Thursday, August 11, 2011

Installing Exchange Server 2007


Lesson 1: 
In this lesson, you will learn how to perform the installation of Exchange Server 2007 and ancillary components such as clustering, antivirus, and anti-spam. As part of the predeployment process, you will have determined which Exchange Server roles are appropriate for your organization and prepared the appropriate software environment for the installation of these roles. The lesson will then discuss the methods of installing Exchange Server 2007 and how to configure SSL and Network Load Balancing (NLB). The lesson will examine steps that should be taken prior to implementing clustering and adding antivirus and anti-spam protection to Exchange Server 2007.

After this lesson, you will be able to:
  • Select the appropriate roles for an Exchange Server deployment given a set of organizational requirements.
  • Perform a GUI-based, unattended, and command-line install of Exchange Server 2007.
  • Install extra components, such as those that support clustering, load balancing, cryptography, antivirus, and spam-blocking functionality.
Estimated lesson time: 40 minutes


Choosing the Appropriate Role or Roles for the Server

The roles that you install on a computer running Exchange Server 2007 are determined by a set of needs. For example, if your organization is going to use only traditional e-mail and does not intend Exchange to meet voice-messaging or fax storage roles, you need not install the Unified Messaging server role. Part of the 70-236 exam involves being able to decide which roles to install on an Exchange Server 2007 computer given a specific set of organizational requirements. The first part of this lesson will provide you with the information that will help you make such a recommendation. In the second part of the lesson, we will examine the configuration of clustering, load balancing, and the steps that you should take to protect against spam and viruses. When determining which roles to deploy on a computer, remember that each Active Directory site in which clients will access Exchange resources requires at least one Mailbox server, a Hub Transport server, and a Client Access server.
MORE INFO Typical Exchange Server 2007 setup
For more information on performing a typical Exchange Server 2007 setup, consult the following link: http://technet.microsoft.com/en-us/library/bb123694.aspx.


Edge Transport Role

Edge Tansport servers route messages between the Internet and your Exchange organization. Edge Transport servers are placed on an organization’s perimeter network and are not members of the Active Directory environment. A perimeter network is a location between an outer firewall and an inner firewall. Other vendors sometimes refer to perimeter networks as screened subnets or demilitarized zones. Rather than traffic passing through a firewall directly to a protected internal network, perimeter networks are configured so that traffic can pass only from unprotected networks, such as the Internet, to the perimeter network or from the protected network to the perimeter network. Hosts located on the perimeter network are used to relay that traffic.
NOTE
To find out more about perimeter networks, access the following link: http:// technet2.microsoft.com/windowsserver/en/library/10e8360c-c0fe-4a52-87e8-cd8b42e446281033.mspx?mfr=true


Edge Transport servers are often used as a blockade point for incoming and outgoing mail, ensuring that the mail is checked for viruses or unsolicited commercial e-mail, known colloquially as spam, prior to leaving the perimeter network. If problematic messages can be discarded on the perimeter of your organization’s network, they will not clog up your internal mail infrastructure. If only 50 percent of the mail that is addressed to your organization is spam, dealing with it at the edge of your organization’s network will halve the load on the rest of your mail infrastructure.
The main consideration with Edge Transport servers is that this role can be installed only if other roles are not present. Edge Transport servers should be placed only on perimeter networks. If your organization has no perimeter network, you should install the Hub Transport server role instead.

Hub Transport Role

The purpose of the Hub Transport role is to route traffic between Active Directory sites. If your organization has multiple Active Directory sites, any message you send to someone in a remote site will be routed to that site through your organization’s Hub Transport servers. Exchange servers assigned the Hub Transport role are deployed on the protected network and are members of the Active Directory environment. At least one server assigned the Hub Transport role is required at each site for mail to be routed correctly. Servers with the Hub Transport role function in a manner similar to that of the bridgehead servers in earlier versions of Exchange.
In the event that you do not deploy an Edge Transport server, a server configured with the Hub Transport role can be used to receive and send mail traffic to the Internet. Many small and medium-sized organizations are likely to use the Hub Transport role to handle this traffic, especially if they have only a small number of computers running Exchange Server 2007. Like a server assigned the Edge Transport role, a server assigned the Hub Transport role can be configured to examine the traffic that it processes for viruses and spam. The Hub Transport role can coexist with the Client Access, Unified Messaging, and Mailbox server roles.

Client Access Role

The Client Access role provides a gateway between clients and their mailboxes. A client computer running Outlook or Exchange ActiveSync or connected using a Web browser to Outlook Web Access (OWA) connects to the Client Access server, which in turn connects to the appropriate Mailbox server. The Client Access server role is designed to optimize the performance of the Mailbox server by offloading the processing requirements. For example, rather than having the server hosting mailboxes be responsible for performing the necessary calculations to encrypt SSL traffic, this task is handled by the Client Access server. Of course, in many situations, the Client Access role will be hosted on the same computer as the Mailbox server role. The ability to separate these tasks onto a different computer allows administrators to optimize their Exchange organization.
If a single external URL of OWA or Exchange ActiveSync is required, Client Access servers must be configured for proxying. The Client Access server should be connected to the Mailbox servers it provides access to with a bandwidth of at least 100 Mbps. In enterprise environments, a gigabit connection is preferable. This means that you should have a Client Access server located in each site where there is a Mailbox server.

Mailbox Server Role

The Mailbox server role hosts mailboxes and public folders. Mailbox servers are where all the message data is stored, so they need to be provisioned with more disk space than any other role in your Exchange organization. There needs to be a computer hosting the Mailbox server role in each location where mail will be accessed. Besides storing message data, Mailbox servers also provide the scheduling services for Microsoft Office Outlook users.

Clustered Mailbox Roles

Clustered Mailbox servers provide high availability through the use of Windows Server 2003 and Windows Server 2008 clustering technology. You would choose this role over the standard Mailbox server role if you needed to ensure that mailboxes were always available. Of course, you want mailboxes to be available all the time anyway, but to ensure that they are, your organization will have to spend the money to host them on a cluster. Because of their reliance on clustering technology, you can install the Clustered Mailbox server roles only on computers running Windows Server 2003 enterprise edition or Windows Server 2008 enterprise edition. The standard editions of Windows Server software do not support the necessary form of clustering. Clustered Mailbox servers cannot share hardware with other server roles. If you select one of the Clustered Mailbox options during the installation process, as shown in Figure 2-1, you will not be able to install any other server roles.
Cc505857.figure_C02624108_1(en-us,TechNet.10).png
Figure 2-1 Installing the Active Clustered Mailbox role
There are two separate types of Clustered Mailbox role:
  • Active Clustered Mailbox role This role provides highly available, redundant e-mail storage. Install this role on the active node of the cluster.
  • Passive Clustered Mailbox role This role provides highly available, redundant e-mail storage. Install this role on the passive node of the cluster.
MORE INFO More on Mailbox servers
If you want to find out more about standard and Clustered Mailbox servers, consult the following link: http://technet.microsoft.com/en-us/library/bb201699.aspx.


Unified Messaging Server Role

Unified Messaging allows users to access their Exchange Server 2007 mailbox over an appropriately configured smart phone or telephone. You should deploy one Unified Messaging server in each site where you want to provide access to its services. When deployed, Unified Messaging provides the following features:
  • Answering machine
  • Fax reception
  • Subscriber access
    • Access voice mail over telephone
    • Listen to, forward, and reply to e-mail messages over the telephone
    • Listen to calendar information over the telephone
    • Dial contacts stored within Exchange over the telephone
    • Respond to meeting requests over the telephone
Exam Tip
The 70-236 exam objectives do not mention this role directly, but we thought it prudent to provide you with some information about the role’s functionality in case the topic turns up in some capacity.


NOTE Unified Messaging For more information on the capabilities of the Unified Messaging server role, consult the following link: http://technet.microsoft.com/en-us/library/bb123911.aspx.

Quick Check

  1. What are the requirements that need to be met to install the Edge Transport role on a computer running Windows Server 2003 R2 64-bit edition?
  2. Which server role can be used to manage the routing of e-mail into and out of an organization in the event that the Edge Transport server role is not deployed?

Quick Check Answers

  1. The computer cannot be a member of the domain. Active Directory Application Mode (ADAM) must be installed. Server should be deployed on the perimeter network.
  2. In the event that a server with the Edge Transport role is not deployed, a server with the Hub Transport role can manage the routing of e-mail into and out of the organization.


Preparing an Exchange Server 2007 Cluster

You can use clustering with Exchange Server 2007 only if you are also using Windows Server 2003 (or Windows Server 2008) enterprise edition. This is because Exchange Server 2007 relies on the Windows Cluster service, which is unavailable in the standard edition of Windows Server 2003. When you start Exchange Server 2007 setup on a node of an existing cluster, a version of Exchange that is compatible with clusters is installed. You cannot install Exchange Server 2007 on a server that is not a member of a cluster, join the server to a cluster, and then configure Exchange Server 2007 to work in a clustered configuration. If you want to shift from a standard Mailbox server role to a Clustered Mailbox server role, it will be necessary to remove Exchange entirely and reinstall the software before assigning the role. Chapter 13, “Recovering Server Roles and Configuring High Availability,” covers Exchange Server 2007 clustering in more detail.
MORE INFO More on High Availability
To find out more about Exchange Server 2007 high-availability solutions, consult the following link: http://technet.microsoft.com/en-us/library/bb124721.aspx.


Load Balancing

When two or more servers are configured to load balance, they accept requests on the basis of their current workload. For example, if two servers are configured to load balance and the first server is under greater workload than the second server, client requests will be directed to the second server until such time as the workload is balanced more evenly between the computers in the load-balancing set. Load balancing is used primarily with the Client Access, Edge Transport, and Hub Transport server roles.
An advantage of load balancing is that it is not necessary to configure it prior to the installation of Exchange Server 2007. Another advantage is that you are able to add and remove nodes without a significant amount of effort. For example, if you have load-balanced Edge Transport servers that are straining under the weight of transmitting and receiving e-mail, it is relatively simple to add another Edge Transport server to the NLB cluster and have it automatically share the load with the existing servers. In the event that a server fails in an NLB cluster, the NLB service automatically reconfigures the way it distributes traffic until the failed server can be brought back online.
MORE INFO NLB
To find out more about how to set up NLB, consult the following link: http://go.microsoft.com/fwlink/ ?linkid=49315.


Lesson 2 of Chapter 13 covers the configuration of network load balancing in Exchange Server 2007 in more detail. Round-robin DNS also provides a good way of load balancing Hub Transport roles within a particular site. The drawback of using round-robin DNS as a load balancing solution is that, unlike NLB, round-robin DNS cannot automatically detect the failure of one of the load-balanced hosts.
MORE INFO Round-robin DNS
For more information about configuring round-robin DNS, consult the following link: http:// technet2.microsoft.com/windowsserver/f/?en/library/e0f49958-f290-49fc-adb4-71ed8deefd621033.mspx.


