Solved

Exchagne 365 to on premises Exchagne 2013 - 500pnts

Posted on 2014-04-13
7
333 Views
Last Modified: 2014-04-15
Ok so I need to move our user back from 365 online to Exchange 2013 within our Lan

I have 46 users to move my plan is to move the MX records on the Friday night and export everything to PST files - reconnect client to on premise exchange server and reimport from pst. - I don't have time to learn about the hybrid mode as there very little documentation and I don't want to use Migrationwizard

Below is my game plan with some questions thrown in 500pnts available.


Our server FQDN is WLEXCH001.wiseman.co.uk - Internal IP 192.168.2.239 - I think our external IP for SMTP is 77.73.11.54
 
1.)      Change MX records from wiseman-co-uk.mail.protection.outlook.com (365) to wlexch001.wiseman.co.uk
2.)      Change CNAME autodiscover from autodiscover.outlook.com – to what?? Guessing the internal server but where
3.)      So if I configure external access domain from within Virtual directory for OWA say mailserver.wiseman.co.uk to our internal server would this be 77.73.11.54
As I have these line in my firewall “access-list mail permit tcp any host 77.73.11.54 eq smtp”+ “static (inside,outside) 77.73.11.54 192.168.2.239 netmask 255.255.255.255 0 0”
Or do I need another external ip address

Other than the above I need to - have I missed anything?

A.)      Setup Mailboxes – What is the PS command to do this?
B.)      Setup Dynamic Groups
C.)      Setup Address list
D.)      Config Malware and Spam filter – create quarantine user
E.)      Do I need to doing anything in the Accepted Domain tab if we want to add wisemanlee.co.uk
F.)      Setup the send connector – Do I enter our ISP MX records in here?
G.)      Setup Public Folder
H.)      Setup the databases and enable the Journal
I.)      Create the Certificate

Thank you

Ian
0
Comment
Question by:ise438
  • 4
  • 3
7 Comments
 
LVL 30

Expert Comment

by:Gareth Gudger
Comment Utility
So, it sounds like you are moving from Office 365 back to on-prem. If you don't want to use Hybrid mode then I highly recommend MigrationWiz.

This will automate a good deal of this for you and eliminate the need to export and import those 46 PSTs. The cost per user is low and in the long run it will be cheaper than the time needed to do all those imports/exports.

MigrationWiz
http://goo.gl/83ZVeP
0
 
LVL 30

Expert Comment

by:Gareth Gudger
Comment Utility
1). This needs to point to your CAS server (or load balancer).
2). This needs to point to your CAS server (or load balancer).
3). Normally only one IP is required. Unless you have multiple MX records for redundancy.

Your firewall ACLs and NAT statements look correct. It is old code so I am guessing you are running Cisco IOS 8.2 or older.

A). New-Mailbox. But you can do this from the ECP as well. Whichever you are more comfortable with.

B). Depends on your needs. Normally, I see static groups created over dynamic groups.

C). For a 46 user network I would assume you most likely will just use the default address lists. Again, depends on your needs. One thing you will likely need to modify is the Email Address Policy to match that of the policy in Office 365. That way your users get the same email addresses assigned to their user accounts.

D). You can either use an Edge server (Exchange 2013 has an Edge Server now!), or, add the antimalware/antispam feature on the Exchange server. Or, put an appliance in front of it all. Personally, I prefer cloud based antispam solutions such as FOPE. Keeps all the spam off my internet connection/firewall/server.

E). You will need to make sure that wisemanlee.co.uk is listed as an authoritative domain in the Accepted Domain tab.

F) No. If you plan to use a Smart-Host you can use that (especially if you are using a cloud based anti-spam solution for outbound/inbound filtering). Otherwise, sending to DNS directly is fine. Just one send connector for the entire namespace is likely all you will need for 46 users / 1 domain.

G). You will need a Public Folder Mailbox if you plan to use Public Folders. Are you using Public Folders in Office365?

H). For 46 users you can most likely get away with one database. I am assuming a single server with all roles (no DAG). When you installed Exchange it should have created a Mailbox Database. You can use this. Although I would relocate the database and logs to dedicated drives.
 
I). Yes, you will need a 3rd-party certificate for all Exchange Web Services. You will need a UC/SAN certificate. I recommend GoDaddy.com. Their prices are usually the lowest and with a quick Google Search on GoDaddy.com Promo Codes you can normally find additional savings. www.godaddy.com. The Exchange Control Panel will walk you through the certificate generation process. GoDaddy.com also has specific Exchange 2013 instructions as well for installing their certs.
0
 

Author Comment

by:ise438
Comment Utility
Thats Excellent diggisaur - couple of questions.

Do I need to configure my firewall to poing to my CAS server?
If I change my MX records to WLEXCH001.wiseman.co.uk which has a internal ip address - will I need a external IP and some sort of NAT?

Certificate:- Can I not use a cert create in AD CA?

Thanks

Ian.
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 30

Accepted Solution

by:
Gareth Gudger earned 500 total points
Comment Utility
You could use an AD CA but that will only be recognized by domain joined devices, or, devices you manually install the certificate on.

Some ActiveSync devices may have problems with a self signed cert as well.

With the amount of time it can take troubleshooting certificate errors on devices over the course of a year, it probably will be cheaper to just buy the third party cert.

With regard to the Cisco IOS, I am assuming you are using a single Exchange 2013 with all roles. If so, then you can direct it all to the same place.

access-list mail permit tcp any host 77.73.11.54 eq smtp
access-list mail permit tcp any host 77.73.11.54 eq https
access-list mail permit tcp any host 77.73.11.54 eq www
static (inside,outside) 77.73.11.54 192.168.2.239 netmask 255.255.255.255 0 0

Then make sure the access-list is assigned to the outside interface with an access-group.

That should be it.
0
 

Author Comment

by:ise438
Comment Utility
Excellent
0
 

Author Closing Comment

by:ise438
Comment Utility
Fantastic answer -  thank you
0
 
LVL 30

Expert Comment

by:Gareth Gudger
Comment Utility
You're welcome!
0

Featured Post

Why spend so long doing email signature updates?

Do you spend loads of your time carrying out email signature updates? Not very interesting are they? Don’t let signature updates get you down. Let Exclaimer Cloud - Signatures for Office 365 make managing email signatures a breeze.

Join & Write a Comment

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

5 Experts available now in Live!

Get 1:1 Help Now