Jaarbeurs Utrecht, 18-1-2007 Alex de Jong Consultant Security Exchange System Center Trainer...

Post on 01-Apr-2015

212 views 0 download

Transcript of Jaarbeurs Utrecht, 18-1-2007 Alex de Jong Consultant Security Exchange System Center Trainer...

Jaarbeurs Utrecht, 18-1-2007

Alex de Jong

Exchange 2007 sessies vandaag

Programma

Enterprise … MKB … ConsumentHeliview, November 2005

RTM eind 2006 Longhorn time RTM+2 mnd

Microsoft mailproducten

Vroeger…

Exchange 5.0 Exchange 5.5 Exchange 2000 Exchange 2003

Exchange 2003 Architectuur

Exchange Admins in 2003

System Manager Exmerge Active Directory Users and

Computers

Verdwenen features

OWA access to public folders IMAP and NNTP access to public

folders GUI for public folder management OMA Exchange 5.5 support Groupwise support Lotus Notes support X.400 support

Verdwenen features vervolg Routing Groups -> AD Sites Administrative Groups -> Per server

ACL OWA Message Rules

Nog niet verdwenen features Public folders CDOEx (Developer - apps) WebDAV en ExOLEDB (Developer –

access) Store events (message checking on

stores) Streaming backup

Het Nieuwe Werken… volgens MS

Informatie beter beveiligen en

beheren

Informatie vinden en inzicht vergroten

40% Nederlanders voelt informatie

overload38.791 files in 2005 18% meer autokm’s

in 10 jaar

Enkele trendsEnkele trends Exch 2007Exch 2007Mensen

eenvoudiger laten

samenwerken

Implementatie-kosten en risico´s verminderen

60% van IT budget wordt besteed aan

onderhoud en ondersteuning

Nederlanders vergaderen gem. 6,5

uur per week

10 Redenen… volgens MS

Keep your e-mail system running at lower cost Access e-mail, voice mail, calendar, and anywhere, any

contacts from virtually time Get affordable, enterprise-class mobile messaging

that’s better than ever Empower employees with unified messaging while

saving money Get comprehensive protection from spam, viruses and

phishing attacks Reduce compliance risk in a way that makes sense for

your business Take advantage of powerful Web access Boost administrator productivity with new tools Ease deployment and management Optimize your investment for future growthhttp://www.microsoft.com/exchange/evaluation/topreasons.mspx

Huidige Exchange gebruikers

Nieuwe features

Built-in Protection Anti-spam, Antivirus Confidential Messaging

Anonymous TLS Compliance

Transport rules Journaling, archiving

Business Continuity LCR, CCR Faster, fewer backups Database portability

Nieuwe features

Administration Exchange Management Console Exchange Management Shell Troubleshooting tools Automatic Server Updates

WSUS, SCCM, SCE

Nieuwe features

Deployment Server Rollen Autodiscover in Outlook ExPBA

Nieuwe features

Performance Native 64 bit Storage optimization

Checkpoint Depth – reduced IO OWA

Nieuwe features

Anywhere Access Calendaring

Resource booking attendant, Scheduling assistant, Scheduled Out of Office

Mobile Messaging MBX Search, Direct Push, Device Security

Web based improvements Unified Messaging

Outlook Voice Access

Enterprise Enterprise networknetwork

MailboxMailbox

MailboxMailbox

EdgeEdgeTransportTransportOtherOther

SMTPSMTPServersServers

Hub Hub TransportTransport

RoutingRouting HygieneHygieneRoutinRoutin

ggPolicyPolicy

Unified Unified Messaging Messaging

Applications:Applications:OWAOWA

Protocols:Protocols:ActiveSync, POP, ActiveSync, POP,

IMAP, RPC / HTTP …IMAP, RPC / HTTP …ProgrammabilityProgrammability

::Web services, Web Web services, Web

partsparts

Client AccessClient Access

PBX PBX or or

VoIPVoIPII

NN

TT

EE

RR

NN

EE

TT PublicPublicFolderFolder

ss

FaxFax

Exchange 2007 Server Rollen

http://technet.microsoft.com/en-us/library/bb124558.aspx

Edge Transport Server

Internet Message Outbound Internet Message Inbound Antivirus / Anti-spam Edge Transport rules

Woorden, text combinaties, bijlage-extensies, subject

Quarantine, drop, reject, deliver

Edge Transport server

Address rewriting Gaat niet samen met een andere

Exchange 2007 rol Geen domain member In Perimeter network (DMZ) plaatsen

Hub Transport server

Message routing Categorization (AD checks) Routing (DNS checks, SMTP connect) Message delivery (tussen Ex2007 rollen)

Antivirus / Anti-spam Message policies

Rules voor verzenden, terugsturen, doorsturen, verwijderen

Journaling, archiving

Client Access server

Mailbox toegang voor non-MAPI clients POP3 IMAP4 HTTP(S)

