should a school expect anything less regardless of the economic climate?

Buts its not your opinion that counts. Its your responsibility to identify (the mail server failing) and report the risk, but SMT decision on how to respond to the risk. They may want to avoid it, but they may just accept it too - its their decision based upon their business case.

 

In our school we have accepted some of the risks, but for other we have fallback and for a few we have steps to avoid the risk altogether. We do not see email as being mission critical. Our fallback plan is to use an alternative email solution whilst the server is offline - just a matter of switching over the DNS at the domain provider to provide online email service which takes minutes to propogate. All our emails are backed up within the school and before they reach the school so none should ever be lost so there is no lasting impact. The solution we implemented covers a number of risks, such as broadband/firewall/router failures etc etc, so its cost is justified over many different risk scenarios.

 

A significant part of my remit is to propose cost effective solutions. I have halved the schools IT spend and they are no worse off for it. The children certainly don't care how the system works as long as it does, most of the SMT don't know any different, the bursar and trustees are very happy and most importantly, the bank manager and accountant are happy as they can see that we are keeping budgets well under control and we can justify every penny spent on IT.

Edited by ianh64
Posted
Do you really need redundancy for emails? Some people think that they are running a corporate HQ rather than a school. Mind you, I see you are in Sydney so maybe your country is not broke like ours so doesn't have the bank manager or LEA breathing down your neck wanting justification for every expense.

 

My school here is a private school, and a fairly large one at that. As such, and with students paying in excess of $20k a year each, it is run as a "corporate HQ" as that is exactly what it is. Email is as mission critical here as it would be anywhere in the corporate world..

 

IMHO, any outage of a service is unacceptable be it for a sole trader working from his home computer to a large corp. Why should a school expect anything less regardless of the economic climate?

 

Exactly!

 

Buts its not your opinion that counts.

 

We are the IT department. We get given our budget to run everthing IT related. Once the money is approved, of course our opinion counts. We make the decisions, and if stuff goes titsup, its us on the line

 

We only have two physical servers in the school

 

Well obviously if you are a small primary school with a couple of years and a couple of students, with hardly any money, they your hands are tied. Why not look at something like live@edu which would suite your scenario perfectly?

 

 

 

As an aside, the purpose of my thread is not related to my school in any way, it is a seperate organisation that I also do work for.

 

Im looking into DPM 2010 to do the backups of the exchange, but would like to have Exchange accessible immediately if VIrtualbox host went down.

Posted
DPM is very good for Exchange backups, we use it for recovery on a per e-mails basis if needed, also DPM does live snapshots of the whole hyper-v VM for disaster recovery. Not sure on backup options for Virtual Box though I’m afraid, just make sure it has VSS support for exchange if you’re doing live backups. Don’t want to corrupt your databases.
  • 2 weeks later...
Posted

Hi

 

Depends if you plan to use DAG, if so on a virtual machine or physical. If you want HA for your mailboxes then you can either use Exchange 2010 DAG or implement HA at the virtual layer. Be careful not to have DAG on VM's if you are also using VM HA on the root servers. This is NOT supported by MFST and can lead to DB corruption.

 

From MSFT Exchange 2010 System Requirements: Exchange 2010 SP1 Help

 

"DAGs are supported in hardware virtualization environments provided that the virtualization environment doesn't employ clustered root servers, or the clustered root servers have been configured to never failover or automatically move mailbox servers that are members of a DAG to another root server"

 

There are catches too but the main one which I have come across is where Exchange is using DAG on VM's. this has vcaused issues.

 

Regards

Sukh

  • Thanks 1
Posted

OK so DAG will not be an option at the moment, because the existing server Exchange is on is only 2008R2 Standard, not enterprise, and so doenst include the failover cluster stuff..

 

Ive installed a new instance of Exchange 2010 with all the roles onto 2008R2 Enterprise, what do I need to do to move evertything onto this new server so I can wipe the old 2008R2 Standard and re-install with Enterprise?

Posted (edited)

Hi,

 

What have you got configured on your existing Exchange server?

Do you have CAS setup? OWA/Outlook Anywhere/OMA/EAS/Archiving

How many databases do you have?

Do you have any aliases for OWA? Internal/External

Did you change an default settings when you installed existing Exchange server?

 

Also, am wondering if it may just be better to uninstall Exchange and upgrade the OS rather reinstalling the OS. Will save you time, however you can't do this with Exchange installed.

 

Regards

Sukh

Edited by sukh
Posted

Existing one does everything and is setup for external OWA, Outlook anywhere, mobile phone, etc.. it does everytinig exept for Unified Messanging. It has 1 database.

 

I have used the Move mailbox command to move the mailboxes to the new server's database, and all seems to be working OK.

 

So I guess I just need to go thru all the settings and make sure they match the old one, and then update the firewall to point to the new IP, and then re-import the certificate.

 

Reinstalling the OS only takes a couple of minutes. Plus it will let me go straight to SP1 of 2008R2.

Posted

Hi

 

Make sure you have set-up CAS roles correctly on your new server, to include certificates and also your external A/SRV records too.

 

Regards

Sukh

  • 3 weeks later...
Posted

HAving a think a bit further, and again remembering this is just test setups with only 1 or 2 mailboxes..

 

Would the following work?

 

At the moment Exchange sits in scotland, the Client Access from the Internet goes to it. If I were to add a second exchange box here in australia, and VPN the two, and create a DAG via the VPN, could I then setup the client access from the internet to go to either exchange? Have mail.mydomain.com resolve to 2 IPs, both of which will process the mail, but will store it in the DAG which is available in both countries? Also means I can have a mx1. and a mx2 right?