Installing Exchange Server 2007 Using the GUI

Exchange Server setup using the GUI can be completed using two options, as shown in Figure 2-2. Selecting the Typical Exchange Server Installation option with Hub Transport, Client Access, and Mailbox server roles. The Exchange Management tools will also be installed, as it is not possible to install any role without the management tools also being installed. It is possible to install the Edge Transport, Unified Messaging, or Clustered Mailbox server roles only if you select a custom install.
Cc505857.figure_C02624108_2(en-us,TechNet.10).png
Figure 2-2 Selecting the installation type
Once you have selected the roles to be installed, either through the typical or the custom setup screen, the Exchange Server 2007 installation routine performs a series of readiness checks, shown in Figure 2-3, to determine that the environment is ready for installation. If the readiness checks are passed, the wizard proceeds to installation. If the readiness checks fail, you will be informed as to the reason for the failure, and the installation process will terminate. During the installation, the Exchange Server 2007 installation files will be copied to the server. This means that if you need to add or remove a role at a later date—assuming that you have installed a role that can coexist with other roles—you will not need to remember where you put the installation media.
When the installation process finishes, the Exchange Server 2007 Finalize Deployment checklist is displayed. The Finalize Deployment checklist reminds you to perform the following tasks:
  • Enter the Exchange Server product key
  • Run the Exchange Best Practices Analyzer
  • Configure offline address book distribution for Outlook 2007 clients
  • Configure offline address book distribution for Outlook 2003 and earlier clients
  • Configure SSL for your Client Access server
  • Configure Exchange ActiveSync
  • Configure domains for which you will accept e-mail
  • Subscribe the Edge Transport server
  • Create a postmaster mailbox
  • Configure Unified Messaging
The methods through which you can complete these tasks will be covered throughout the rest of this chapter.
Cc505857.figure_C02624108_3(en-us,TechNet.10).png
Figure 2-3 Readiness checks

Command-Line and Unattended Installations of Exchange Server 2007

You are unlikely to use the unattended installation features of Exchange Server 2007 if you need to configure only one or two Exchange servers. If you need to deploy 50 identically configured servers running Exchange Server 2007, the option to perform an unattended installation becomes far more attractive. The unattended installation feature allows you to perform large deployments of Exchange Server 2007 without having to constantly configure the same set of options through the GUI.
BEST PRACTICES Do it the easy way first
You should be familiar with the requirements of a typical installation before you attempt to run your first unattended installation. Virtual machines are an excellent environment in which to test unattended installations to ensure that you’ve set everything up correctly. You do not want to run 50 unattended installations using the same script only to find that you’ve made a configuration error.


An unattended installation allows you to set all the Exchange server’s configuration parameters at the start of the installation rather than having to provide them during the installation. Generally, this is done by configuring the options following a single setup command. Although you can use an answer file for part of the installation process, the answer file is used primarily for the installation of Clustered Mailbox roles.
BEST PRACTICES Building a command
Although we talk about command-line installations, when a command contains as many options as the setup command for Exchange Server 2007 does, it is simpler to write the command to a batch file and execute the batch file than it is to type it all out on the command prompt.


Prior to examining all the options that can be used with the command line, we should examine the answer file, which is used in conjunction with the setup command. The first thing to realize is that not everything goes into the answer file. In fact, only a small set of the possible parameters that you can use with a command-line installation can be included in the answer file. The answer file can have the following parameters: CMSName, CMSIPAddress, CMSSharedStorage, CMSDataPath, NewCMS, RemoveCMS, RecoverCMS, UpgradeCMS, EnableLegacyOutlook, LegacyRouting-Server, ServerAdmin, ForeignForestFQDN, OrganizationName, DoNotStartTrans-port, UpdatesDir, EnableErrorReporting, NoSeltSignedCertificates, AdamLdapPort, and AdamSslPort.
A quick look at these parameters shows you that the majority of them have the CMS prefix. CMS is the acronym for Clustered Mailbox server. The answer file is used to ensure that nodes in a cluster have the same configuration. You use a single answer file for each node of the cluster. You generally do not use an answer file for a nonclus-ter Exchange Server 2007 deployment.
The setup command has the following options:
Setup.com [/mode:<setup mode>] [/roles:<server roles to install>] [/OrganizationName:<name for 
the new Exchange organization>] [/TargetDir:<target directory>] [/SourceDir:<source
directory>][/UpdatesDir:<directory from which to install updates>] [/DomainControler <FQDN of 
domain controller>] [/AnswerFile <filename>] [/DoNotStartTransport] 
[/EnableLegacyOutlook] [/LegacyRoutingServer] [/EnableErrorReporting] 
[/NoSelfSignedCertificates] [/AdamLdapPort <port>] [/AdamSslPort <port>] 
[/AddUmLanguagePack:<UM language pack name>] [/RemoveUmLanguagePack:<UM language pack name>]
[/NewProvisionedServer] [/RemoveProvisionedServer] [/ForeignForestFQDN] [/ServerAdmin <user 
or group>] [/NewCms] [/RemoveCms] [/RecoverCms] [/CMSName:<name>] [/CMSIPAddress:<IP address>]
[/CMSSharedStorage] [/CMSDataPath:<CMS data path>] [/?]
    
Many of the options are self-explanatory, and you can use abbreviations rather than entering the full option. The most important ones include the following:
  • /mode or /m You can set this to install, upgrade, uninstall, and recover Server.
  • /role, /roles, or /r Specifies which roles to install. You can install the following:
    • ClientAccess, CA, or C Client Access role
    • EdgeTransport, ET, or E Edge Transport role
    • HubTransport, HT, or H Hub Transport role
    • Mailbox, MB, or M Mailbox role
    • UnifiedMessaging, UM, or U Unified Messaging role
    • ManagementTools, MT, or T Management tools (automatically installed if any other role is selected)
  • /OrganizationName or /on Necessary only when setting up a new Exchange organization. If you have run Setup /PrepAD, then the /OrganizationName switch is unnecessary.
MORE INFO Command-line deployment
For more information about the command-line options not covered here, consult the following link: http://technet.microsoft.com/en-us/library/aa997281.aspx.


Installing an Edge Transport Server

Edge Transport servers should be stand-alone computers that are not members of the Active Directory forest. It follows that the user account used for the installation of the Exchange Server 2007 software does not need to be delegated any of the Exchange administrator roles. When installing the Edge Transport server role using the GUI, ensure that the Windows .NET Framework version 2.0, Windows PowerShell, ADAM with Service Pack 1, and Microsoft Management Console version 3.0 or higher are installed. You also need to ensure that the fully qualified domain name (FQDN) for the server that will host the Edge Transport role is set. You can set this information from the Computer Name tab of System Properties. Prior to installing the Edge Transport role, you should also ensure that the IP addresses assigned to the computer are registered in DNS and that MX records have been set appropriately.
MORE INFO More on ADAM
To find out more about ADAM, consult the following link: http://www.microsoft.com/ windowsserver2003/adam/default.mspx.


You need to choose a custom Exchange Server installation on the Exchange Server 2007 Setup page to be able to select the Edge Transport server role on the Server Role Selection page. Once the role is installed, Exchange Management Console will launch and a list of postinstallation tasks be displayed. These tasks will be covered in more detail in Lesson 2 of this chapter.
Once the Edge Transport server role has been installed, it is possible to clone the configuration of the server so that you can install more Edge Transport servers to share the load. You run an Exchange Management Shell script to export the configuration from the original Edge Transport server to an XML file and then import that XML configuration file on the target server.
NOTE Edge Transport server cloned configuration
You can find out more about configuring Edge Transport servers using cloned configuration by navigating to the following link: http://technet.microsoft.com/en-us/library/aa998622.aspx.



Quick Check

  1. What do the majority of the possible parameters in the answer file relate to?
  2. What command would you use from the command line to install the Edge Transport role on a stand-alone server?

Quick Check Answers

  1. Clustered Mailbox servers.
  2. Setup /mode:install
/roles:EdgeTransport.


Postinstallation Tasks

The quickest way to verify the configuration of a newly installed Exchange Server 2007 deployment is to open an Exchange Management Shell and issue the command get-ExchangeServer | Format-List. This command produces output in the format shown in Figure 2-4. By examining this output, you can determine which server roles have successfully installed as well as other important configuration information, including whether a valid license key has been input.
Cc505857.figure_C02624108_4(en-us,TechNet.10).png
Figure 2-4 You can verify the configuration of an Exchange Server from Exchange Management Shell

Examining Logs for Problems

If you suspect that a deployment has not gone according to plan, you should examine the logs to tease out details of things that may have gone awry. You can search for information in two primary locations:
  • Check the installation logs. The installation logs are located at C:\Program Files\Microsoft\Exchange Server\Logging\SetupLogs.
  • Check the event logs. Events related to Exchange Server 2007 are written to the Application event log. Exchange events include warning, information, and critical errors.
In most cases, you can resolve the issue and then attempt to reinstall the role. You can do this either through Add/Remove Programs or using the setup /mode:reinstall option from the command line.

Applying Updates and Service Packs

In general, you should apply all available updates and service packs to Windows Server 2003 (or Windows Server 2008 in the event you are using it as the host operating system) prior to the installation of Exchange Server 2007. Once the installation process has been successfully completed, you should check whether new service packs or updates exist for Exchange Server 2007. Service packs provide updates and sometimes add new functionality. The best time to deploy updates and service packs is directly after installation. This way, you do not have to worry about taking management’s mailboxes offline while you do maintenance, as you will not have deployed management mailboxes to the server yet.

Assigning Users Roles

Chapter 1 examined what each of the Exchange Server 2007 administrative roles is used for. Once Exchange is installed, it is possible to use the Exchange Management Console to apply these roles to particular users. To do this, open the Exchange Management Console, right-click the Organization Configuration node, and then click Add Exchange Administrator. This will start the Add Exchange Administrator Wizard. As shown in Figure 2-5, you browse to select a user or group and select the role and scope of the role. It is necessary to specify servers for a role only if the Exchange Server administrator role is assigned. If you are assigning the Exchange Server administrator role, you must ensure that the user or group you have assigned this role to is a member of the Local Administrators group on the server you have designated. If the user or group does not have membership of the Local Administrators group, they will be unable to perform some or all of their tasks.
Cc505857.figure_C02624108_5(en-us,TechNet.10).png
Figure 2-5 Adding an Exchange administrator
You can also assign roles to users and groups using Exchange Management Shell. The configuration setting shown in the previous figure can be achieved by entering the following command:
Add-ExchangeAdministrator –Identity ‘tailspintoys.internal/Users/Sam Abolrous’ –Role 
‘ServerAdmin’ –Scope ‘GLASGOW’
    
It is also possible to apply these roles to users by adding user accounts and groups to the appropriate security group in Active Directory Users and Computers, the method used in Chapter 1.
MORE INFO Adding groups to administrator roles
For more information about adding users and groups to administrator roles within an Exchange organization, consult the following link: http://technet.microsoft.com/en-us/library/aa998008.aspx.


Exam Tip Try to keep the purpose of each Exchange Server 2007 role clear in your mind, as there are likely to be questions exploring the differences between each role.