Outlook Web Access 2007 (OWA) Exchange ActiveSync (EAS) Outlook Anywhere (RPC over HTTPS)

AutoDiscover service

Mailbox server

Mailbox stores Public folder stores Geen mailverkeer tussen mailboxen

(Hub transport taak) High availability

Clustering Local Continuous Replication (LCR) Clustered Continuous Replication (CCR)

© 2006 SF Solution Factory AG, P070110_00L_E2k7_SCC_LCR_CCR

Standalone Data Availability Problems

Data outages expensive to recover (single server, big database)

Significant data loss Local Continous Replication

One machine Enabled per storage group

Two copies, Replay One datacenter (= single machine) Easy configuration (some minutes)

Logs

DBs

Logs

DBs

© 2006 SF Solution Factory AG, P070110_00L_E2k7_SCC_LCR_CCR

Local Continous Replication Other requirements and behaviors

Manual activation per storage group Resource costs (CPU, memory, more disks &

storage space) Range of configurations (SAN, iSCSI, others) Variety of backup options (VSS from copy DB) Configuration limitations (single DB/SG, PF)

Benefits Enables recovery in minutes Enables recovery without data loss Enables large mailboxes

100 GB without, 200 GB max DB size with CCR Enables I/O offloading for backups

Logs

DBs

Logs

DBs

© 2006 SF Solution Factory AG, P070110_00L_E2k7_SCC_LCR_CCR

Local Continuous ReplicationA few “Recommendations” …

Use a single mailbox database per storage group

Use volume mount points to mount a target patition into a folder on another physical disk (pair)

Distribute the production and copy database and transaction log files to separate disks

Ensure hard disks meet performance & space requirements

Can‘t use LCR for a PF database if more than one PF db exists in org

C:C:

Disk1Disk1

Disk2Disk2

\ExchData\ExchData \ExchCopy\ExchCopy

© 2006 SF Solution Factory AG, P070110_00L_E2k7_SCC_LCR_CCR

Exchange Server Clusters Exchange Server 2003

Requires shared storage Single copy of mailbox data Transport, OWA & Mailbox cluster aware Up to 8 node active/passive 2 Node active/active

Exchange Server 2007 (Single Copy Cluster) Requires shared storage Single copy of mailbox data Mailbox Only Up to 8 node active/passive Active/active cut! Improvements in: Installation, Management,

Behavior

Q

DB

Log

s

SSMMT T PP- - MMBB- - OOWWAA

DB

Q

Log

s

MMBB

Draw Backs

© 2006 SF Solution Factory AG, P070110_00L_E2k7_SCC_LCR_CCR

Lacks full redundancy Quorum and Exchange database levels

Deployment and operational complexity Cost

e.g. Hardware > HCL for the whole package Recovery time after corruption or data failure varies

based on backup technology Two datacenter solution requires integration of 3rd-party

technology

Clustered Continuous Replication (CCR) solves these issues …

DB

Q

Log

s

MB

11.1.07/34

Clustered Continous Repl…

© 2006 SF Solution Factory AG, P070110_00L_E2k7_SCC_LCR_CCR

Two node cluster MNS with File Share Witness on Hub Transport (Recommendation)

Two copies

Clustered Automatic recovery

W2k3 Server HCL only!

Full redundancy

Log Replay

1 or 2 datacenters

Local Quorum

Local Quorum

q

DB

DB

L

og

s

L

og

s

FileShare

KB 921181

… CCR

© 2006 SF Solution Factory AG, P070110_00L_E2k7_SCC_LCR_CCR

Other requirements and behaviors Outage Management

Easy-to-use “scheduled outage” support Automatic recovery of an “unscheduled outage” (fail over)

Symmetric failover Resource requirements (no penalty) Variety of backup options Reduced backup TCO Configuration limitations

Active/Passive node solution Public Folder replicas and DC on a node is NOT supported

Local Quorum

Local Quorum

q

DB

DB

L

og

s

L

og

s

FileShare

KB 921181

Benfits CCR

File Share WitnessFile Share Witness

Passive NodePassive Node

Active NodeActive Node

Private NetworkPrivate

Network

Public NetworkPublic

Network

Benefits… Fast, automatic recovery to data problems

on active node No single point of failure No shared data storage Simplified storage requirements

No cluster hardware validation required Improved management experience Ability to offload backup workload

© 2006 SF Solution Factory AG, P070110_00L_E2k7_SCC_LCR_CCR 11.1.07/37

Unified Messaging server

Call Answering (voice mail in mailbox) Fax receiving (faxen in mailbox) Subscriber Access by phone

Voice mail Listen, forward e-mail Listen to calendar information Access or dial contact from GAL or

personal contact list Accept or cancel meeting requests Set Out-of-Office message in voice-mail

Unified Messaging server

Automated Attendant Use telephone keys or voice commands

In het LAN plaatsen Toegang tot IP-PBX, VoIP gateway of

IP Centrex telefoon systemen Vertalen fax of spraak naar IP data en

andersom

Eerst even regelen… Unf Mess

Exchange 2007 serverPBX

Toestel 401

Toestel 402Gateway

Lokaal netwerkTelefoon verkeer

Wireless Lan

Windows Mobile 5.0 device

Rollen combineren

Edge Transport server moet alleen zijn

Alle andere rollen kunnen worden gecombineerd.

