Ehlo All,
I've been involved (meaning supporting) BlackBerry Exchange Servers (BES) for 5 years or so, and I just found out about the failover process of BES 4.0 & 4.1. RIM calls it "knife-edge cutover". This is a pretty cool capability that's not too difficult to implement.
I'm a big believer in reading documentation, and didn't know about this until another IT tech casually mentioned this in passing while we discussed virtualization. To summarize, it allows you to quickly failover to a new BES without the need to reactivate BlackBerry devices for end users. So, it allows you to upgrade server hardware, replace a virtual machine (which we recently did and used this approach), or test fail-overs. It worked flawlessly. BlackBerry users didn't even know we failed over to a new vm (virtual machine) since it took only a few minutes. A client's BES vm was having issues, so we used a base vm image and setup BES capability, and then perform a knife-edge cutover. Problem solved, and I'm sure we won't be touching that image for many more years.
Enjoy this gift.... RIM's KB10278 instructions about knife-edge cutover for BES 4.0 & 4.1
-Ben
Thursday, January 1, 2009
Sunday, December 28, 2008
Favorite URLs for my Exchange & Admin Work Posted...
Ehlo All,
I figured I would share the websites I use for my Exchange and other admin work so other admin's would benefit. So, enjoy. Any comments or suggestions for other sites, let me know in the comments.
-Ben
I figured I would share the websites I use for my Exchange and other admin work so other admin's would benefit. So, enjoy. Any comments or suggestions for other sites, let me know in the comments.
-Ben
Wednesday, December 10, 2008
Exchange Server 2007 Rollups Existing for SP1 & non-SP version
So Everyone,
Question: which is the latest Update Rollup for Exchange Server 2007, 5 or 7? That was last night at the Exchange User Group meeting (nyexug.com). We had a discussion of the latest update for Exchange Server 2007. Some folks said roll-up 7 was the latest, and I said roll-up 5 was the latest. Turns out everyone was right. How can that be you may ask? Exchange Server 2007 is a DIFFERENT product than Exchange Server 2007 SP1 so they have different updates. Which explains why the tech who installed a rollup for non-SP1 broke his SP1 Exchange. He smartly do a snapshot before upgrading and disconnected the server from the network, so he quickly reverted to the pre-patch state. So, pay attention which updates are for your version of Exchange.
As of December 10, 2008, here are the latest updates for each version of Exchange Server 2007. I don't know why folks would stay on base version 2007 due to all the gains in SP1, but obviously many folks are and MS is paying attention to them.
Exchange Server 2007 - Update Rollup 7
http://support.microsoft.com/kb/953469
Exchange Server 2007 SP1 - Update Rollup 5 (not on Windows Update yet, will be posted in 1-2 weeks, so you must know about it to download it)
http://support.microsoft.com/?kbid=953467
-Ben
Question: which is the latest Update Rollup for Exchange Server 2007, 5 or 7? That was last night at the Exchange User Group meeting (nyexug.com). We had a discussion of the latest update for Exchange Server 2007. Some folks said roll-up 7 was the latest, and I said roll-up 5 was the latest. Turns out everyone was right. How can that be you may ask? Exchange Server 2007 is a DIFFERENT product than Exchange Server 2007 SP1 so they have different updates. Which explains why the tech who installed a rollup for non-SP1 broke his SP1 Exchange. He smartly do a snapshot before upgrading and disconnected the server from the network, so he quickly reverted to the pre-patch state. So, pay attention which updates are for your version of Exchange.
As of December 10, 2008, here are the latest updates for each version of Exchange Server 2007. I don't know why folks would stay on base version 2007 due to all the gains in SP1, but obviously many folks are and MS is paying attention to them.
Exchange Server 2007 - Update Rollup 7
http://support.microsoft.com/kb/953469
Exchange Server 2007 SP1 - Update Rollup 5 (not on Windows Update yet, will be posted in 1-2 weeks, so you must know about it to download it)
http://support.microsoft.com/?kbid=953467
-Ben
Tuesday, December 9, 2008
NYExUG Member Review of PowerShell Book
At one of our last NY Exchange User Group meeting which was focused on PowerShell and Exchange presented by PowerShell MVP Brandon Shell, Manning Publications provided us a copy of their Windows PowerShell in Action book to review. One of the winners of the book provided me this review.
-Ben
Here is my review of the PowerShell book:
There are usually two different types of sysadmin who script: the ones who will find a script online, modify it for their needs (hopefully test it) and deploy it, and one that will figure out all the methods and procedures and write a script from scratch. This book while it says is geared to all beginner’s is really written for the later type of sysadmin. The book does a wonderful job of explaining in detail how the pipeline works but for most sysadmins they would want a more finished example of doing something versus how the pipeline itself works.
