Solved

Exchange 2010 - Virtualization and Load Balancing

Posted on 2013-05-20
3
321 Views
Last Modified: 2013-06-11
Hello!

I'm looking to reconfigure Exchange 2010 in a test environment, eventually with the goal to be put into production. Any help you could answer on the following would be greatly appreciated.

I plan on setting up my environment as follows:

               LoadBalancer
                         /\
               Edge Transport
                          /\
               CAS Array
                          /\
               Mailbox Database

Each tier is composed of multiple virtual servers, for a large organization type of environment.

I am able to do most of this, but have some embarrassing gaps in my knowledge:

1. Which tiers will need to have public IPs assigned? (i.e. Edge Transport, CAS)

2. Does the Edge transport interact with the CAS at all? or does it simply go straight to the Mailbox Database?

3. Will I need SSL certs for the CAS servers, or can I install them on my Load Balancer (Zen, at the moment)

4. Any additional security recommendations for the CAS / Edge servers?

5. Any recommendations or criticisms to my current model?

Thank you!
0
Comment
Question by:jmichaelpalermo4
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 23

Expert Comment

by:Malli Boppe
ID: 39183470
I think your Edge should be in DMZ with public IP addresses. Then you would have load balancer in the internal VLAN. The load balancer would be configured with distribute the load between all the CAS servers.
Theen you would have CAS servers in the  internal VLAN and same with mailbox servers.
CAS array has nothin to do with the certificates . You need to have SAN certificate with the following domains

webmail.domain.com
autodiscover.com
casserver1.domain.com
casserver2.domain.com

http://blogs.technet.com/b/exchange/archive/2012/03/23/demystifying-the-cas-array-object-part-1.aspx
0
 
LVL 15

Accepted Solution

by:
msmamji earned 500 total points
ID: 39183573
1. Your emails would eventually land on edge and using send connectors (created during edge subscription) would be sent inside to the HUB Transport server. NAT would be a better option then assigning public IPs directly to edge servers.

2. Edge send and receives messages to and from HUB transport server and has nothing to do with CAS.

3. SSL would be required on CAS but they are used for client access not mail flow.

4 and 5. CAS, HUB and MBX on the inside network. Edge on DMZ with NAT. Use LB for client access protocols as well among other things.
0
 
LVL 1

Expert Comment

by:ssk_2k3
ID: 39184073
I would say that please have Edge servers on DMZ and place the load balancer's for CAS server requests. So that it can mange MAPI and internet requests well for users.

Once the load balancer placed point the CAS array IP to that to get work well.

SAN certificate should require to installed on CAS servers.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question