Deployement Scenario -klein Alle rollen op één server (muv Edge) Geen edge (uitbesteden) Tot 75 werknemers?

Small Business Server “Longhorn” incl Ex2007

Deployement Scenario -middel Twee exchange 2007 servers

1e Server HU B Transport Client Access Mailbox Unified Messaging

2e Server Edge Transport

Deployement Scenario -groot Rollen splitsen Meerdere edge servers Meerdere mailbox servers Per site met mailbox server

minimaal: 1 HUB transport 1 Client access server

Eerst even regelen… AD

Schema master moet Windows Server 2003 SP1 draaien

Global Catalog Servers moeten ook SP1 draaien

Domain functional level moet minimaal 2000 Native zijn

DNS op orde Géén exchange 5.5 servers en huidige

exchange organisatie moet Native zijn.

Eerst even regelen… AD (2) Setup.exe

/PrepareLegacyExchangePermissions Bij een mix met Ex2000 of Ex2003

/PrepareSchema /PrepareAD

Voor root domain /PrepareDomain

Other domains /PrepareAllDomains

Eerst even regelen… hardware Processor

X64 architecture (x86 alléén voor test/training)

Memory Minimaal 1 GB internal memory

Disks 1,2 GB voor Exchange 2007 files 200 MB op System Disk NTFS everywhere

Eerst even regelen… Software MMC 3.0 .NET Framework 2.0 Windows Powershell IIS niet meer nodig op alle exchange

2007 rollen.

Eerst even regelen… Mbx Srv Internet Information Server

COM+ access Internet Information Services World Wide Web Service

Worden niet gebruikt door een dedicated Mailbox Server, maar moeten wel worden geinstalleerd.

Eerst even regelen… Cli Acc Internet Information Server

components ASP.NET World Wide Web Service

Eerst even regelen… HUB trns Zoek maar uit, maar géén SMTP

service en ook géén NNTP service.

Eerst even regelen… Edge trn Ook hier geen SMTP en NNTP

services DNS Suffix moet zijn geconfigureerd.

Upgraden???

In-Place Upgrade NOT SUPPORTED Wel supported

Transition upgrade (extra server, data move)

Migration (new organization, data move) Coexistence (Ex2000, Ex2003)

Administrative Groups wél aanwezig voor oudere versies van Exchange, niet voor 2007

Routing Groups wél aanwezig voor oudere versies, Ex2007 servers staan allemaal in de Exchange Routing Group

Interoperability met Lotus Notus via download. Groupwise en Exchange hebben geen toekomst samen.

Upgrade… Chronologisch

Client Access Hub Transport Mailbox Move data Uninstall previous versions, delete

RG’s / AG’s Unified Messaging Edge TransportLiefst per routing group upgraden

vanwege het nieuw routing mechanisme

FYDIBOHF23SPDLT (Adm Group in 2k3) DWBGZMFD01QNBJR (Routing Group in 2k3)

Service Packs can be Slipstreamed Volgende versie… Exchange 14, geldt

ook voor Office

Leuk om te weten

Prijzen

Servers Standard Edt… 699 $ - 5 SG’s, 5 DB’s Enterprise Edt… 3999$ - 50 SG’s, 50

DB’s, UM CAL´s

Standard CAL… 67$ per user of per device

Meer info…

Exchange Server Site http://www.microsoft.com/exchange/default.mspx

Exchange Server 2007 Preview Site http://www.microsoft.com/exchange/preview/default.mspx

Exchange Server 2007 Demo http://www.microsoft.com/exchange/preview/evaluation/

demos.mspx Exchange Server in Depth (Webcasts)

http://www.microsoft.com/events/series/tnexchangeserver.mspx Exchange Server 2007 Technical Library

http://www.microsoft.com/technet/prodtechnol/exchange/2007/library/default.mspx

Exchange Server TechCenter http://www.microsoft.com/technet/prodtechnol/exchange/

default.mspx TechNet Virtual Lab: Exchange Server

http://www.microsoft.com/technet/traincert/virtuallab/exchange.mspx

The Microsoft Exchange Team Blog http://msexchangeteam.com/default.aspx