?
Solved

Publishing Exchange HT-CAS 2007 with Threat Management Gateway 2010 ?

Posted on 2014-02-09
10
Medium Priority
?
452 Views
Last Modified: 2014-02-11
Hi Folks,

I got 2 Exchange servers 2007 with the Hub Transport and Client Access Server role combined together and then running Windows NLB with IGMP Multicast (recommended by Vmware).

When publishing with Forefront Threat Management Gateway 2010, shall I create the rule to point into the Virtual Server / cluster name or one of the HT-CAS server only ?
0
Comment
  • 5
  • 3
9 Comments
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 39846539
So is it possible to change the published site to point to the NLB cluster virtual IP instead of one server FQDN ?
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39847110
When you are dealing with a Load Balancer the point of the Vitrual IP is so that it can distribute the load between the 2 servers based on the servers health. If you point it directly to the IP or FQDN of one of the servers this defeats the purpose of a load balancer. Also another thing, WNLB is not supported in a production environment and only should be used for testing environments.

If possible i would consider getting a hardware load balanacer or a vitrual load balancer.

Will.
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 39847154
Will,

Is this official from Microsoft or not the best practice ?
because when I join this company, the HT-CAS is already using WNLB as IGMP Multicast and then published by TMG 2010 to the internet.

if it is not recommended by Microsoft, then what should I do then to publish it to the internet securely ?
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 37

Accepted Solution

by:
Jamie McKillop earned 2000 total points
ID: 39847176
WNLB is not supported in a production environment and only should be used for testing environments

WNLB is most certainly supported on the CAS/HT role. What isn't specifically supported is the use of Exchange Server authentication on the HT role when using WNLB. See here: http://technet.microsoft.com/en-us/library/dd577077%28v=exchg.80%29.aspx

That said, I don't recommend using WNLB. Hardware load balancers are far superior. Unfortunately, they are also expensive, so you may be stuck with WNLB due to your budget.

Another option you have is to ditch WNLB and setup TMG to publish your servers as a farm. You would need to have your internal clients pointed at your TMG server to maintain redundancy though. Also, I assume you have have a TMG array for fault tolerance and redundancy.

-JJ
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 39847232
No my TMG 2010 is just standard deployment.

I had a problem when I vMotioned the HT-CAS it broke the Activesync, so the fix was to change the Activesync publishing rule in TMG 2010 to pint just one HT-CAS server instead of the VIP fqdn or the WNLB DNS names.

Strange and hard to believe.

It used to work fine but somehow live migration broke the Activesync
0
 
LVL 37

Expert Comment

by:Jamie McKillop
ID: 39847255
My suggestion would be to ditch WNLB and use farm publishing in TMG.

-JJ
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 39848347
Cool,

So in this case let the existing HT-CAS configuration work as it is but then change the TMG publishing rule only into farm publishing for the Activesync ?

For the Hub Transport I see no issue with email flow. It was just the Activesync that is doesn't work when the NLB is drainstopped and then resumed and started.
0
 
LVL 37

Expert Comment

by:Jamie McKillop
ID: 39848387
I would go to farm publishing for all your web services. You get the added benefit that TMG can do some health checks and automatically remove a member from the farm if there is an issue.

-JJ
0
 
LVL 8

Author Closing Comment

by:Senior IT System Engineer
ID: 39849526
Thanks man ! you are very helpful !
0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

The article is for all the Exchange users seeking smooth and effective EDB to PST conversion. Exchange Server is the most widely used platform for messaging with collaborative sharing, Exchange online, secure working environment, etc.
Importing Outlook PST contacts to Exchange Server can become a complicated task. Situations arise where an Exchange user is not able to import contacts from PST to Exchange Mailboxes in an efficient manner. Try SysTools Exchange Import to move conta…
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…
Watch the video to know the process of migration of Exchange or Office 365 mailboxes in absence of MS Outlook. It is an eminent tool which can easily migrate Public, Archive user mailboxes from one another Exchange server and Office 365. Kernel Migr…

569 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question