Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Exchagne 365 to on premises Exchagne 2013 - 500pnts

Posted on 2014-04-13
7
Medium Priority
?
345 Views
Last Modified: 2014-04-15
Ok so I need to move our user back from 365 online to Exchange 2013 within our Lan

I have 46 users to move my plan is to move the MX records on the Friday night and export everything to PST files - reconnect client to on premise exchange server and reimport from pst. - I don't have time to learn about the hybrid mode as there very little documentation and I don't want to use Migrationwizard

Below is my game plan with some questions thrown in 500pnts available.


Our server FQDN is WLEXCH001.wiseman.co.uk - Internal IP 192.168.2.239 - I think our external IP for SMTP is 77.73.11.54
 
1.)      Change MX records from wiseman-co-uk.mail.protection.outlook.com (365) to wlexch001.wiseman.co.uk
2.)      Change CNAME autodiscover from autodiscover.outlook.com – to what?? Guessing the internal server but where
3.)      So if I configure external access domain from within Virtual directory for OWA say mailserver.wiseman.co.uk to our internal server would this be 77.73.11.54
As I have these line in my firewall “access-list mail permit tcp any host 77.73.11.54 eq smtp”+ “static (inside,outside) 77.73.11.54 192.168.2.239 netmask 255.255.255.255 0 0”
Or do I need another external ip address

Other than the above I need to - have I missed anything?

A.)      Setup Mailboxes – What is the PS command to do this?
B.)      Setup Dynamic Groups
C.)      Setup Address list
D.)      Config Malware and Spam filter – create quarantine user
E.)      Do I need to doing anything in the Accepted Domain tab if we want to add wisemanlee.co.uk
F.)      Setup the send connector – Do I enter our ISP MX records in here?
G.)      Setup Public Folder
H.)      Setup the databases and enable the Journal
I.)      Create the Certificate

Thank you

Ian
0
Comment
Question by:ise438
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 39999927
So, it sounds like you are moving from Office 365 back to on-prem. If you don't want to use Hybrid mode then I highly recommend MigrationWiz.

This will automate a good deal of this for you and eliminate the need to export and import those 46 PSTs. The cost per user is low and in the long run it will be cheaper than the time needed to do all those imports/exports.

MigrationWiz
http://goo.gl/83ZVeP
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 39999992
1). This needs to point to your CAS server (or load balancer).
2). This needs to point to your CAS server (or load balancer).
3). Normally only one IP is required. Unless you have multiple MX records for redundancy.

Your firewall ACLs and NAT statements look correct. It is old code so I am guessing you are running Cisco IOS 8.2 or older.

A). New-Mailbox. But you can do this from the ECP as well. Whichever you are more comfortable with.

B). Depends on your needs. Normally, I see static groups created over dynamic groups.

C). For a 46 user network I would assume you most likely will just use the default address lists. Again, depends on your needs. One thing you will likely need to modify is the Email Address Policy to match that of the policy in Office 365. That way your users get the same email addresses assigned to their user accounts.

D). You can either use an Edge server (Exchange 2013 has an Edge Server now!), or, add the antimalware/antispam feature on the Exchange server. Or, put an appliance in front of it all. Personally, I prefer cloud based antispam solutions such as FOPE. Keeps all the spam off my internet connection/firewall/server.

E). You will need to make sure that wisemanlee.co.uk is listed as an authoritative domain in the Accepted Domain tab.

F) No. If you plan to use a Smart-Host you can use that (especially if you are using a cloud based anti-spam solution for outbound/inbound filtering). Otherwise, sending to DNS directly is fine. Just one send connector for the entire namespace is likely all you will need for 46 users / 1 domain.

G). You will need a Public Folder Mailbox if you plan to use Public Folders. Are you using Public Folders in Office365?

H). For 46 users you can most likely get away with one database. I am assuming a single server with all roles (no DAG). When you installed Exchange it should have created a Mailbox Database. You can use this. Although I would relocate the database and logs to dedicated drives.
 
I). Yes, you will need a 3rd-party certificate for all Exchange Web Services. You will need a UC/SAN certificate. I recommend GoDaddy.com. Their prices are usually the lowest and with a quick Google Search on GoDaddy.com Promo Codes you can normally find additional savings. www.godaddy.com. The Exchange Control Panel will walk you through the certificate generation process. GoDaddy.com also has specific Exchange 2013 instructions as well for installing their certs.
0
 

Author Comment

by:ise438
ID: 40000146
Thats Excellent diggisaur - couple of questions.

Do I need to configure my firewall to poing to my CAS server?
If I change my MX records to WLEXCH001.wiseman.co.uk which has a internal ip address - will I need a external IP and some sort of NAT?

Certificate:- Can I not use a cert create in AD CA?

Thanks

Ian.
0
NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

 
LVL 31

Accepted Solution

by:
Gareth Gudger earned 2000 total points
ID: 40000180
You could use an AD CA but that will only be recognized by domain joined devices, or, devices you manually install the certificate on.

Some ActiveSync devices may have problems with a self signed cert as well.

With the amount of time it can take troubleshooting certificate errors on devices over the course of a year, it probably will be cheaper to just buy the third party cert.

With regard to the Cisco IOS, I am assuming you are using a single Exchange 2013 with all roles. If so, then you can direct it all to the same place.

access-list mail permit tcp any host 77.73.11.54 eq smtp
access-list mail permit tcp any host 77.73.11.54 eq https
access-list mail permit tcp any host 77.73.11.54 eq www
static (inside,outside) 77.73.11.54 192.168.2.239 netmask 255.255.255.255 0 0

Then make sure the access-list is assigned to the outside interface with an access-group.

That should be it.
0
 

Author Comment

by:ise438
ID: 40000885
Excellent
0
 

Author Closing Comment

by:ise438
ID: 40000886
Fantastic answer -  thank you
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40001277
You're welcome!
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

New style of hardware planning for Microsoft Exchange server.
Here in this article, you will get a step by step guidance on how to restore an Exchange database to a recovery database. Get a brief on Recovery Database and how it can be used to restore Exchange database in this section!
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
This video discusses moving either the default database or any database to a new volume.

597 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question