--Tracy
-Ben
Here is my review of the PowerShell book:
There are usually two different types of sysadmin who script: the ones who will find a script online, modify it for their needs (hopefully test it) and deploy it, and one that will figure out all the methods and procedures and write a script from scratch. This book while it says is geared to all beginner’s is really written for the later type of sysadmin. The book does a wonderful job of explaining in detail how the pipeline works but for most sysadmins they would want a more finished example of doing something versus how the pipeline itself works.
--Tracy
Sunday, December 7, 2008
In pursuit of my Exchange 2007 deployment - the ugly of VMware ESXi 3.5 and hard drive resizing for Windows Server 2008
Hello All,
How do you resize partition sizes in VMware ESXi 3.5 (version 110271, VI 2.5 build 103682, VCenter 2.5.0 build 104215) and Windows Server 2008 (these were MBR and Simple volumes)?
1) VI client built-in functionality (VI 2.5 build 103682)
2) DISKPART (as included with Windows 2003)
3) GParted (gparted-livecd-0.3.4-11.iso)
4) VMware Converter (3.0.3 build 89816)
5) vmkfstools (VMware ESXi 3.5 (version 110271)
6) none of the above. Re-install the OS.
Spoiler plot... this does NOT have a happy ending. The answer is 6. If you think you can prove me wrong with the versions above, please let me know how.
If you're a reader of my blog skip to the next paragraph, since this is an executive summary for the non-regulars. I'm in the process of finally upgrading to Exchange 2007 from 2003. I've decided to make it a challenge and do it on a platform I have had no experience with, Windows Server 2008. All my clients and all my servers are Windows 2003 or a variation (e.g. R2, x64, etc). To make it even more difficult, even though I have extensive experience with VMware Server and Workstation, I'm running it under VMware ESXi 3.5 [embedded & w/virtual center]. ESXi is a different beast than other VMware products. It contains a WHOLE lot more functionality especially when you add Virtual Center.
After a few months of planning on functionality & redundancy desired, hardware sizing, migration plans, and a number of other factors, I took the plunge into testing. So, I created my base OS images of Windows 2003 (x32) and Windows 2008 (x64) to test for 1 month which turned into 4 months. After I was done testing installs and configurations, I deleted all those images and started again. The party began.
So, I setup base OS images with 30GB partitions since I was planning on adding a minimum of 14 images & 12 virtual machines (aka vm's). Space is a concern since it is 6 x 300GB SAS 10k hard drives in direct attached storage (DAS) in a RAID 10 config. Problem was I mistakenly made the 2008 system partition size 30GB. I figured, it would be large enough. I'm blogging about this, so obviously it was not and the attempted fix wasn't a quick 1-2-3 or even a 2-3 hour fix.
Attempt #1 - How VMware hard drive resizing is suppose to work
So, after making my 2008 partition size 30GB, I figured the beauty of VMware would show of it's skills. Similar to VMware Server & Workstation, you right-click and enter the new larger hard drive size, and click OK, and a few seconds later it would be increased to 50GB. No such luck. Attempting this resulted in ESXi simply ignoring my request to enlarge the partition. No error, nothing. It stayed on 30GB. A bit of research indicated that Windows Server 2008 is NOT supported for hard drive increases via the VMware Infrastructure Client (aka VI). So, I looked into the other options.
Attempt #2 - Diskpart
This techtarget.com article talks about Diskpart, but all the screenshots are 2003 related, so I didn't even bother, since I figured since diskpart shipped with Windows 2003 SP1, it probably was a dead-end solution. Diskpar was Windows 2003 related, diskpart was 2003 SP1 related. You can find a good article about Exchange 2003 and align your partitions for database storage here.
Attempt #3 - GParted
As per attempt #2, that same techtarget article talks about using an open-source partition tool. I uploaded the ISO to the datastore, did the booting, and attempted to modify the partition to 50GB. It reported no additional space execpt for one more 1MB. Obviously, that isn't correct. Next....
Attempt #4 - VMware Converter
I tried this 2 different ways since some sites including the above techtech article here talked about running VMware Converter directly on the server you are attempting to modify the hard drive partition size, and via a remote server. In my case I attempted via Virtual Center. Both ways failed with the same error "Unable to determine Guest Operating system". Problem: Windows Server 2008 is not supported. Oops. Next attempt.
Attempt #5 - vmkfstools
Run a single command to enlarge your partition ("vmkfstools -X 50g ExchangeSrv.vmdk" ["50g" is for 50GB the size you want, and "ExchangeSrv.vmdk" is for the server name]) and all your troubles go away. Or that's how all the documentation sounded. Problem is, you can't run this command via VI or a command line on ESXi out-of-the-box. A number of advanced functionality for ESX require run command line based commands. The only way to do this with ESXi, is to enable console access. This is NOT supported on ESXi by VMware and use your judgement (similar warnings when using regedit). So, to gain console access, I found this handy blog posting that gave a summary how to enable SSH access for ESXi (I found it better than the VMware KB tech article). This is when I had to remember my days back on AIX with the vi editor. Since you need to modify a configuration file, and it's a bit tricky. You'll need to google "vi" if you need help. I then had ssh root access to my ESXi server.
So, I ran the command and then issued a "ls -l" and noticed the server vmdk had increased to 50GB. Awesome, I figured I was done. Nope. So, I then had to run the process in attempt #3, GParted. I ran that and it saw the extra 20GB and enlarged the partition. Almost there. Until I rebooted the server and it failed to boot with a non-bootable error of "winload.exe is missing or corrupt." I started the repair process and then realized I didn't want a base image to be off a corrupt partition or possible issues with files. So, at this point I scrapped the process and did a re-install of 2008.
The best part of Windows Server 2008 is I can install it under 40 minutes on the hardware I'm running. So, this makes it very fast. Also, I recommend you make OS partitions at least 40-50GB. I plan on using a secondary partition for Exchange databases, but I still wanted extra space on the 1st partition. Here are the Microsoft Windows Server 2008 System Requirements. So, I have my 50GB OS partition and a 2nd for the Exchange databases. I return to installing Exchange now.
Good site to explain VMware's resizing of Virtual Disks (primarily for Windows 2003)
Side Notes
- Windows Server 2008 annoyance, why is hibernation enabled on a server OS. I quickly noticed storage was being used up faster than it should. I found out a hibernate file is created on the root of c:\. To delete it and disable this "very useful" [note sarcasm] server feature, open a command prompt and enter "powercfg -h OFF". And it'll delete the file and disable the feature.
- thin provisioning capability (means, create a 50GB partition, and have it dynamically grow. So, only use what you need). Only downside of this, is a reduction in performance. It's only available to SAN based storage. I'll need to explore that in the future.
- I tend to recommend folks avoid Dynamic Disks and GPT based partitions unless there is a requirement to select these since compatibility can easily become a problem with these types of disks. GPT is used when you want partitions over 2TB, as per Dynamic disks, for online resizing (I think) and use of OS based RAID types.
Until next time,
-Ben
How do you resize partition sizes in VMware ESXi 3.5 (version 110271, VI 2.5 build 103682, VCenter 2.5.0 build 104215) and Windows Server 2008 (these were MBR and Simple volumes)?
1) VI client built-in functionality (VI 2.5 build 103682)
2) DISKPART (as included with Windows 2003)
3) GParted (gparted-livecd-0.3.4-11.iso)
4) VMware Converter (3.0.3 build 89816)
5) vmkfstools (VMware ESXi 3.5 (version 110271)
6) none of the above. Re-install the OS.
Spoiler plot... this does NOT have a happy ending. The answer is 6. If you think you can prove me wrong with the versions above, please let me know how.
If you're a reader of my blog skip to the next paragraph, since this is an executive summary for the non-regulars. I'm in the process of finally upgrading to Exchange 2007 from 2003. I've decided to make it a challenge and do it on a platform I have had no experience with, Windows Server 2008. All my clients and all my servers are Windows 2003 or a variation (e.g. R2, x64, etc). To make it even more difficult, even though I have extensive experience with VMware Server and Workstation, I'm running it under VMware ESXi 3.5 [embedded & w/virtual center]. ESXi is a different beast than other VMware products. It contains a WHOLE lot more functionality especially when you add Virtual Center.
After a few months of planning on functionality & redundancy desired, hardware sizing, migration plans, and a number of other factors, I took the plunge into testing. So, I created my base OS images of Windows 2003 (x32) and Windows 2008 (x64) to test for 1 month which turned into 4 months. After I was done testing installs and configurations, I deleted all those images and started again. The party began.
So, I setup base OS images with 30GB partitions since I was planning on adding a minimum of 14 images & 12 virtual machines (aka vm's). Space is a concern since it is 6 x 300GB SAS 10k hard drives in direct attached storage (DAS) in a RAID 10 config. Problem was I mistakenly made the 2008 system partition size 30GB. I figured, it would be large enough. I'm blogging about this, so obviously it was not and the attempted fix wasn't a quick 1-2-3 or even a 2-3 hour fix.
Attempt #1 - How VMware hard drive resizing is suppose to work
So, after making my 2008 partition size 30GB, I figured the beauty of VMware would show of it's skills. Similar to VMware Server & Workstation, you right-click and enter the new larger hard drive size, and click OK, and a few seconds later it would be increased to 50GB. No such luck. Attempting this resulted in ESXi simply ignoring my request to enlarge the partition. No error, nothing. It stayed on 30GB. A bit of research indicated that Windows Server 2008 is NOT supported for hard drive increases via the VMware Infrastructure Client (aka VI). So, I looked into the other options.
Attempt #2 - Diskpart
This techtarget.com article talks about Diskpart, but all the screenshots are 2003 related, so I didn't even bother, since I figured since diskpart shipped with Windows 2003 SP1, it probably was a dead-end solution. Diskpar was Windows 2003 related, diskpart was 2003 SP1 related. You can find a good article about Exchange 2003 and align your partitions for database storage here.
Attempt #3 - GParted
As per attempt #2, that same techtarget article talks about using an open-source partition tool. I uploaded the ISO to the datastore, did the booting, and attempted to modify the partition to 50GB. It reported no additional space execpt for one more 1MB. Obviously, that isn't correct. Next....
Attempt #4 - VMware Converter
I tried this 2 different ways since some sites including the above techtech article here talked about running VMware Converter directly on the server you are attempting to modify the hard drive partition size, and via a remote server. In my case I attempted via Virtual Center. Both ways failed with the same error "Unable to determine Guest Operating system". Problem: Windows Server 2008 is not supported. Oops. Next attempt.
Attempt #5 - vmkfstools
Run a single command to enlarge your partition ("vmkfstools -X 50g ExchangeSrv.vmdk" ["50g" is for 50GB the size you want, and "ExchangeSrv.vmdk" is for the server name]) and all your troubles go away. Or that's how all the documentation sounded. Problem is, you can't run this command via VI or a command line on ESXi out-of-the-box. A number of advanced functionality for ESX require run command line based commands. The only way to do this with ESXi, is to enable console access. This is NOT supported on ESXi by VMware and use your judgement (similar warnings when using regedit). So, to gain console access, I found this handy blog posting that gave a summary how to enable SSH access for ESXi (I found it better than the VMware KB tech article). This is when I had to remember my days back on AIX with the vi editor. Since you need to modify a configuration file, and it's a bit tricky. You'll need to google "vi" if you need help. I then had ssh root access to my ESXi server.
So, I ran the command and then issued a "ls -l" and noticed the server vmdk had increased to 50GB. Awesome, I figured I was done. Nope. So, I then had to run the process in attempt #3, GParted. I ran that and it saw the extra 20GB and enlarged the partition. Almost there. Until I rebooted the server and it failed to boot with a non-bootable error of "winload.exe is missing or corrupt." I started the repair process and then realized I didn't want a base image to be off a corrupt partition or possible issues with files. So, at this point I scrapped the process and did a re-install of 2008.
The best part of Windows Server 2008 is I can install it under 40 minutes on the hardware I'm running. So, this makes it very fast. Also, I recommend you make OS partitions at least 40-50GB. I plan on using a secondary partition for Exchange databases, but I still wanted extra space on the 1st partition. Here are the Microsoft Windows Server 2008 System Requirements. So, I have my 50GB OS partition and a 2nd for the Exchange databases. I return to installing Exchange now.
Good site to explain VMware's resizing of Virtual Disks (primarily for Windows 2003)
Side Notes
- Windows Server 2008 annoyance, why is hibernation enabled on a server OS. I quickly noticed storage was being used up faster than it should. I found out a hibernate file is created on the root of c:\. To delete it and disable this "very useful" [note sarcasm] server feature, open a command prompt and enter "powercfg -h OFF". And it'll delete the file and disable the feature.
- thin provisioning capability (means, create a 50GB partition, and have it dynamically grow. So, only use what you need). Only downside of this, is a reduction in performance. It's only available to SAN based storage. I'll need to explore that in the future.
- I tend to recommend folks avoid Dynamic Disks and GPT based partitions unless there is a requirement to select these since compatibility can easily become a problem with these types of disks. GPT is used when you want partitions over 2TB, as per Dynamic disks, for online resizing (I think) and use of OS based RAID types.
Until next time,
-Ben
Tuesday, December 2, 2008
Emptying Those Pesky OLK Folders (Outlook design flaw)
Hello All,
This came up on the New York Exchange Server User Group (aka NYExUG) Google Group mailing list. See below to download the script to empty those pesky Outlook 2003 OLK folders.
Down Here: Magical Script to Purge the Outlook OLK Folder
Background on the issue. When an Outlook 2003 (not sure if Outlook 2007 has the same problem) user opens an attachment, Outlook creates a cached copy (with a similar name and a few digits) in a hidden OLK folder (random folder name) in the user's profile. Now, the issue is, if the user opens up the same file name (e.g. scanner creates PDF files named Scanned.pdf", eventually the random digits run out and user will not be able to open the new file due to a same file name error. Of course the error message isn't so clear cut. The reason I call this a design flaw, there isn't a way to clear the Outlook "cache" without manually doing this. I've looked for Group Policy adm add-ons, and a number of other solutions, but in the end, a co-worker of mine at REEF Solutions found and configured a script to empty all OLK folders on Startup. Now, we simply place that script in the startup folder, and "BANG!" every login solves the problem. I'm sure there's a better way to deploy it, but this was a quick and easy solution. If you know how to handle this via GP, post it in the comments.
Until next time.
-Ben
This came up on the New York Exchange Server User Group (aka NYExUG) Google Group mailing list. See below to download the script to empty those pesky Outlook 2003 OLK folders.
Down Here: Magical Script to Purge the Outlook OLK Folder
Background on the issue. When an Outlook 2003 (not sure if Outlook 2007 has the same problem) user opens an attachment, Outlook creates a cached copy (with a similar name and a few digits) in a hidden OLK folder (random folder name) in the user's profile. Now, the issue is, if the user opens up the same file name (e.g. scanner creates PDF files named Scanned.pdf", eventually the random digits run out and user will not be able to open the new file due to a same file name error. Of course the error message isn't so clear cut. The reason I call this a design flaw, there isn't a way to clear the Outlook "cache" without manually doing this. I've looked for Group Policy adm add-ons, and a number of other solutions, but in the end, a co-worker of mine at REEF Solutions found and configured a script to empty all OLK folders on Startup. Now, we simply place that script in the startup folder, and "BANG!" every login solves the problem. I'm sure there's a better way to deploy it, but this was a quick and easy solution. If you know how to handle this via GP, post it in the comments.
Until next time.
-Ben
Friday, November 7, 2008
Feedback on my 1st Exchange 2007 Install running on Windows 2008
Hello Everyone,
So, I decided to really challenge myself. Not only had I never used or installed Exchange 2007, but I decided to do it on an OS I have had no experience with, Windows 2008 Server (I have a test Vista laptop but rarely use it). So, this was a completely new beast to me. Overall, even though Exchange 2007 has a brand new interface, requires more work on user creation, more complicated install requirements, & Microsoft pushes for you to learn PowerShell scripting, Exchange 2007 has a well laid out interface for configuration and the use of wizards makes learning this product easier than Exchange 2003. Yes, you heard that right. This is easier to setup and manage than Exchange 2003 out of the box. Anyone who is familiar with Exchange 2003, should not have an issue learning Exchange 2007. The learning curve is a lot easier than expected. Remember, I've never seen Exchange 2007 nor have I used Windows 2008 and was able to get the Exchange Server functionality up and running fairly quickly. Good job Microsoft!
My complaints seeing it for the first time, are minor issues, such as copying text from dialog boxes is either not possible or limited, fancy GUI is a waste of CPU processing [View -> Visual Effects -> Never resolves that], and wizards take longer to execute than the old ESM or setting the configuration yourself. But Microsoft has made your life a lot easier with a one stop article (below) to install it. So, would I recommend everyone go out and upgrade, no. I'll address who should upgrade in a future post.
Well, it's taken me a while to finally get to the point of testing Exchange 2007 since performance has not been an issue so far with all the Exchange 2003 environments I've worked on (maybe after a hardware upgrade though). Which is a compliment to Exchange 2003. It's a great product since it's rock solid and scalable when you properly size your Exchange Server.
So, I'm testing Exchange 2007 SP1 (remember, SP1 is the full software code so you don't need to install the base and then SP1, just install the full version via SP1) on the following:
- Windows 2008 Server x64
- OS running under VMware ESx 3i 3.5
- VM configured for 2 CPUs (up to 3GHz/cpu, 8192MB, 30GB OS partition, 240GB Exchange install partition [not needed, but plan to deploy my "production" environment in this configuration].
- non-internet based network (in VMware speak, it's called a "virtual switch")
Recommend you read the following Microsoft article for pre-requisites for Windows 2008 or Vista. This article is excellent and includes the command line code needed to load the necessary software (e.g. Roles, Features, etc).
This URL is a gold mine of information. Save this!!!
http://technet.microsoft.com/en-us/library/bb691354.aspx
I ran the typical install (all roles minus Unified Messaging on a single server) of Exchange Server 2007 SP1 setup on a Windows 2008 Server after running the pre-requisites as per Microsoft above, I received the following error:
The Active Directory Schema is not up-to-date and Ldifde.exe is not installed on this computer. You must install Ldifde.exe by running 'ServerManagerCmd -i RSAT -ADDS' or restart setup on a domain controller.
Turns out I missed the following command (on the above URL) which I promptly ran on the planned Exchange server and rebooted. My AD is based on Windows 2003 Native Mode environment.
-------------------------
C:\Users\administrator.domaintest>ServerManagerCmd -i RSAT-ADDS
.
Start Installation...
[Installation] Succeeded: .
[Installation] Succeeded: [Remote Server Administration Tools] Active Directory
Domain Services Tools.
Warning: [Installation] Succeeded: [Remote Server Administration Tools] Active D
irectory Domain Controller Tools. You must restart this server to finish the ins
tallation process.
Warning: [Installation] Succeeded: [Remote Server Administration Tools] Server f
or NIS Tools. You must restart this server to finish the installation process.
<100/100>
Success: A restart is required to complete the installation.
C:\Users\administrator.domaintest>
------------------
Next issue was the following SMTP detection issue. The answer to create a "Send Connector" as per http://support.microsoft.com/kb/556055 .
---------------
Hub Transport Role Prerequisites
Completed
Warning:
Setup cannot detect an SMTP or Send connector with an address space of '*'. Mail flow to the Internet may not work properly.
Elapsed Time: 00:00:14
---------------
On to the install. When the Exchange setup runs the pre-requisites, it attempts to connect to Microsoft for the latest requirements. Since there is no internet, it fails but it's not reported. This is the setup dialog as it continues. Technically you could disable this auto-internet check using ExBPA and configuring some xml files, but I don't think it's worth the time.

Process took 50 minutes to complete. No errors reported. The next steps are presented by the Exchange Management Console. Here are the more important configuration steps to get up and running in order of importance.
- configure domains for which you will accept e-mail
- configure internet mail flow
- configure the E-mail Address Policies (formerly known as Recipient Update Policy) to automatically change all your users "from" address
[optional/recommended] - configure OAB public folder distribution for Outlook 2003 and earlier
[optional/recommended] - configure SSL for CAS (Client Access Server)
[optional] - configure ActiveSync
[optional] - configure offline address book (OAB) for Outlook 2007
[optional] configure an external postmaster recipient to receive mails from our systems (e.g. NDRs, etc)
I performed the following:
"Configure Domains for which You Will Accept E-mail"
Clicking on the link inside the wizard pointed me to the correct location and then I selected the Actions "New Accepted Domain". You type the "Accepted Domain" which is your emailed domain, and then you probably want to leave it as "Authoritative Domain". If you don't know what this means, this is most likely your correct setting. The other 2 options are Internal Relay Domain and External Relay Domain. Then you're done while you wait for the wizard to run the command which took 15 seconds on my server.
After completing the above, you probably want to make that domain your default. So, highlight the domain you added, and on the Actions, click "Set as Default".
Now, you can receive if you've configured your firewall and DNS for this domain, but you need to be able to send email.
Next step - configuring sending email. In Exchange 2007 speak, "Configure internet mail flow"
Exchange Management Console -> Organization Configuration -> Hub Transport -> Send Connectors tab -> click "New Send Connector..." Actions.
Now you have 4 options
Custom - for sending via non-Exchange servers (e.g. relay servers, your smtp gateway server, etc)
Internal - for sending email to other Exchange servers
Internet - use DNS to route email out. Connect to our domains servers directly.
Partner - for sending to domains with TLS encryption that are listed on the "domain-secure domains".
I selected custom, and for the Address space, listed the accepted domain as entered above, and left all settings as is. Network settings (Use domain name system) which means your Exchange Server will communicate to a variety of other servers on the internet or "Route mail through the following smart hosts". I selected a smart host and entered the LAN IP of it (I never allow my Exchange Server to communicate on the internet. All mail inbound and outbound is routed via another smtp server). Now, under "Configure smart host authentication settings", I left this to "None" since I whitelist the Exchange Server on the smtp relay server. "Source Server" lists this Exchange Server.
Configuring the E-mail Address Policies to change the "from" address
Organization Configuration -> Hub Transport -> E-mail Address Policies -> right-click Default Policy and select Edit.
- add an additional domain entry under "E-Mail Addresses". This is typically your new accepted domain.
- I left the default "E-mail address local part" to "Use alias"
- check "Select accepted domain for e-mail address:" and Browse and select domain used above for "new accepted domain"
- highlight newly added SMTP e-mail address, and select "Set as Reply". It should become bold now.
Adding your First Email User Account
- Now this is back to the good ol' days of Exchange 5.5, somewhat, but not as bad as when Exchange 2007 was first released. You can add the user account in AD, and then head over to the EMC (Exchange Management Console in 2007, formerly ESM in 2003, Exchange System Manager) and under Recipient Configuration -> Mailbox -> New Mailbox... under Actions. You want the basic User Mailbox (there are numerous other options). For User Type, select Existing Users, and select the user(s). Select the Mailbox database and "Exchange ActiveSync mailbox policy" if you plan to use that and then click Next. Or you can have EMC create the AD account and then go to the container called "Users" and move it to the correct OU. Hopefully SP2 or an update allows you to select the OU to place the user(s) being created.
And that's it. I logged into Outlook Web Access, and thanks to Microsoft for loading a SSL certificate so out of the box, OWA can be secure & support forms based authenication (major difference from 2003). Some screen shots of OWA and OWA Light. Enjoy.
Initial OWA Login Screen

Your 1st Login Screen and Prompt to Set Time Zone and Language - this is an improvement from Exchange 2003/2000 which the end user had to know to click Settings and set this information.

Logged in OWA on Exchange 2007 running IE 7

Logged in OWA Light on Exchange 2007 running IE 7. This would be similar to Firefox, Safari, and other non-IE browsers.

Comments, feedback, etc.
-Ben
So, I decided to really challenge myself. Not only had I never used or installed Exchange 2007, but I decided to do it on an OS I have had no experience with, Windows 2008 Server (I have a test Vista laptop but rarely use it). So, this was a completely new beast to me. Overall, even though Exchange 2007 has a brand new interface, requires more work on user creation, more complicated install requirements, & Microsoft pushes for you to learn PowerShell scripting, Exchange 2007 has a well laid out interface for configuration and the use of wizards makes learning this product easier than Exchange 2003. Yes, you heard that right. This is easier to setup and manage than Exchange 2003 out of the box. Anyone who is familiar with Exchange 2003, should not have an issue learning Exchange 2007. The learning curve is a lot easier than expected. Remember, I've never seen Exchange 2007 nor have I used Windows 2008 and was able to get the Exchange Server functionality up and running fairly quickly. Good job Microsoft!
My complaints seeing it for the first time, are minor issues, such as copying text from dialog boxes is either not possible or limited, fancy GUI is a waste of CPU processing [View -> Visual Effects -> Never resolves that], and wizards take longer to execute than the old ESM or setting the configuration yourself. But Microsoft has made your life a lot easier with a one stop article (below) to install it. So, would I recommend everyone go out and upgrade, no. I'll address who should upgrade in a future post.
Well, it's taken me a while to finally get to the point of testing Exchange 2007 since performance has not been an issue so far with all the Exchange 2003 environments I've worked on (maybe after a hardware upgrade though). Which is a compliment to Exchange 2003. It's a great product since it's rock solid and scalable when you properly size your Exchange Server.
So, I'm testing Exchange 2007 SP1 (remember, SP1 is the full software code so you don't need to install the base and then SP1, just install the full version via SP1) on the following:
- Windows 2008 Server x64
- OS running under VMware ESx 3i 3.5
- VM configured for 2 CPUs (up to 3GHz/cpu, 8192MB, 30GB OS partition, 240GB Exchange install partition [not needed, but plan to deploy my "production" environment in this configuration].
- non-internet based network (in VMware speak, it's called a "virtual switch")
Recommend you read the following Microsoft article for pre-requisites for Windows 2008 or Vista. This article is excellent and includes the command line code needed to load the necessary software (e.g. Roles, Features, etc).
This URL is a gold mine of information. Save this!!!
http://technet.microsoft.com/en-us/library/bb691354.aspx
I ran the typical install (all roles minus Unified Messaging on a single server) of Exchange Server 2007 SP1 setup on a Windows 2008 Server after running the pre-requisites as per Microsoft above, I received the following error:
The Active Directory Schema is not up-to-date and Ldifde.exe is not installed on this computer. You must install Ldifde.exe by running 'ServerManagerCmd -i RSAT -ADDS' or restart setup on a domain controller.
Turns out I missed the following command (on the above URL) which I promptly ran on the planned Exchange server and rebooted. My AD is based on Windows 2003 Native Mode environment.
-------------------------
C:\Users\administrator.domaintest>ServerManagerCmd -i RSAT-ADDS
.
Start Installation...
[Installation] Succeeded: .
[Installation] Succeeded: [Remote Server Administration Tools] Active Directory
Domain Services Tools.
Warning: [Installation] Succeeded: [Remote Server Administration Tools] Active D
irectory Domain Controller Tools. You must restart this server to finish the ins
tallation process.
Warning: [Installation] Succeeded: [Remote Server Administration Tools] Server f
or NIS Tools. You must restart this server to finish the installation process.
<100/100>
Success: A restart is required to complete the installation.
C:\Users\administrator.domaintest>
------------------
Next issue was the following SMTP detection issue. The answer to create a "Send Connector" as per http://support.microsoft.com/kb/556055 .
---------------
Hub Transport Role Prerequisites
Completed
Warning:
Setup cannot detect an SMTP or Send connector with an address space of '*'. Mail flow to the Internet may not work properly.