 

What would be the best to method to have the 2 sites VPN'd together?dag.png

Posted

Good to see convo's like this pop up, in the last 7 years I have seen email get used from 10 staff to every staff member and every student. If email goes down for 2 minutes everyone will realise they can not live without it so I am glad to see convo's like this pop up and give me some ideas.

 

We are currently looking to buying a new email server which will have 2008 R2 x64 with exchange 2010, I am still thinking on what to do with the current one who future redundancy. Our school is very IT reliant and if anything goes down for a few minutes then serious problems occur (like students/staff not able to work).

 

I will look at DPM and possibly virtualisation for exchange. We have just virtualised our EPO, print, program servers. So I already have Hyper V on the system and running fine with no real problems. It is the way forward with us, we are becoming an academy and just purchased Frog, every block has PC's galore, 50% of all the work produced is on a PC and 95% all Post16 work is done on PC. So we must have things working and always working - 99.99% it should be online for.

  • 2 weeks later...
Posted

Hi Rabbie

 

If you want to implement a 2nd CAS at Australia (which you must if a mailbox server exists) then you have to decide if you want another internet facing CAS server or not. If yes, this will then need to be published on the Internet DNS. In this case, users can directly access the appropiate URL and access the same server in the same site as the user. If the AUS user uses the URL for Scotland then Exchange will redirect them to the Aus CAS server providing their mailbox is on a AUS Exch Server. This type of deployment is called Exchange redirection.

 

If you want a single point of entry into the ORG then you can expose one server, say the one already in Scotland, which will then perform proxying. This is known as Exchange Proxying.

 

On a seperate note for the mx records. This is different to CAS deployment. If you want mail to be delivered to the appropiate site, for example, if a external users sends an email to a user at Scotland then the route the mail should take should be to Scotland and not AUS, then you will need intelligent email routing or we you will have to have a seperate SMTP domain for each of the users. Depending on who hosts your MX records or importantly, where the MX records are pointed will determine if this is possible.

 

For example, MSFT offer this as a service, and what basically happends is that your AD is sync'ed (particular attributes) which identify the users locations and then email is sent to the appropiate HUB/EDGE server.

 

Sukh

Posted (edited)

Thanks for the prompt reply Sukh

 

I was thinking of having both scotland and australia as single CAS, defined by DNS (is it called round robin? Im not entirely sure, my idea is that mail.mydomain.com would resolve to the scottish IP, and the aus IP, so clinets would just connect to either) ..

 

the fact that my 2 sites are located goegraphically apart is different from what I would be trying to achieve in better circumstances, its just to do with what I have avaiolable to me.. Ideally, I would have 2 seperate WAN Ips, which would also be MX, and would go to 2 seperate local exhcnange

 

What Im thinking of, is the 2 seperate locations (sco and au) would be basically DAG I thnk (via a server to server VPN), so the mailboxes for each user would be redplciaed on either side, and each side would offer all of the Client Access. So if the entire SCO network was down, the AU would provide Client acces, and all of the mailbox..

 

This probably woulndnt be practical in a real world environment with real offices and users I guess?

 

Again, this is just me, learning and playing. But I reall appreciate your help and support

Edited by RabbieBurns
see edit
Posted (edited)
HAving a think a bit further, and again remembering this is just test setups with only 1 or 2 mailboxes..

 

Would the following work?

 

At the moment Exchange sits in scotland, the Client Access from the Internet goes to it. If I were to add a second exchange box here in australia, and VPN the two, and create a DAG via the VPN, could I then setup the client access from the internet to go to either exchange? Have mail.mydomain.com resolve to 2 IPs, both of which will process the mail, but will store it in the DAG which is available in both countries? Also means I can have a mx1. and a mx2 right?

 

What would be the best to method to have the 2 sites VPN'd together?[ATTACH=CONFIG]9736[/ATTACH]

 

Yes that method should work, not 100% sure on the DAGs as I have never implemented them but the rest is sound. You can have two MX records either prioritised with one preffered or both equal at which point it will round robin between them. In the same vain you can have two IPs for mail.yourdomain.com and it will just roundrobin pick which is supplied to the user.

 

http://ntrg.cs.tcd.ie/undergrad/4ba2.01/group8/DNS.html

 

If one site goes down though you have a 50/50 chance of getting a host not avalible on a webmail lookup as there is no additional fault tollerance with this method, it just picks one and goes with it.

Edited by SYNACK
  • Thanks 1
Posted

@Synack - If you do point your mail.yourdomain.com to the external URL, when a SCO user hits a Internet CAS at AUS they will be proxied/redirected to SCO CAS server depending on how Exchange is configured as their mailbox will be on at SCO mailbox server. Malibox servers used CAS servers in thier own site.

 

@Rabbie - Yes. If SCO has a server/site failure, then your DAG copies at AUS will privide mailbox/cas for your SCO users.

 

What would be ideal is to either have intelligent email routing, if not, then you can use MX records (round robin), which point to your HNLB, which then point to your CAS array. This will then provide HA/FT at every level.

 

Sukh

  • Thanks 1
  • 3 months later...
Posted
Right I'm just about to set up the Aus end of my tesbed network. What is the best way to get the site to site VPN established? Preferably a software option as I dont really want to spend money on somehting which is just for practice.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...