Enter the Product Key

In previous versions of Exchange, you entered a product key during the installation process. If you did not have the product key, you could not complete the installation. With Exchange Server 2007, the license key is entered during a 120-day period after the installation process has been completed. Until the product key is entered, Exchange Server 2007 runs in trial mode. This is functionally equivalent to the normal operational mode of Exchange Server 2007 except that the trial period lasts only 120 days.
As an administrator, this gives you a grace period to ensure that the server you install and activate is deployed in the location that best benefits your organization. It also gives you a chance to be certain that you have configured a server correctly. If you are rushed into product activation, you may activate a server only to find that you have to reinstall from scratch because of some configuration problem that you did not initially notice. You do not need to rush to enter the product key, but also make sure that you do not do it at the last moment.
When you are ready to enter the product key, open the Exchange Management Console, click Server Configuration, select the server that you wish to enter the product key for, and then click Enter Product Key in the Actions box. You then enter the product key in the dialog box shown in Figure 2-6. When you click Enter, the product ID will be generated, and Exchange Server 2007 will be licensed.
Cc505857.figure_C02624108_6(en-us,TechNet.10).png
Figure 2-6 Entering the product key

Installing Antivirus and Anti-spam

E-mail communication is the lifeblood of many businesses. E-mail is also the conduit through which harmful material can enter and exit the organization in the form of viruses. Spam, also known as unsolicited commercial e-mail, is less harmful than viruses in terms of damaging computers and infrastructure. However, dealing with spam does take valuable time away from other tasks. An evaluation of Forefront Security for Exchange Server 2007 is included with the Exchange Server 2007 installation media. In this section, we will briefly look at setting up Forefront. Chapter 6, “Spam, Viruses, and Compliance,” provides more detail on the application and how it can be used to protect your network environment.
During the setup of Forefront Security for Exchange Server, five separate antivirus scanning engines can be installed. You can either go with the random selection of engines performed by the Setup Wizard or choose four engines in addition to the Microsoft Antimalware engine, as shown in Figure 2-7. The engines that you can install as a part of Forefront Security include the following:
  • AhnLab Antivirus Scan Engine
  • CA InoculateIT
  • CA Vet
  • Authentium Command Antivirus
  • Kaspersky Antivirus Technology
  • Norman Virus Control
  • Sophos Virus Detection
  • VirusBuster Antivirus
Cc505857.figure_C02624108_7(en-us,TechNet.10).png
Figure 2-7 Antivirus engine selection
The antivirus engines will be updated on an hourly basis. You cannot configure a proxy server during installation through which the updates can be obtained, though you can use the Forefront Server Security Administrator tool to configure proxy information so that updates can occur. The installation of Forefront is covered by a practice exercise at the end of this lesson.

Securing Communication

SSL provides a way of encrypting traffic between a client and a server and also provides a method of verifying the server’s identity. You most likely have used SSL before when performing activities like shopping online. When the Client Access server role is installed, a self-signed SSL certificate is generated and installed for the default Web site in Internet Information Services. You can view this certificate by clicking View Certificate on the Directory Security tab of the default Web site properties in Internet Information Services. The downside to this automatically generated certificate is that it is issued by an authority that will not be trusted by any clients, including, as Figure 2-8 demonstrates, the computer that issued the certificate.
Cc505857.figure_C02624108_8(en-us,TechNet.10).png
Figure 2-8 The SSL certificate generated by the Client Access server role
By default, client computers and devices trust only certain issuing authorities. You can view such a list of trusted authorities by clicking Certificates in the Content tab of Internet Properties or Internet Options (depending on which version of Windows you are using) in Control Panel. Although in a managed environment it is possible to configure clients to trust the self-generated certificate created with the installation of the Client Access role, it may be cheaper to obtain an SSL certificate from an issuing authority that is already a trusted publisher than to configure a new trusted publisher for all clients that will access Exchange Server 2007 using SSL. Trusted SSL certificates do cost money, but it also costs your organization money to have you spending many hours configuring clients to accept a new certificate-issuing authority as trustworthy. The money saved on not buying a certificate is lost on paying you to configure devices to trust another certification authority (CA).
To obtain an SSL certificate for a server, you have to provide identity details about the server, specifically the server’s DNS name information. If you later decide to change the server’s name, you will need to obtain a new SSL certificate that reflects this name change. You can generate a certificate request file by running the Web
Server Certificate Wizard. It is also possible to generate a certificate request from Exchange Management Shell by issuing the following command: New-ExchangeCer-tificate –GenerateRequest –FriendlyName “SSL Access to Exchange 2007” –DomainName glasgow.tailspintoys.internal –path c:\sslrequest.txt. The certificate request file is then forwarded to a trusted issuing authority that will issue the SSL certificate, generally for a certain fee. The process of requesting and installing an SSL certificate is covered in more detail by a practice exercise at the end of this lesson.

Practice: Exchange Server 2007 Installation and Setup

In these practices, you will perform several exercises that will familiarize you with installing Exchange Server 2007 and performing some postconfiguration steps. Practices 2 and 3 achieve the same goal by different routes, and you should perform only one of these practices before moving on to Practice 4.
NOTE
If you are using virtual machine software that allows for rollbacks or snapshots, it is possible to perform each installation practice, rolling back to the noninstalled configuration after each practice is completed.


Practice 1: Installing Exchange Server Using Graphical Tools

In this practice, you will create user accounts that will be used in the installation and configuration of Exchange Server 2007 in later practices. To complete this practice, perform the following steps:
  1. Log on to the computer that you prepared for the installation of Exchange Server 2007 in the practices at the end of Lesson 2 in Chapter 1.
  2. Open Active Directory Users and Computers and create the following user accounts and add them to the security groups in the table:
    Cc505857.table_C02624108_1(en-us,TechNet.10).png
  3. Set the password of all these accounts to P@ssw0rd and configure the password to never expire.
    NOTE
    In a real-world environment, you would not configure a password to never expire, but this configuration setting simplifies things for the purposes of the practices in this training kit.

  4. Log off.

Practice 2: Installing Exchange Server Using Graphical Tools

In this practice, you will install Exchange Server 2007 using graphical tools. Even if you end up using primarily command-line and scripted installation to deploy Exchange, you will likely be using the graphical tools the first time you deploy Exchange. If you perform Practice 2, it is not necessary to perform Practice 3. To complete this practice, perform the following steps:
  1. Log on with the Kim_Akers account.
  2. Insert the Exchange Server 2007 installation media. If the Exchange Server 2007 splash screen does not appear, open a command prompt, change to the drive that contains the Exchange Server 2007 installation media, and type setup.
  3. Verify that the first three steps under the Install category are grayed out, as shown in Figure 2-9. These steps are grayed out because you installed these components in an earlier lesson. Click Step 4: Install Microsoft Exchange.
    Cc505857.figure_C02624108_9(en-us,TechNet.10).png
    Figure 2-9 The Exchange Server splash screen
  4. On the Introduction page, click Next.
  5. On the License Agreement page, review the license terms. Once you have reviewed the terms, select I Accept The Terms In The License Agreement and then click Next.
  6. On the Error Reporting page, click Next.
  7. On the Installation Type page, click Custom Exchange Server Installation and then click Next.
  8. On the Server Role Selection page, shown in Figure 2-10, select the Mailbox Role, Client Access Role, Hub Transport Role, and Unified Messaging Role options. Click Next.
    Cc505857.figure_C02624108_10(en-us,TechNet.10).png
    Figure 2-10 The Exchange Server splash screen
  9. On the Client Settings page, review the information about Outlook 2003 and Entourage. Verify that No is selected and then click Next.
  10. The Exchange Server 2007 setup process will now perform readiness checks. As you have already installed the required components, this should produce no errors. Once the readiness checks are complete, click Install.
  11. The installation process will take between 20 and 50 minutes to complete, depending on the speed of the computer that you are installing it on. Exchange files will be copied to the server, and then the selected roles will be installed. 12. When all the roles have been installed, you will get a message informing you that Exchange has successfully installed with no errors, as shown in Figure 2-11. Ensure that the Finalize Installation Using The Exchange Management Console option is selected and then click Finish.
    Cc505857.figure_C02624108_11(en-us,TechNet.10).png
    Figure 2-11 Successful installation of Exchange server roles
  12. Once the installation finishes, the Exchange Management Console will open. You will be presented with a report informing you of which servers are currently unlicensed and how long they may remain so before their functionality is diminished. Click OK to dismiss this report.
  13. You will then be presented with the Finalize Deployment checklist shown in Figure 2-12.
    Cc505857.figure_C02624108_12(en-us,TechNet.10).png
    Figure 2-12 Finalize Deployment checklist

Quick Check

  • According to the information on the Client Settings page of the Exchange Server 2007 Setup Wizard, what will happen if you inform the installation wizard that there are client computers running Outlook 2003 or Entourage in your organization?

Quick Check Answer

  • A public folder database will be created during setup. For more information on why a public folder database is necessary for computers running Outlook 2003 or Entourage, see Chapter 4, “Configuring Public Folders.”


Practice 3: Installing Exchange Server Using the Command Line

When you have to deploy multiple Exchange multiple times, you will find it more efficient to use the command line rather than the graphical tools. In this practice, you will perform a command-line installation of Exchange Server 2003, adding exactly the same roles as were added in Practice 2. In essence, this practice achieves the same results as Practice 2 but does so using an alternate method. If you have performed Practice 2, it is not necessary to complete this practice. To complete this practice, perform the following steps:
  1. Log on with the Kim_Akers account.
  2. Insert the Exchange Server 2007 installation media. If the Exchange Server 2007 splash screen does not appear, open a command prompt and change to the drive that contains the Exchange Server 2007 installation media.
  3. Enter the command:
    setup /mode:install
    /roles:HubTransport,ClientAccess,Mailbox,UnifiedMessaging<
                
    NOTE Exchange Management tools
    The Exchange Management tools will be automatically installed when the other roles are installed.

Practice 4: Assigning Users Administrative Roles

In this practice, you will assign two of the user accounts that you created in the first practice. To complete this practice, perform the following steps:
  1. Log on to the computer on which you have installed Exchange Server 2007 with the Kim_Akers user account.
  2. Open the Exchange Management Console.
  3. Select the Organization Configuration node, right-click, and then click Add Exchange Administrator.
  4. On the Add Exchange Administrator dialog box shown in Figure 2-13, click Browse and navigate to the Sam Abolrous account. Select the Exchange View-Only Administrator role and then click Add.
    Cc505857.figure_C02624108_13(en-us,TechNet.10).png
    Figure 2-13 Configuring Exchange administrator roles
  5. Click Finish to close the Completion dialog box.
  6. Right-click the Organization Configuration node and then click Add Exchange Administrator.
  7. Click Browse and navigate to the Terry Adams user account.
  8. Select the Exchange Server Administrator role option and then click Add.
  9. In the Select Exchange Server dialog box, shown in Figure 2-14, select GLAS-GOW and then click OK. .
  10. Click Add in the Add Exchange Administrator dialog box.
  11. Review the warning and then click Finish.
    Cc505857.figure_C02624108_14(en-us,TechNet.10).png
    Figure 2-14 Configuring the Exchange Server Administrator role

Quick Check

  1. What does the warning instruct you to do?

Quick Check Answer

  1. The warning instructs you to add the Terry Adams user account to the Local Administrators group on the computer hosting Exchange Server 2007.


