Exchange Server 2010 Hardening

padas6
padas6 used Ask the Experts™
on
Hi ,

We are planning to upgrade Exchange from Exchange 2007 to Exchange 2010. Please let me know what is the best practices to do the Exchange Serevr 2010 Hardeing before putting into Production environment.
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Manpreet SIngh KhatraSolutions Architect, Project Lead
Top Expert 2013

Commented:
What is your current infrastructure and do you have the budget for HA ?
Look i dont think anyone can give you a complete answer before knowing your thoughts and basic requirements

- Rancy
"Merry Christmas and Happy New Year"

Author

Commented:
Hi Rancy,

Current Infrastructure is Exchange Server 2007 SCC model with Single HUb & Single CAS, duel Iron Port is being used for SMTP gateway with 2000 user mailbox .

We are planning to Migrate with below feature,

1. Two HUB & CAS in Cas Array
2. Two Mailbox Server is in DAG Functionality.

We are already going to start to installation but I have couple of queries which I posted today itself.

I just wanted to know if any good guidelline is availble for Exchange Hardening.
Manpreet SIngh KhatraSolutions Architect, Project Lead
Top Expert 2013

Commented:
Perfect for your concern for point 1 & 2

Look i would suggest use Storage Calculator to understand whats best with number of Mailbox DB's you should have .... (Ram, Storage, Bandwidth)

Are you not getting a EDGE but using Ironport itself i guess ?
What exactly do you mean by Hardening ?

- Rancy
Success in ‘20 With a Profitable Pricing Strategy

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Author

Commented:
Server haredening, sany Minimum port opening, renaming local administrator account, basically you can server Server Hardening & if any thing I can focus on Exchange part.
Solutions Architect, Project Lead
Top Expert 2013
Commented:
Look Ports i guess should be opened for it to communicate with DC\GC and fr port25 and HTTP and HTTPS rest depends if there is some additional ports you need to open on it.

http://social.technet.microsoft.com/Forums/en-US/exchange2010/thread/b2f623cc-ab97-402d-92f7-18e7fe0cc516

http://loguinfo.blogspot.in/2007/12/hardening-exchange-server.html

http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_26646314.html

- Rancy

Author

Commented:
Usuable link.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial