Solved

Exchange Cluster, Front-End Back-End, SMPT Gateway

Posted on 2006-11-22
8
1,211 Views
Last Modified: 2013-11-15
Exchange Cluster, Front-End Back-End, SMPT Gateway

I am rebuilding our Exchange structure. We are going from a mix of 2000 and 2003 Exchange servers in a distributed environment to a single location in a CyberCenter. We currently have 9 Exchange servers (single servers) in different locations. We have 3 SMTP Gateways running Trend Interscan Messaging & Security Suite (IMSS). The IMSS servers don't do any spam filtering. They are for outbound disclaimers and some content filtering, like blocking Internal Use Only emails. Our MX records point to MX Logic. They spam filter and then deliver directly to our IMSS servers. We have Trend ScanMail on exchange servers for virus. We have about 1000 users.

Current Setup
-------------
9 Exchange Servers (2000 and 2003)
ScanMail
3 SMTP Gateways (IMSS)
MX Logic Spam filtering for inbound mail, deliver directly to our IMSS servers

New Setup
---------
Exchange 2003 Cluster Back-end (2 active, 1 passive)
Exchange 2003 Front-End (2 servers, OWA and RPC/HTTP)
Antigen on the Cluster for virus
GFI MailEssentials for disclaimers and content filtering (not sure on this one)

I really don’t like the IMSS SMTP Gateway. I want to eliminate them if feasible. I also don’t like ScanMail. I would prefer Antigen. I’m not sure that we need SMTP Gateways at all. We don’t allow email from the Internet to hit our servers directly. It is all coming from MX Logic. I think we may be better off delivering directly to and from the Exchange Cluster. The mail tracking with IMSS is terrible. I would rather do it with Exchange, unless there’s something better out there. My current thought is Antigen on the Cluster for virus and GFI MailEssentials on the Cluster for disclaimers and outbound content filtering.

Any thoughts or suggestions?

Charlie
0
Comment
Question by:Shaktur
  • 4
  • 4
8 Comments
 
LVL 24

Expert Comment

by:flyguybob
ID: 17997125
There is a lot to post, but I wanted to make one quick note.
Cluster nodes recieve mail on the Virtual IP for the Exchange cluster resource group.
Cluster nodes send mail on the physical IP of the active node.
Keep this in mind if you don't utilize a full FE/BE architecture.

Bob
0
 

Author Comment

by:Shaktur
ID: 18048002
Thanks for the reply Bob. I was not aware of that (outbound email on the nodes IP). That could cause potential reverse DNS problems.

As for a full FE/BE architechture, would the FE servers actually send outbound email in this case?

Charlie
0
 
LVL 24

Expert Comment

by:flyguybob
ID: 18048625
If you configure it, yes.  

In many cases I have had an edge system on the outside, be it an Exchange 2007 Edge server,  IIS server, Ironport, Sendmail server, etc.  As such, I create an SMTP connector that will send all e-mail to the edge system(s), using (a) specific IP(s), and only allow the FE server to use the connector.  If you don't have an edge connector, then you just leave the connector set to use DNS to deliver the mail.

Front-end server considerations in Exchange Server 2003  
http://support.microsoft.com/kb/822443/
0
 

Author Comment

by:Shaktur
ID: 18246594
Sorry for the delay in responding, December was a busy month. =/

In a full FE/BE setup, does the BE relay mail to the FE and then the FE send it on out to the Internet? I'm still not sure if we need a separate gateway(s) since it is really just for outbound mail. All inbound mail coming directly from MXLogic.

Any more thoughts on this?
0
Network it in WD Red

There's an industry-leading WD Red drive for every compatible NAS system to help fulfill your data storage needs. With drives up to 8TB, WD Red offers a wide array of solutions for customers looking to build the biggest, best-performing NAS storage solution.  

 
LVL 24

Accepted Solution

by:
flyguybob earned 500 total points
ID: 18247432
Yes, that is one of the configurations.
Generally a true Front-end Server will perform several functions:
1.  SMTP gateway
2.  OWA front-end
3.  Security barrier between the BE server, with the databases, and the internet.
0
 

Author Comment

by:Shaktur
ID: 18252028
Ok, cool, good info.

So far my plan remains pretty much the same. FE/BE config. 3 node (active/active/passive) cluster for backend. 2 NLB frontend servers.

The remaining question is whether or not to use a gateway. I imagine you could use another Exchange server for a gateway, separate from the FE servers. How much "tracking info" would you lose if the gateway was not an Exchange server. What would you recommend as a good gateway product. We are currently using Trend IMSS and I really don't like it.
0
 

Author Comment

by:Shaktur
ID: 18252077
Also, I should restate, this is for about 1000 users, possibly 2000 by years end. I know the 3 node cluster is overkill, but it needs to be a highly avaliable resource.
0
 
LVL 24

Expert Comment

by:flyguybob
ID: 18254360
I have worked with A/A/P clusters and they work just fine.  I would not go anywhere above 4 nodes A/A/A/P, if at all possible.

The best gateway product, outside of an Exchange 2007 Edge server, and an application which meets your out of the box reporting requirements, is likely going to be overkill.  MX Logic performs your front-end hosting and anti-spam services as well as mailbagging if your FE is down.  That is one of the primary reasons to have a Front-End.  The other primary reason for a FE is to allow OWA access.  

In all honesty, you could put something like Forefront (formerly Sybari Antigen) on your server, and use a 3rd party reporting tool for outbound mail statistics.  You are only scanning outbound messages and it is likely that you have anti-virus on your Exchange cluster nodes.

My current engagement requires me to remain vendor neutral, but I can mention several products that handle front-end services as a software/hardware package, and can meet your reporting requirements.
Ironport (recently purchased by Cisco)
   I have worked with Ironport extensively with several small enterprise customers (1000 users) and some very large enterprise customers (20,000+ users).  I haven't ever had a complaint, personally or from a previous customer who implemented their product as an SMTP gateway, anti-spam and anti-virus.
Barracuda (Symantec)
   I haven't worked with the hardware device.
0

Featured Post

Superior storage. Superior surveillance.

WD Purple drives are built for 24/7, always-on, high-definition security systems. With support for up to 8 hard drives and 32 cameras, WD Purple drives are optimized for surveillance.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

864 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now