Practice 5: Installing an SSL Certificate on Exchange Server 2007

In this practice, you will install an Enterprise Root Certificate Authority and configure it to generate SSL certificates. Although Exchange will automatically generate an SSL certificate and install it when you install the Client Access server role, clients attempting to access the server using SSL will not trust the issuing CA. By installing a CA and performing a request for an SSL certificate, this practice will simulate the steps you would take in requesting and installing an SSL certificate trusted by a third-party CA.
You will then install an SSL certificate on Exchange. To complete this practice, you will need access to the Windows Server 2003 installation media. Once you have verified that you have access to the installation media, perform the following steps:
  1. Log on to the computer that hosts Exchange Server 2007 using the Kim_Akers account.
  2. From Control Panel, open Add Or Remove Programs and then click Add/ Remove Windows Components.
  3. Select Certificate Services. Click Yes to dismiss the warning that informs you that the computer name and domain membership cannot be changed. Click Next.
  4. On the CA Type page of the Windows Components Wizard, select Enterprise Root CA, as shown in Figure 2-15, and then click Next.
    Cc505857.figure_C02624108_15(en-us,TechNet.10).png
    Figure 2-15 Installing an Enterprise Root CA
  5. On the CA Identifying Information page, enter the common name for the CA as Glasgow and then click Next.
  6. On the Certificate Database Settings page, review the default locations and then click Next.
  7. In the warning dialog box that informs you that Internet Information Services needs to be temporarily stopped, click Yes. Certificate Services will now be installed. You will be prompted for the Windows Server 2003 installation media during the installation process.
  8. You will be asked to enable Active Server Pages as a part of the Certificate Services installation process. Click Yes.
  9. On the Completing The Windows Components Wizard page, click Finish.
  10. Open Internet Information Services and expand the Server And Web Sites node.
  11. Right-click Default Web Site and select Properties.
  12. Click the Directory Security tab and then click the Server Certificate button. This will start the Web Server Certificate Wizard. Click Next.
  13. On the Modify The Current Certificate Assignment page, select Remove The Current Certificate and then click Next twice. Click Finish.
  14. Click the Server Certificate button again to restart the wizard and then click Next.
  15. Select Create A New Certificate and click Next. Select Send The Request Immediately To An Online Certification Authority and then click Next.
  16. Set the name for the certificate to OWA and then click Next.
  17. Set the organization to Tailspin Toys and the organizational unit to Exchange and then click Next.
  18. Leave the default common name and then click Next.
  19. Set the state/province to Washington and the city/locality to Redmond and then click Next twice.
  20. Leave the default SSL port and click Next.
  21. Select GLASGOW.tailspintoys.internal\glasgow as the CA to process the request and click Next twice. Click Finish.
  22. Click OK to close Default Website Properties.
  23. In Internet Explorer, open the site https://glasgow/certsrv.
  24. On the Security Warning About Trusted Sites List page, click Yes.
  25. Click Download A CA Certificate, Certificate Chain, Or CRL.
  26. Click Download CA Certificate and save it to the desktop.
  27. Open the certificate and then install it using the Certificate Import Wizard.

Practice 6: Installing the Evaluation Version of Forefront

WARNING Optional practice
Warning: Installing Forefront Security for Exchange Server dramatically increases memory requirements. Do not perform this practice unless the computer you have installed Exchange Server 2007 on has more than 2 GB of memory.


An evaluation version of Forefront Security for Exchange Server is included with the Exchange Server 2007 installation media. Although you would normally perform message screening on an Edge Tansport server on a perimeter network, we will install this package on the computer assigned the Hub Transport server role.
NOTE Downloading Forefront Security for Exchange Server
Although included on the Exchange Server 2007 installation media, an evaluation version of Forefront Security for Exchange Server can be downloaded by accessing the following link: http://www.microsoft.com/technet/prodtechnol/eval/fses/default.mspx.


To complete this practice, perform the following steps:
  1. Log on to the computer hosting Exchange Server 2007 using the Kim_Akers account.
  2. Navigate to the Forefront directory on the Exchange Server 2007 installation media and double-click Setup.exe. This will start the Microsoft Forefront Security for Exchange Server Installation Wizard, as shown in Figure 2-16. Click Next to continue.
    Cc505857.figure_C02624108_16(en-us,TechNet.10).png
    Figure 2-16 Starting installation of Forefront for Exchange Server
  3. Review the license agreement and then click Yes.
  4. On the Customer Information page, click Next.
  5. On the Installation Location page, ensure that Local Installation is selected and then click Next.
  6. On the Installation Type page, ensure that Full Installation is selected, as shown in Figure 2-17, and then click Next.
    Cc505857.figure_C02624108_17(en-us,TechNet.10).png
    Figure 2-17 Forefront installation type
  7. On the Quarantine Security Settings page, ensure that Secure Mode is selected and then click Next.
  8. Review the five randomly selected antivirus scan engines and then click Next.
  9. Review the information on the Engine Updates Required page and then click Next.
  10. On the Choose Destination Location page, review the installation location and then click Next.
  11. In the Select Program Folder, review the location the program icons will be installed to and then click Next.
  12. On the Start Copying Files page, review the installation settings and then click
  13. Next. The installation process will now commence.
  14. During the installation process, you will be asked if you would like setup to restart the Exchange Transport service. Click Next to have the service restarted.
    BEST PRACTICES Restarting Transport Service
    In a production environment, you might choose to wait until an off-peak period to perform this operation. In general, you would add a component such as this during a period when having the server offline would cause minimal impact to your organization’s operations.

  15. After the service has been restarted, click Next and then click Finish. The readme file for Forefront Security for Exchange will open automatically. Review its contents and then close the file.
  16. Restart the computer.
    NOTE Restart optional
    Restarting the computer is not strictly necessary but will refresh all services that Exchange Server 2007 relies on.

  17. When the computer has restarted, log back on using the Kim_Akers user account. From the Programs menu, open Forefront Server Security Administrator. Click OK in the Connect To Server dialog box to open the local instance of this program. Click OK to dismiss the License Notice dialog box.
  18. Click Scanner Updates under Settings.
  19. Click Update Now in the right-hand-side pane of Forefront Server Security Administrator when Scanner Updates is selected, as shown in Figure 2-18.
Cc505857.figure_C02624108_18(en-us,TechNet.10).png
Figure 2-18 Updating virus definitions

Lesson Summary

  • Mailbox servers host message data. Client Access servers allow access to Mailbox servers. Hub Transport servers route message data. Edge Transport servers route messages to and from the Internet, though this can also be done by Hub Transport servers. Unified Messaging servers store voice and fax data.
  • The active Clustered Mailbox, passive Clustered Mailbox, and Edge Transport server roles cannot be installed with other roles.
  • Computers assigned the Edge Transport server role are located on perimeter networks. They should not be members of an Active Directory environment.
  • The standard way to set up Exchange Server 2007 is using a wizard that allows you to perform either a typical install, which installs the Client Access, Mailbox, and Hub Transport roles, or a custom install, where the combination of roles is selected by the administrator. The Unified Messaging, Edge Transport, and Clustered Mailbox roles can be installed graphically only by using a custom install.
  • Command-line installation allows for a greater number of configuration options than the graphic installation. The majority of setup options must be passed directly from the command line. Answer files are used primarily to set up clusters.
  • Communications with Client Access servers are encrypted using SSL. Installing the Client Access server role creates a default SSL certificate, though this will not be trusted by clients.
  • Clustered roles require that the host server already be a node in a cluster. Clusters can be implemented on the enterprise editions of Windows Server 2003 and Windows Server 2008. You can implement active or passive mailbox clusters.
  • Load balancing can be used to ensure that computers that host the Client Access, Hub Transport, and Edge Transport roles are not overwhelmed. This is done by adding servers hosting identical roles as nodes in an NLB cluster.
  • An evaluation version of Forefront Security for Exchange Server is included with the Exchange Server 2007 installation media.

Lesson Review

You can use the following questions to test your knowledge of the information in Lesson 1, “Installing Exchange Server.” The questions are also available on the companion CD if you prefer to review them in electronic form.
NOTE Answers
Answers to these questions and explanations of why each answer choice is correct or incorrect are located in the “Answers” section at the end of the book.


  1. You are preparing a new deployment of Exchange Server 2007 in a single-domain environment spread over five separate Active Directory sites. Users at all sites will need speedy access to mail. Branch office sites are connected by a virtual private network (VPN) tunnel to the head office site, where you have already deployed an Edge Transport server and a server with the Hub Transport, Client Access, and Mailbox server roles. A single computer running Exchange Server 2007 will be deployed at each site. Which of the following roles should be deployed on these computers? (Choose all that apply.)
    1. Edge Transport
    2. Hub Transport
    3. Client Access
    4. Mailbox server
    5. Unified Messaging server
  2. In which of the following network locations should you deploy an Edge Transport server?
    1. Direct connection to the Internet
    2. Perimeter network
    3. Internal network >
    4. Encrypted network
  3. Which of the following digital certificate templates should you use when requesting and installing a digital certificate on a computer that will provide the OWA service to remote clients?
    1. Code signing
    2. SSL
    3. IPSec
    4. EFS
  4. Your organization has a single computer with Exchange Server 2007 installed. This Exchange Server 2007 computer hosts the Hub Transport, Client Access, and Mailbox server roles. Users in your organization, who use primarily OWA, report slow connections to the server. You examine the performance of the server and find that although only 25 percent of the disk space on the server is consumed by mailbox databases, the processor usage statistics are consistently above 80 percent. To alleviate this problem, you will install a second computer running Exchange Server 2007. If you were to deploy only a single role on that computer, removing it from the existing server, which of the roles would you deploy to improve performance?
    1. Hub Transport
    2. Client Access
    3. Edge Transport
    4. Mailbox server
  5. Which of the following Exchange Server 2007 setup commands will install the Client Access, Hub Transport, and Mailbox server roles on a computer in an existing Exchange 2007 organization?
    1. setup /mode:install /roles:ClientAccess,Mailbox,EdgeTransport
    2. setup /mode:install /r:C,E,M,H
    3. setup /mode:upgrade /r:C,E,M,H
    4. setup /mode:install /r:C,M,H,U
    5. setup /mode:install /r::Mailbox,UnifiedMessaging,ClientAccess
  6. Each Exchange Server computer at your single site organization is assigned only one Exchange Server role. Your organization has five computers running Exchange Server 2007. You want to deal with messages containing spam or viruses before they reach user mailboxes. Which of the following computers running Exchange Server 2007 should you deploy Forefront Security for Exchange Server on? (Choose all that apply.)
    1. The computer assigned the Edge Transport server role
    2. The computer assigned the Hub Transport server role
    3. The computer assigned the Client Access server role
    4. The computer assigned the Mailbox server role
    5. The computer assigned the Unified Messaging server role

Configuring Exchange Server Roles


Lesson 2: 
Installing roles is not the end point of deploying Exchange 2007. Once roles are deployed, it is necessary to configure them. Configuring a role to best meet the needs of your organization is a critical part of the postinstallation process. Although when you install a role it is configured to suit the needs of most organizations, you will find that you can make a number of tweaks that best suit your organization. Although later chapters in this book look in more detail at specific configuration settings, this lesson provides an overview of the general postinstallation tasks an Exchange administrator would carry out on servers assigned these roles.