Elapsed Time: 00:00:14
---------------
On to the install. When the Exchange setup runs the pre-requisites, it attempts to connect to Microsoft for the latest requirements. Since there is no internet, it fails but it's not reported. This is the setup dialog as it continues. Technically you could disable this auto-internet check using ExBPA and configuring some xml files, but I don't think it's worth the time.
Process took 50 minutes to complete. No errors reported. The next steps are presented by the Exchange Management Console. Here are the more important configuration steps to get up and running in order of importance.
- configure domains for which you will accept e-mail
- configure internet mail flow
- configure the E-mail Address Policies (formerly known as Recipient Update Policy) to automatically change all your users "from" address
[optional/recommended] - configure OAB public folder distribution for Outlook 2003 and earlier
[optional/recommended] - configure SSL for CAS (Client Access Server)
[optional] - configure ActiveSync
[optional] - configure offline address book (OAB) for Outlook 2007
[optional] configure an external postmaster recipient to receive mails from our systems (e.g. NDRs, etc)
I performed the following:
"Configure Domains for which You Will Accept E-mail"
Clicking on the link inside the wizard pointed me to the correct location and then I selected the Actions "New Accepted Domain". You type the "Accepted Domain" which is your emailed domain, and then you probably want to leave it as "Authoritative Domain". If you don't know what this means, this is most likely your correct setting. The other 2 options are Internal Relay Domain and External Relay Domain. Then you're done while you wait for the wizard to run the command which took 15 seconds on my server.
After completing the above, you probably want to make that domain your default. So, highlight the domain you added, and on the Actions, click "Set as Default".
Now, you can receive if you've configured your firewall and DNS for this domain, but you need to be able to send email.
Next step - configuring sending email. In Exchange 2007 speak, "Configure internet mail flow"
Exchange Management Console -> Organization Configuration -> Hub Transport -> Send Connectors tab -> click "New Send Connector..." Actions.
Now you have 4 options
Custom - for sending via non-Exchange servers (e.g. relay servers, your smtp gateway server, etc)
Internal - for sending email to other Exchange servers
Internet - use DNS to route email out. Connect to our domains servers directly.
Partner - for sending to domains with TLS encryption that are listed on the "domain-secure domains".
I selected custom, and for the Address space, listed the accepted domain as entered above, and left all settings as is. Network settings (Use domain name system) which means your Exchange Server will communicate to a variety of other servers on the internet or "Route mail through the following smart hosts". I selected a smart host and entered the LAN IP of it (I never allow my Exchange Server to communicate on the internet. All mail inbound and outbound is routed via another smtp server). Now, under "Configure smart host authentication settings", I left this to "None" since I whitelist the Exchange Server on the smtp relay server. "Source Server" lists this Exchange Server.
Configuring the E-mail Address Policies to change the "from" address
Organization Configuration -> Hub Transport -> E-mail Address Policies -> right-click Default Policy and select Edit.
- add an additional domain entry under "E-Mail Addresses". This is typically your new accepted domain.
- I left the default "E-mail address local part" to "Use alias"
- check "Select accepted domain for e-mail address:" and Browse and select domain used above for "new accepted domain"
- highlight newly added SMTP e-mail address, and select "Set as Reply". It should become bold now.
Adding your First Email User Account
- Now this is back to the good ol' days of Exchange 5.5, somewhat, but not as bad as when Exchange 2007 was first released. You can add the user account in AD, and then head over to the EMC (Exchange Management Console in 2007, formerly ESM in 2003, Exchange System Manager) and under Recipient Configuration -> Mailbox -> New Mailbox... under Actions. You want the basic User Mailbox (there are numerous other options). For User Type, select Existing Users, and select the user(s). Select the Mailbox database and "Exchange ActiveSync mailbox policy" if you plan to use that and then click Next. Or you can have EMC create the AD account and then go to the container called "Users" and move it to the correct OU. Hopefully SP2 or an update allows you to select the OU to place the user(s) being created.
And that's it. I logged into Outlook Web Access, and thanks to Microsoft for loading a SSL certificate so out of the box, OWA can be secure & support forms based authenication (major difference from 2003). Some screen shots of OWA and OWA Light. Enjoy.
Initial OWA Login Screen
Your 1st Login Screen and Prompt to Set Time Zone and Language - this is an improvement from Exchange 2003/2000 which the end user had to know to click Settings and set this information.
Logged in OWA on Exchange 2007 running IE 7
Logged in OWA Light on Exchange 2007 running IE 7. This would be similar to Firefox, Safari, and other non-IE browsers.
Comments, feedback, etc.
-Ben
Subscribe to:
Posts (Atom)