Solved

Publishing Exchange HT-CAS 2007 with Threat Management Gateway 2010 ?

Posted on 2014-02-09
10
431 Views
Last Modified: 2014-02-11
Hi Folks,

I got 2 Exchange servers 2007 with the Hub Transport and Client Access Server role combined together and then running Windows NLB with IGMP Multicast (recommended by Vmware).

When publishing with Forefront Threat Management Gateway 2010, shall I create the rule to point into the Virtual Server / cluster name or one of the HT-CAS server only ?
0
Comment
  • 5
  • 3
10 Comments
 
LVL 7

Author Comment

by:Senior IT System Engineer
Comment Utility
So is it possible to change the published site to point to the NLB cluster virtual IP instead of one server FQDN ?
0
 
LVL 53

Expert Comment

by:Will Szymkowski
Comment Utility
When you are dealing with a Load Balancer the point of the Vitrual IP is so that it can distribute the load between the 2 servers based on the servers health. If you point it directly to the IP or FQDN of one of the servers this defeats the purpose of a load balancer. Also another thing, WNLB is not supported in a production environment and only should be used for testing environments.

If possible i would consider getting a hardware load balanacer or a vitrual load balancer.

Will.
0
 
LVL 7

Author Comment

by:Senior IT System Engineer
Comment Utility
Will,

Is this official from Microsoft or not the best practice ?
because when I join this company, the HT-CAS is already using WNLB as IGMP Multicast and then published by TMG 2010 to the internet.

if it is not recommended by Microsoft, then what should I do then to publish it to the internet securely ?
0
 
LVL 37

Accepted Solution

by:
Jamie McKillop earned 500 total points
Comment Utility
WNLB is not supported in a production environment and only should be used for testing environments

WNLB is most certainly supported on the CAS/HT role. What isn't specifically supported is the use of Exchange Server authentication on the HT role when using WNLB. See here: http://technet.microsoft.com/en-us/library/dd577077%28v=exchg.80%29.aspx

That said, I don't recommend using WNLB. Hardware load balancers are far superior. Unfortunately, they are also expensive, so you may be stuck with WNLB due to your budget.

Another option you have is to ditch WNLB and setup TMG to publish your servers as a farm. You would need to have your internal clients pointed at your TMG server to maintain redundancy though. Also, I assume you have have a TMG array for fault tolerance and redundancy.

-JJ
0
Do email signature updates give you a headache?

Do you feel like all of your time is spent managing email signatures? Too busy to visit every user’s desk to make updates? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today!

 
LVL 7

Author Comment

by:Senior IT System Engineer
Comment Utility
No my TMG 2010 is just standard deployment.

I had a problem when I vMotioned the HT-CAS it broke the Activesync, so the fix was to change the Activesync publishing rule in TMG 2010 to pint just one HT-CAS server instead of the VIP fqdn or the WNLB DNS names.

Strange and hard to believe.

It used to work fine but somehow live migration broke the Activesync
0
 
LVL 37

Expert Comment

by:Jamie McKillop
Comment Utility
My suggestion would be to ditch WNLB and use farm publishing in TMG.

-JJ
0
 
LVL 7

Author Comment

by:Senior IT System Engineer
Comment Utility
Cool,

So in this case let the existing HT-CAS configuration work as it is but then change the TMG publishing rule only into farm publishing for the Activesync ?

For the Hub Transport I see no issue with email flow. It was just the Activesync that is doesn't work when the NLB is drainstopped and then resumed and started.
0
 
LVL 37

Expert Comment

by:Jamie McKillop
Comment Utility
I would go to farm publishing for all your web services. You get the added benefit that TMG can do some health checks and automatically remove a member from the farm if there is an issue.

-JJ
0
 
LVL 7

Author Closing Comment

by:Senior IT System Engineer
Comment Utility
Thanks man ! you are very helpful !
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now