After this lesson, you will be able to:

  • Configure Exchange Server roles.
    • Configure the Hub Transport server role.
    • Configure the Edge Transport server role.
    • Configure the Client Access server role.
      • Configure Outlook Anywhere.
      • Configure the server to enable client and mobile device connectivity.
      • Configure OWA for changing passwords.
      • Configure OWA for file sharing.
      • Configure OWA for SharePoint.
    • Configure the Mailbox server role.
      • Create, modify, and delete databases and storage groups.
      • Manage mailbox size limits.
    • Add and remove roles.
    • Remove the Exchange Server.

Estimated lesson time: 40 minutes



Configuring the Edge Transport Server Role

Once the Edge Transport server role is installed, you need to configure it to work with EdgeSync. EdgeSync links Active Directory with ADAM. Prior to establishing replication from Active Directory to ADAM, it is necessary to create an Edge subscription file. Each Edge Transport server requires a unique Edge subscription file. Three Edge Transport servers means three separate Edge subscription files.
To create an Edge subscription file, perform the following steps:
  1. Verify that the Edge Transport server can resolve the FQDN of the Hub Transport server to an IP address using the nslookup command-line utility. Verify that the Hub Transport server can resolve the FQDN of the Edge Transport server to an IP address using the nslookup command-line utility.
  2. Create the Edge subscription file on the Edge Transport server by issuing the following command from Exchange Management Shell: New-EdgeSubscription –file “C:\EdgeSubExport.xml.”

    NOTE Loss of manual configuration settings

    When you configure an Edge Transport server to be managed by EdgeSync, you will lose configuration settings that may have already been made to the Edge Transport server manually, such as accepted domains, message classifications, remote domains, and send connectors. Once the subscription is configured, the Exchange Management Shell commands that allow you to make these configuration settings will be blocked on the Edge Transport server. All these settings will be configured through the organization-wide Hub Transport settings.

  3. Copy the exported file to a Hub Transport server. This file needs to be imported within 1,440 minutes (24 hours) of creating the file; otherwise, you will need to re-create it.
  4. On the Hub Transport server, open the Exchange Management Console and click on Hub Transport under Organization Configuration.
  5. Click the Edge Subscriptions tab and then click New Edge Subscription in the Actions pane.
  6. This will launch the New Edge Subscription Wizard, shown in Figure 2-19. Ensure that you have selected the site for which the Edge Transport server will become a member and then click Browse to locate the subscription file.
    Cc505858.figure_C02624108_19(en-us,TechNet.10).png
    Figure 2-19 Enabling anti-spam updates
  7. Click New to create the new subscription.
Once an Edge Transport server is subscribed, all Hub Transport servers located in the site to which the Edge Transport server is subscribed can contribute to the EdgeSync process. This does not apply to any new Hub Transport servers added to the site after the subscription has occurred. If you add more Hub Transport servers to the site, it will be necessary to remove and re-create the Edge subscription. In the event that the licensing status of the Edge Transport server changes, for example, if you created the subscription prior to activating the Edge Transport server, it will be necessary to perform the subscription process again.

MORE INFO Subscribing the Edge Transport server

For more information on subscribing the Edge Transport server to your Exchange organization, consult the following link: http://technet.microsoft.com/en-us/library/bb125236.aspx.


For successful synchronization between Active Directory and ADAM to occur, the firewall between the secure network and the perimeter network needs to have TCP/IP port 50636 open. Once the subscription has been set up, the Hub Transport server will periodically sync with the Edge Transport server, transmitting information about accepted domains, remote domains, and internal Simple Mail Transfer Protocol (SMTP) servers. To force synchronization, issue the Start-EdgeSynchronization command in the Exchange Management Shell.

Configuring the Hub Transport Server Role

Hub Transport servers are configured both at the server and at the organizational level. Server-level configuration includes external and internal DNS configuration, domain controller, and global catalog server configuration and message limit configurations. The domains for which your Exchange Server 2007 computers will accept e-mail are configured on an organizational level rather than a per server level. The New Accepted Domain Wizard allows you to configure Exchange Server 2007 to be authoritative for a domain. This configures your Exchange organization to accept e-mail sent to particular e-mail addresses, such as @tailspintoys.com or @wingtiptoys.com. If mail arrives at the server and is not addressed to a domain on the accepted domain list, it will bounce. The accepted domain list stops nefarious third parties from using your mail servers as relays to send spam and viruses.
You can configure an accepted domain through the wizard or from the Exchange Management Shell by issuing the command new-AcceptedDomain –Name ‘tailspin-toys.com’ –DomainType ‘Authoritative,’ where you substitute tailspintoys.com for the domain name for which you wish your Exchange organization to accept mail.
You can also use the New Accepted Domain Wizard to configure an internal relay domain and an external relay domain. The internal relay domain option is used if you want e-mail relayed to another Active Directory forest within your organization. An external relay domain is used to relay traffic to an e-mail server outside the Exchange organization.
Any e-mail received by the Hub Transport server that is not addressed to an accepted domain will be dropped. As companies often change their names, it is important to ensure that messages addressed to previously registered domain names will still be received properly. For example, Tailspintoys.com was known several years ago as Wingtiptoys.com. Several customers might still send e-mail to wingtiptoys.com addresses. If Wingtiptoys.com is not on the list of accepted domains, this e-mail will be dropped by the server.

Configuring Remote Domains

Remote domains allow the configuration of formatting and messaging policies to specific remote domains. For example, if you know that a partner company requires specifically configured e-mail, you can set up a remote domain policy for all e-mail sent to that particular domain. Remote domain policies can be applied to a specific domain only or to all subdomains of that specific domain. Configuring mail for specific destinations is covered in more detail in Chapter 7, “Connectors and Connectivity.”

Create a Postmaster Mailbox

The postmaster address is the address listed on nondelivery reports and other delivery status notifications. The postmaster at a particular mail domain is the person whom you contact if you want to follow up on an offensive or problematic e-mail. The standard postmaster alias allows anyone to send an e-mail for whatever reason to the person in charge of the e-mail servers at a particular organization.
Each Transport server will have a separate postmaster address. To view the currently assigned postmaster address, issue the following command in Exchange Management Shell:
Get-TransportServer | Format-List Name,ExternalPostMasterAddress
In the event that you want to redirect the postmaster address to another address, you can use the following Exchange Management Shell command:
Set-TransportServer –Identity ‘ServerName’ –ExternalPostMasterAddress
‘newpostmaster@tailspintoys.com’
Alternatively, you could then assign the postmaster address as a secondary address on the user account that will be responsible for dealing with postmaster inquiries. In the event that person leaves your organization, you can move the postmaster address, as necessary. Ensuring that the postmaster address is watched is an important part of the responsibility of being a mail administrator. For example, if someone from within your organization has been sending spam, the postmaster e-mail address is the first place that some notification about it will exist. It is better to monitor this address than to find out that your mail domain has been placed on a blocking list because you were not aware that a rogue user was sending out unsolicited commercial e-mail.

Enabling Anti-spam Features on Transport Servers

Although Edge Transport servers have anti-spam features enabled by default, Hub Transport servers do not. To enable the Exchange Server 2007 anti-spam features on a computer with the Hub Transport server role installed, issue the following Exchange Management Shell command:
Set-TransportServer –Identity ‘ServerName’ –AntispamAgentsEnabled $true
You will then need to restart the Exchange Server Transport service and any open Exchange Management Consoles before the anti-spam features are enabled. You can verify that anti-spam features have been enabled, as the Enable Anti-Spam Updates item will now be available in the Actions pane when the Hub Transport server is selected under Server Configuration in the Exchange Management Console. The Anti-spam tab will also become available in the Actions pane when the Hub Transport option is selected under Organization Configuration in Exchange Management Console.
Clicking on Enable Anti-spam Updates in the Action pane allows you to configure how the anti-spam definitions and application will be updated, as shown in Figure 2-20. You can allow automatic updating of spam signatures as well as IP reputation updates. Configuring anti-spam settings is covered in more detail in Chapter 6.
Cc505858.figure_C02624108_20(en-us,TechNet.10).png
Figure 2-20 Enabling anti-spam updates

Configuring the Client Access Server Role

The Client Access role is the gateway between clients and their mailbox data. It is possible to use NLB to load balance the Client Access role in the event that client traffic is putting too much strain on resources. In most instances, you can install the client access server role, and your users will automatically be able to access e-mail. If you are using SSL, you should remember that clients will not trust the default SSL certificate generated during the installation of the Client Access server role. You have to either obtain an SSL certificate from a commercial and trusted source or find a way for your organization to manage and generate its own SSL certificate.

Configuring Outlook Anywhere

Outlook Anywhere allows clients using Microsoft Outlook 2007 and Outlook 2003 to access Exchange Server 2007 using the RPC over HTTP protocol. The primary benefit of using Outlook Anywhere is that it simplifies the configuration of remote access to Exchange. Access can be granted without having to use VPN connections, and rules allowing the quick setup of RPC over HTTP access to Exchange are built into Internet Security and Acceleration (ISA) Server, Microsoft’s firewall and proxy product.
Outlook Anywhere can be enabled by clicking on Enable Outlook Anywhere on the Actions pane when the Client Access role is selected under the Server Configuration node. When configuring Outlook Anywhere, you need to specify the external host name, the authentication type, and whether you want to allow SSL offloading. The authentication options are Basic and NTLM with the option to use SSL offloading. SSL offloading allows you to use an SSL accelerator device to assist with the processing load involved in encrypting network connections to the Client Access server, as shown in Figure 2-21. You should not enable SSL offloading unless your server has an SSL accelerator device, as this can cause connection problems.
Cc505858.figure_C02624108_21(en-us,TechNet.10).png
Figure 2-21 Outlook Anywhere properties
You can also enable Outlook Anywhere from the Exchange Management Shell by issuing the following command:
Enable-OutlookAnywhere -Server 'GLASGOW' -ExternalHostname 'externalhostname. 
tailspintoys.com' -ExternalAuthenticationMethod 'Basic' -SSLOffloading $false
MORE INFO Enabling Outlook Anywhere
To find out more about Outlook Anywhere, access the following link: http://technet.microsoft.com/ en-us/library/bb123741.aspx.


Configuring Client and Mobile Device Connectivity

Exchange ActiveSync is automatically enabled when the Client Access server role is installed on a computer running Exchange Server 2007. ActiveSync allows for the synchronization of data between mobile devices and Exchange Server 2007. Supported devices include Pocket PC 2002, Pocket PC 2003, and Windows Mobile 5.0. Windows Mobile 5.0 devices that have the Messaging Security and Feature Pack installed also support Direct Push, a technology that keeps a mobile device continuously synchronized with Exchange Server 2007.
The primary configuration that you have to make is on the clients themselves. Lesson 2 of Chapter 7 provides more information on configuring mobile device policies.
MORE INFO Managing ActiveSync
For more information on managing ActiveSync, consult the following link: http://tech-net.microsoft.com/en-us/library/bb124396.aspx.


Configuring OWA

OWA can be used for more than just reading and responding to e-mail. Depending on how the Client Access role is configured, OWA clients can use their browser to access standard file shares or SharePoint sites. Access to Windows file shares and Windows SharePoint services can be enabled on the basis of whether a remote user is accessing OWA using a public or shared computer or is using a private computer. This way, you can disable access to Windows file shares or SharePoint when a user is connecting to OWA from an Internet café but allow access to Windows file shares and SharePoint when connecting to OWA from a company mobile computer using a café’s WiFi connection. This demarcation relies on the user selecting the correct option when logging on to OWA, as shown in Figure 2-22.
Cc505858.figure_C02624108_22(en-us,TechNet.10).png
Figure 2-22 When logging on to OWA, the users specify whether they are using a public or a private computer
This access is granted by setting options within the OWA Web site’s Properties dialog box. The Public Computer File Access tab allows you to configure the access granted to users accessing OWA from computers designated as public or shared. The Private Computer File Access tab allows you to configure the access granted to users accessing OWA from computers designated as private.
Once you have determined what type of access you want to grant users who are connecting remotely to OWA from public, shared, and private computers, you can configure the specific servers on your local network that they can access. You perform this task on the Remote File Servers tab of the OWA Web site properties, as shown in Figure 2-23.
The Remote File Servers tab has four items that can be configured:
  • Block list A list of servers that OWA clients cannot access. Items on this list override items on the allow list.
  • Allow list A list of servers that OWA clients can access.
  • Unknown servers How servers not on either the block list or the allow list are to be treated. The default option is Block. This setting can also be configured to Allow.
Cc505858.figure_C02624108_23(en-us,TechNet.10).png
Figure 2-23 Remote File Servers tab
  • Domain suffixes that should be treated as internal OWA clients can access only servers that are recognized as internal. If a server that an OWA client attempts to access has a DNS suffix that is not on the list, it will be considered external and will not be accessible to the client.
By their nature, OWA clients are usually using computers that are not managed by your organization. You can not always be 100 percent certain that the person logging in using the publicly available computer in an airport in Volgograd, Russia, is actually your company’s sales rep who is currently traveling in the area. It is not unheard of for nefarious third parties to place keylogging devices on public computers at airports or Internet cafés in an attempt to capture user names and passwords from the unwary. Although considering these threats might lead you to block off remote access to OWA entirely, some options that you can use to limit the damage are available. One configurable option allows you to block the ability to make password changes using OWA. In the event that a password is compromised, at least the person who has stolen the password will be unable to entirely hijack the compromised account by changing the password to something unknown to the user. To configure the option to block password changes for OWA users, edit the properties of the OWA Web site in Exchange Management Console, click the Segmentation tab, and then disable the Change Password feature, as shown in Figure 2-24.
Cc505858.figure_C02624108_24(en-us,TechNet.10).png
Figure 2-24 Blocking password change
MORE INFO Managing OWA
For more information on managing OWA, navigate to the following link: http://technet. microsoft.com/en-us/library/aa996373.aspx..


POP3 and IMAP4

POP3 and IMAP4 are disabled by default on a computer configured with the Client Access role. As almost all e-mail clients use one of these protocols to retrieve e-mail, it is necessary to activate them prior to putting the Client Access role into a production environment. You can activate these services using two methods: using the Services console or using the NET START command from a command prompt. You should use the Services console, as this will also allow you to change the service startup type from manual to automatic. If you do not do this, you may reboot the server after applying updates and forget that neither the POP3 nor the IMAP4 service starts automatically. To enable each service, right-click on it within the Services console and select Properties. Change the start-up type to automatic and then click Start, as shown in Figure 2-25.
Cc505858.figure_C02624108_25(en-us,TechNet.10).png
Figure 2-25 Setting the start-up type of the IMAP4 service

Quick Check

  1. How does OWA determine whether a remote client is using a public or shared computer or a private computer?
  2. Which SharePoint sites does a client connecting to OWA have access to by default?

Quick Check Answers

  1. The remote client is queried when connected to OWA.
  2. None. Sites must be added explicitly or by domain suffix.


Configuring the Mailbox Server Role

The immediate postinstallation tasks that you need to perform on a computer hosting the Mailbox server role are creating, modifying, and deleting databases and storage groups. Prior to performing those acts, you need to understand the differences between the two editions of Exchange Server 2007:
  • The standard edition of Exchange Server 2007 supports five storage groups and five mailbox databases per server. The standard edition supports a maximum of five mailbox databases in a single storage group, one of which is reserved for recovery.
  • The enterprise edition of Exchange Server 2007 supports up to 50 storage groups and a maximum of 50 databases per server, with a maximum of five mailbox databases per storage group.
Microsoft recommends that you allocate only one mailbox database per storage group, although it is possible to locate five mailbox databases in a single storage group. All databases within the same storage group share the same backup schedule. Having only a single database within a storage group provides greater flexibility in setting backup schedules on a per mailbox database basis. Storage groups are managed by separate server processes, and separating mailbox databases into their own separate storage group reduces transaction log complexity. Chapter 12, “Configuring Disaster Recovery,” provides more information on backups and storage groups.
Storage groups can be created using the GUI by clicking New Storage Group in the Actions pane. You can also manage storage groups from Exchange Management Shell. The following Exchange Management Console command will create a storage group named Second Storage Group in the location C:\Program Files\Microsoft\Exchange Server\Mailbox\Second Storage Group:
new-StorageGroup –Server ‘GLASGOW’ –Name ‘Second Storage Group’ –LogFolderPath ‘C:\Program
Files\Microsoft\Exchange Server\Mailbox\Second Storage Group’ –SystemFolderPath ‘C:\Program
Files\Microsoft\Exchange Server\Mailbox\Second Storage Group’
To create a new mailbox database, select the storage group that will host the database and then click New Mailbox Database. You can achieve the same thing using the Exchange Management Shell by issuing the following command:
new-mailboxdatabase -StorageGroup 'CN=Second Storage 
Group,CN=InformationStore,CN=GLASGOW,CN=Servers,CN=Exchange Administrative Group
(FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Tailspintoys,CN=Microsoft 
Exchange,CN=Services,CN=Configuration,DC=tailspintoys,DC=internal' -Name 'Second Mailbox 
Database' -EdbFilePath 'C:\Program Files\Microsoft\Exchange Server\Mailbox\Second Storage 
Group\Second Mailbox Database.edb'
This command creates a mailbox database called Second Mailbox Database in the Second Storage Group of a server named Glasgow. You will create this database and storage group in the practices at the end of this lesson.
You can view the location mailbox database by viewing the Mailbox Database properties, as shown in Figure 2-26. From this dialog box, it is possible to view the last time the mailbox database was backed up and the location of the database mailbox copy if local continuous replication is enabled and to configure the mailbox maintenance schedule.
Cc505858.figure_C02624108_26(en-us,TechNet.10).png
Figure 2-26 Mailbox database properties
During the period specified in the maintenance schedule, the following tasks are completed:
  • Dumpster cleanup involves the removal of deleted messages that have passed the deleted item retention date.
  • Public folder expiration involves messages posted to public folders expiring after a certain amount of time and being removed by the maintenance process.
  • Deleted mailboxes are cleaned up.
  • An online defragmentation of the mailbox is performed.

Managing Mailbox Size Limits

Although on a per gigabyte basis hard disk drive storage costs are always dropping, at some point you will most likely want to limit the amount of information that users can store in a mailbox. Although some users will be diligent about removing unnecessary material, the mailboxes of other users will continue to grow unless they reach some preconfigured limit. Some users never delete an attachment, even if it is completely outdated and has not been relevant for several years. If you do not impose mailbox limits, it is possible that a small number of mailboxes might account for the majority of the disk space on your mailbox servers.
BEST PRACTICES The 80/20 rule
One common rule of thumb in many fields, including systems administration, is that 80 percent of resources will be consumed by 20 percent of the users. This applies to mailbox usage. You will find that without mailbox size limits, 20 percent (or less) of your users will end up taking 80 percent (or more) of the available disk space.


Besides the issue of a small number of users using a disproportionate amount of disk space, another practical reason for limiting the size of mailboxes involves backups. Data can be backed up and restored at only a finite rate. The larger the mailboxes, the longer the backup process is and the greater the amount of backup media that will be required. Larger mailboxes have a similar impact on restore operations. It takes longer to restore data from backups containing larger mailboxes than it does to restore data from backups containing smaller mailboxes.
You can manage mailbox size limits by editing the properties of the mailbox database and clicking the Limits tab. From this tab, it is possible to configure the following properties:
  • Issue Warning At (KB) The threshold in kilobytes when a warning is automatically issued to the user about the amount of data stored in a mailbox.
  • Prohibit Send At (KB) The threshold in kilobytes when the user is no longer able to send e-mail.
  • Prohibit Send And Receive At (KB) The threshold in kilobytes when the user is no longer able to send and receive e-mail.
  • Warning Message Interval The schedule by which warning messages will be sent to users who have mailboxes larger than the specified thresholds.
  • Keep Deleted Items For (Days) How long deleted items are kept before being removed from the mailbox database.
  • Keep Deleted Mailboxes For (Days) How long a deleted mailbox is kept in the database before being permanently deleted.
  • Do Not Permanently Delete Items Until The Database Has Been Backed Up This option overrides the previous settings, keeping deleted items past their expiration date until the database has been backed up.
Mailbox limits are configured in a practice at the end of this lesson.

Removing Exchange Server 2007

Three separate Exchange Server 2007 removal scenarios exist, each of which must be treated differently. These include removing of one or more roles from an Exchange Server while keeping the server operational, removing Exchange Server 2007 in its entirety from a computer, and removing the Exchange Server 2007 organization from an Active Directory forest. Also covered in this section are the steps that must be taken to remove a final Exchange Server 2003 or Exchange 2000 from a mixed Exchange environment.

Removing Roles

To remove roles that have been previously installed on a computer running Exchange Server 2007, your user account must have been added to the Exchange organization administrator role. To remove the roles, open Add Or Remove Programs, click Microsoft Exchange Server 2007, and then click Change. This will bring up the Exchange Server 2007 Setup Wizard in Exchange Maintenance Mode, as shown in Figure 2-27. On the next page of the wizard, you select the roles that you wish to unin-stall from the server. Readiness checks are performed, warning you of potential problems, and then the role removal is completed.
When removing the Mailbox server role, ensure that existing mailboxes have been either moved, disabled, or deleted. You should also ensure that all public folders and public folder replicas have been migrated to another Mailbox server. Similarly, if removing a Client Access server, ensure that clients that are directly connecting to OWA are redirected to an appropriate alternative.
Roles can be removed from an Exchange Server using setup from the command line. The command setup /mode:uninstall /roles:<roles to remove> will remove the specified roles from the computer running Exchange Server. If, in the future, you decide to reinstall the Mailbox server role on a computer that has had that role removed, it will be necessary to manually remove the existing database and log files from the server.
Cc505858.figure_C02624108_27(en-us,TechNet.10).png
Figure 2-27 Removing roles using the GUI

Removing Exchange from a Server

In some cases you may want to remove not only an Exchange role but the entire program itself. It is important to perform a proper uninstall rather than just wiping the server and reinstalling the operating system, as a proper installation updates the rest of the Exchange organization about the status of the decommissioned server. Removing Exchange Server 2007 entirely includes removing all server roles, installation files, the Exchange Server object, and all the associated child objects from the Active Directory forest. For this reason, you can perform a complete removal of Exchange Server 2007 only by using an account that has been delegated the Exchange organization administrator role.
Prior to attempting to remove Exchange Server 2007 entirely, ensure that any mailboxes hosted on the computer have been deleted, disabled, or moved. Also verify that public folders and public folder replicas have been migrated to another server. Removal of Exchange Server 2007 is accomplished using the Add/Remove Programs item in Control Panel. It can also be achieved using the command setup /mode:unin-stall. As with the removal and reinstallation of the Mailbox server role mentioned earlier, if you reinstall Exchange with the Mailbox server role on a computer that has hosted this role in the past, it is necessary to remove the existing database and log files from the server.

Removing an Exchange 2007 Organization

In the event that you want to completely remove an Exchange Server 2007 organization, you must first remove Exchange from all servers in the organization. Once Exchange is removed from all servers, the following data and settings will remain:
  • Microsoft Exchange System Objects container in Active Directory
  • Exchange Configuration container in Active Directory
  • Active Directory schema modification
  • User data, including database files, log files, public folder, and public folder replica data
Although it is relatively simple to remove the Active Directory containers and objects as well as the leftover user data, rolling back the schema modifications made by Active Directory setup is technically possible but very difficult to implement in a production environment. Unless you are well prepared, returning a large environment to the precise state it was in prior to the deployment of Exchange Server 2007 is next to impossible. This is another reason why you need to get deployment right from the start.
MORE INFO Schema rollback
To learn how Microsoft manages its Active Directory schema, including some techniques used for rolling back schema changes, consult the following link: http://www.microsoft.com/technet/ itshowcase/content/adschemamgmt.mspx.


Removing the Last Exchange 2000 or Exchange Server 2003 Server in a Coexistence Environment

Many organizations that implement Exchange Server 2007 are likely to have an existing Exchange Server infrastructure. As you roll out Exchange Server 2007 across your organization, you are likely to want to decommission the previous versions of Exchange. Before decommissioning legacy Exchange server computers, you need to ensure that people in your organization are not using services that only those editions of Exchange provide and that all relevant user data has been migrated to Exchange Server 2007.
Just as Exchange Server 2007 includes new features not available in previous editions, previous editions of Exchange Server have features that do not exist in Exchange Server 2007. If your organization still uses these services, you will need to migrate users to alternatives prior to removing the legacy Exchange servers that support them. The features that you have to be careful about are the following:
  • Exchange Server 2003. Novell GroupWise connector and NNTP Protocol
  • Exchange 2000 Server. Mobile Information Server, Instant Messaging Service, Exchange Chat Service, Exchange 2000 Conferencing Server, Key Management Service, cc: Mail connector, and MS Mail connector

You do not want to remove a prior version of Exchange server only to discover that it provides a critical service to some department in your organization of which you were unaware. Other steps that you need to take prior to decommissioning a legacy Exchange Server include the following:
  • Move all mailboxes to a computer running Exchange Server 2007.
  • Move all public folder replicas to a computer running Exchange Server 2007.
  • Move all offline address book generation processes to a computer running Exchange Server 2007.
  • Configure send connectors on a computer hosting the Exchange Server 2007 Hub or Edge Transport roles (depending on your Exchange architecture) to replace all existing outbound SMTP connectors.
  • Alter DNS MX records to ensure that they resolve to computers running Exchange Server 2007 with the Hub or Edge Transport roles installed. Ensure that no DNS MX records point to the computer hosting the legacy edition of Exchange.
  • Ensure that inbound protocol services, including ActiveSync, OWA, POP3, and IMAP4, point to a computer running Exchange 2007 with the Client Access role installed.
  • Remove routing group connectors connecting legacy Exchange routing groups to the Exchange 2007 routing group.

MORE INFO Removing and modifying Exchange Server 2007
For more information on how to remove Microsoft Exchange Server 2007 server roles from a computer on which they are already installed, consult the following link: http://technet.microsoft.com/en-us/library/aa998193.aspx.


Exam Tip
When sitting the exam, take a moment to reread the question before you look at the answers. Many people taking multiple-choice exams glance at the answers before they have fully comprehended the question. When they reread the question, they have an incorrect answer in their mind, bending their interpretation of the question text. A helpful technique is to write the answer down on the scratch pad before glancing at the answers on the screen. That way, you will not be tempted to try to fit a wrong answer to the question setup.


Practice: Exchange Server Role Configuration

In these practices, you will perform several exercises that will familiarize you with the configuration of Exchange Server 2007 roles. Each of the practices in this section relates to the most common role configuration tasks that you will have to perform as an Exchange Server 2007 administrator. Before attempting these practices, ensure that you have performed all the practices in Lesson 1 of this chapter.

Practice 1: Configuring the Hub Transport Role

In this practice, we will examine Hub Transport role configuration on both the server and the organizational level. We will be examining organizational policies in more detail in later chapters, and the coverage of organizational configuration is intended only to familiarize you with the configuration options that are available at both the server and the organizational level. To complete this practice, perform the following steps:
  1. Log on to the Exchange Server 2007 computer using the Kim_Akers user account.
  2. Open Exchange Management Console. Dismiss the unlicensed server warning and expand the Server Configuration node.
  3. Click Hub Transport, then right-click the GLASGOW entry and select Properties. This will bring up the GLASGOW Properties dialog box, as shown in Figure 2-28.
  4. Verify that the domain controller and global catalog servers being used by Exchange are set to GLASGOW.tailspintoys.internal. Click the External DNS Lookups tab.
  5. On the External DNS Lookups tab, select the Use These DNS Servers option. In the field, enter the IP address 207.68.160.190 and then click Add.
    Cc505858.figure_C02624108_28(en-us,TechNet.10).png
    Figure 2-28 Hub Transport server general properties
  6. Click the Limits tab. Change the settings so that the value for transient failure retry attempts is set to 10, that the maximum time since submission for message expiration is three days, and that senders will be notified if their message is delayed more than one hour, as shown in Figure 2-29. Click OK to close the Glasgow Properties dialog box.
  7. Under Microsoft Exchange, expand the Organization Configuration node and then click the Hub Transport node.
  8. Click the Accepted Domains tab and then click New Accepted Domains under Actions. This will start the New Accepted Domain Wizard.
  9. On the New Accepted Domain page, enter Tailspintoys.com in the Name box and tailspintoys.com in Accepted Domain. Verify that the Authoritative Domain option is selected, as shown in Figure 2-30. Click New.
  10. Flick Finish to close the wizard. The Exchange Server 2007 organization that you deployed in the first lesson of this chapter is now authoritative for both the tailspintoys.com and the tailspintoys.internal domain.
Cc505858.figure_C02624108_29(en-us,TechNet.10).png
Figure 2-29 Hub Transport server limits
Cc505858.figure_C02624108_30(en-us,TechNet.10).png
Figure 2-30 New accepted domain

Practice 2: Configuring Client Access Server Role

In this practice, you will configure OWA so that remote users can change their password. You will also configure OWA so that remote users can access File Shares and SharePoint sites. To complete this practice, perform the following steps:
  1. Log on to the Exchange Server 2007 computer using the Kim_Akers user account.
  2. Open the DNS console from the Administrative Tools menu.
  3. Create a new primary forward lookup zone called Tailspintoys.com. Create a new host record called outlkany in the tailspintoys.com zone. Assign the new host the IP address of the Exchange Server 2007 computer.
  4. Open Exchange Management Console. Dismiss the unlicensed server warning and expand the Server Configuration node.
  5. Click the Client Access node. In the Actions pane, click Enable Outlook Anywhere.
  6. On the Enable Outlook Anywhere page, set the external host name to out-lkany.tailspintoys.com and verify that basic authentication is set, as shown in Figure 2-31, and then click Enable.
    Cc505858.figure_C02624108_31(en-us,TechNet.10).png
    Figure 2-31 Enable Outlook Anywhere
  7. When the Completion page is shown, click Finish.
  8. Under the Outlook Web Access tab, right-click owa (Default Web Site) and then click Properties.
  9. Click the Segmentation tab, as shown in Figure 2-32. Verify that the Change Password item is set to be enabled.
    Cc505858.figure_C02624108_32(en-us,TechNet.10).png
    Figure 2-32 Allowing OWA users to change passwords
  10. Click the Public Computer File Access tab and remove the checks next to the
  11. Windows File Shares and Windows SharePoint Services items, as shown in Figure 2-33. Click Apply.
  12. Click the Remote File Servers tab and then click Allow.
  13. In the Allow list, enter the hosts sharepoint.tailspintoys.internal and fileserver. tailspintoys.internal and click OK twice to close the dialog box.
  14. From the Administrative Tools Program menu, open the Services console.
  15. Right-click the Microsoft Exchange IMAP4 service and then click Properties.
  16. On the General tab, change Startup Type to Automatic and then click Start. Click OK to close the Properties dialog box.
  17. Repeat this process for the Microsoft Exchange POP3 service.
Cc505858.figure_C02624108_33(en-us,TechNet.10).png
Figure 2-33 Restricting access to shared files on public computers

Practice 3: Configuring the Mailbox Server Role

In this practice, you will create a storage group. Once you have created the storage group, you will create a new mailbox database within the group. You will then also configure the retention settings of the new mailbox database. To complete this practice, perform the following steps:
  1. Log on to the Exchange Server 2007 computer using the Kim_Akers user account.
  2. Open the Exchange Management Console. Dismiss the unlicensed server warning and expand the Server Configuration node.
  3. Click the Mailbox item.
  4. In the Actions pane, click New Storage Group. This will bring up the New Storage Group dialog box.
  5. Enter the name Second Storage Group in the Storage group name text box and accept the default values for the Log Files And System Files path, as shown in Figure 2-34. Click New.
  6. Click Finish to close the New Storage Group Wizard.
  7. Verify the creation of the new storage group by examining the Database Management pane when the Mailbox node is selected under Server Configuration. Click Second Storage Group.
    Cc505858.figure_C02624108_34(en-us,TechNet.10).png
    Figure 2-34 New Storage Group dialog box
  8. With the Second Storage Group highlighted, in the Actions pane, click New Mailbox Database. This will bring up the New Mailbox Database page.
  9. Enter Second Mailbox Database in the Mailbox database name text box, as shown in Figure 2-35, and then click New.
    Cc505858.figure_C02624108_35(en-us,TechNet.10).png
    Figure 2-35 New Mailbox Database dialog box
  10. The exchange mailbox will be created and then mounted, click Finish.
  11. Right-click on Second Mailbox Database under the Second Storage group and then click Properties.
  12. Click the Limits tab, as shown in Figure 2-36.
    Cc505858.figure_C02624108_36(en-us,TechNet.10).png
    Figure 2-36 Configuring mailbox database limits
  13. Change the Keep Deleted Items value to 21 days and the Keep Deleted Mailboxes value to 50 days.
  14. Check the Do Not Permanently Delete Items Until The Database Has Been Backed Up option and then click OK.

Lesson Summary

  • By default, Exchange Server 2007’s anti-spam features are enabled on Edge Transport servers but not enabled on Hub Transport servers. You can enable this feature on Hub Transport servers by executing an Exchange Management Shell command.
  • Edge Transport servers need to have EdgeSync configured to replicate data from Active Directory to ADAM.
  • Outlook Anywhere replaces RPC over HTTP, allowing remote clients to access Exchange Server 2007 without connecting through a VPN.
  • By default, mobile devices can access servers configured with the Client Access server role.
  • OWA can be configured to differentiate access to File Shares and SharePoint servers based on whether a client is connecting using a public or shared computer or a private computer. You can allow or block password changes by accessing SharePoint properties.
  • The standard edition of Exchange Server 2007 can host five mailbox databases and five storage groups. The enterprise edition of Exchange Server 2007 can host up to 50 mailbox databases and 50 storage groups.

Lesson Review

You can use the following questions to test your knowledge of the information in Lesson 2. The questions are also available on the companion CD if you prefer to review them in electronic form.
NOTE Answers
Answers to these questions and explanations of why each answer choice is correct or incorrect are located in the “Answers” section at the end of the book.


  1. You have recently deployed Exchange Server 2007 for Coho Vineyard, a large local wine manufacturer. The deployment involves a single computer running Exchange Server 2007 with the Hub Transport, Mailbox, and Client Access roles deployed. You receive a complaint from the manager of the winery that several long-term clients have called to complain that their e-mails have bounced back. One clue to the problem is that the messages were sent to addresses using the cohowinery.com domain, an address used by the winery for many years. Messages addressed to people in the cohovineyard.com domain always arrive successfully at their destination. Which of the following configuration changes could you make to Exchange Server 2007 to ensure that e-mails from these long-term clients do not bounce?
    1. Configure cohowinery.com as an authoritative domain in accepted domains
    2. Configure cohovineyard.com as an authoritative domain in accepted domains
    3. Configure cohowinery.com as an internal relay domain in accepted domains
    4. Configure cohowinery.com as a remote domain
    5. Configure cohovineyard.com as a remote domain
  2. Which of the following Exchange Server 2007 roles would you configure to ensure that users received a warning when their mailbox was becoming too large?
    1. Client Access
    2. Mailbox
    3. Hub Transport
    4. Edge Transport
  3. You want to allow OWA clients in your organization the ability to access the SharePoint site hosted on server sharepoint.tailspintoys.internal. You do not want them to access the SharePoint site hosted on server secureshare.tailspin-toys.internal. Which of the following steps do you need to take to allow this to occur?
    1. Add the site sharepoint.tailspintoys.internal to the block list on the Remote File Servers tab of the OWA Web site properties
    2. Add the site sharepoint.tailspintoys.internal to the allow list on the Remote File Servers tab of the OWA Web site properties
    3. Add the site secureshare.tailspintoys.internal to the block list on the Remote File Servers tab of the OWA Web site properties
    4. Add the domain suffix tailspintoys.internal to the list of domain suffixes that should be treated as internal
    5. Add the site secure.tailspintoys.internal to the allow list on the Remote File Servers tab of the OWA Web site properties
  4. You are planning the deployment of Exchange Server 2007 enterprise edition. This server will host the Mailbox server role. The server will host 16 mailbox databases. What is the minimum number of storage groups that will be necessary to host these mailbox databases?
    1. One
    2. Two
    3. Three
    4. Four
    5. Five
  5. Your Exchange Server 2007 organization has a single site and a single server. The server’s name is Canberra. This server hosts the Hub Transport, Mailbox, and Client Access server roles. You want to enable Exchange’s anti-spam features on this server but cannot locate the Enable Anti-spam item in the Actions pane when the Hub Transport server is selected. Which of the following must you do prior to enabling the anti-spam features of Exchange Server 2007?
    1. Install the Edge Transport role
    2. Run the command Set-TransportServer –Identity ‘Canberra’ –AntispamAgentsEnabled $true from the Exchange Management Shell
    3. Install Forefront Security for Exchange Server
    4. Reinstall the Hub Transport role
  6. Several months ago, you removed the Mailbox server role from a computer running Exchange Server 2007. The computer retained the Client Access server role. Conditions at the location where the server is deployed have changed, and you need to reinstall the Mailbox server role. Which of the following steps must you take before reinstalling this role?
    1. Remove the Client Access server role
    2. Remove the Mailbox server role
    3. Remove the computer hosting Exchange from the domain and then rejoin the computer to the domain
    4. Manually remove the existing Mailbox database files and log files
    5. Reinstall the Client Access server role

Email basics for Exchange Adminstrators

one of the most efficient forms of communication today. Ironically, the email system's infrastructure is similar to that of the traditional post office in that it requires you to have "routable" addresses enabling mail to be delivered. The mail server is similar to your human mail carrier, and the mail client is you physically walking to your mailbox.
To begin, let's dive into understanding how the user goes about creating,
sending, and receiving email. We'll finish with a discussion of how to forge email.
Email Headers
The process of sending and receiving email involves two types of systems: the mail client (that's you) and the mail server (similar to the post office). To understand email headers, one must understand that email doesn't simply go from points A to B and suddenly "You have mail!" In many cases, an email message routes through four computers before it reaches its destination. Technically speaking, the total number of systems involved in the full process of email delivery is about twice that, but it's transparent and performed efficiently.
For examples in our email demonstrations, we will use an email message that I want to send to my readers. The email addresses we will use are:
me@sendingemail.com
you@receivingemail.com
My mail server will be mail.sendingemail.com, the receiver will be mail.receivingemail.com. The sending workstation will be called Sender, and the receiving workstation will be called Receiver. Now let's look at the internal operations of an area most of you reading this book should be familiar with: the client user experience of opening an email client to enter the To, Subject, and Body fields in the new email message.
Figure 1 shows an example of a common screen for creating an email message:

Figure 1
Figure 1 Standard Email Process: Creating a Message
As you can see, there is an optional CC field, enabling you to add email addresses to send this message to (a perk you don't get at the standard post office with a single stamp and envelope). Then I click Send and off my message goes to be received by you@receivingemail.com.
It appears that this comes off without a hitch, but the internal workings are what keep the message going. The mail protocol has headers that mark the emails with information on where it originated, its destination address, and the route it took to get there. Yes, that's right, email tells a story of its delivery, similar to a tracking number when you ship something via a carrier like Federal Express. The development of the email header's progress on its way to the destination address are typically marked by three different systems that are handling the mail delivery. I sent mail to you@receivingemail.com and the minute I clicked Send, the message was handed off to my mail server (mail.sendingemail.com). At that point, my mail client sent the mail server the following email headers to process:
From:me@sendingemail.com (Lance James)
To: you@receivingemail.com
Date: Tue, April 04, 2005 23:01:12 PST
X-Mailer: Microsoft Outlook, Build 10.0.2616
Subject: This is your subject field
As you can see, the fields I referred to are actually headers. Email is technically constructed of headers with the field: value set. A blank line separates sections within the headers, so the actual body has a blank line with a content type before it, usually plaintext, which is indicated by the following:
Content-Type: text\plain; charset=ISO-8859-1: format=flowed
This text is usually found below the headers we displayed previously (different mailers have different header ordering) and indicates the type of content found within the email. The content-type field is determined by the mail client since it knows what it is sending. When we send plaintext, the content-type field is optional, but the majority of mail clients use it to stay within the specifications found in requests for comment (RFCs; see www.imc.org/rfcs.html).
As we continue, our mail client has sent the email to our mail server (mail.sendingemail.com). The mail server will read the header information that our mail client sent it, and will add some additional header information before sending it off to the receiver's mail server (mail.receivingemail.com). Here is what the headers look like:
Received: from sender (xx.7.239.24) 
by mail.sendingemail.com (Postfix) id 125A56; Tue, April 04, 2005 23:01:16 -0800 (PST)
From: me@sendingemail.com (Lance James)
To: you@receivingemail.com
Date: Tue, April 04, 2005 23:01:12 PST
Message-ID: ssc041837262361-293482299@mail.sendingemail.com
X-Mailer: Microsoft Outlook, Build 10.0.2616
Subject: This is your subject field
There are a few extra additions marked on there, mainly stating from where the message was received (the mail client, when it identified itself to the mail server) and the time it was received, along with a message ID. The message ID has no human-based significance, but from an administrative standpoint, a mail administrator can use it to look up emails. The email message ID is similar to a FedEx or UPS Tracking number, and although it's a completely random number, can be very useful.
Let's view the final header additions marked on the receiving mail server endpoint:
Received: from mail.sendingemail.com 
(mail.sendingemail.com [xx.7.239.25]) 
by mail.receivingemail.com (Postfix) with ESMTP id T12FG932 
for <you@receivingemail.com>; Tue, 04 April 2005 23:01:22 -0800 (PST)
Received: from sender (xx.7.239.24) by mail.sendingemail.com 
(Postfix) id 125A56; Tue, April 04, 2005 23:01:16 -0800 (PST) 
From: me@sendingemail.com (Lance James)
To: you@receivingemail.com
Date: Tue, April 04, 2005 23:01:12 PST
Message-ID: ssc041837262361-293482299@mail.sendingemail.com
X-Mailer: Microsoft Outlook, Build 10.0.2616
Subject: This is your subject field
When the receiving client user sits down at the receiver workstation, he will be able to view these email headers within the email (depending on the email client software, he might have to select the appropriate view headers field). When you receive an email, it can be very important to understand headers so you can trace the historical logs of an email. Let's look at the last set of headers we received and review each line item added to the Received headers.
Received from: mail.sendingemail.com 
(mail.sendingemail.com [xx.7.239.25]) 
by mail.receivingemail.com (Postfix) with ESMTP id T12FG932 
for you@receivingemail.com; Tue, 04 April 2005 23:01:22 -0800 (PST)
This first header tells us that this message was received by a server dubbed mail.sendingemail.com. The parentheses show the verification of identity, stating that a DNS reverse lookup revealed that the IP matches this identification and that xx.7.239.25 is the IP address the message came in from. The mail server that received the email is mail.receivingemail.com, which is running Postfix ESMTP with an arbitrary id of T12FG932. The ID is arbitrary and constructed by the receiving mail server for administrative purposes. The email address this message is intended for is you@receivingemail.com, with a receive date of Tuesday, April 4, 2005, at 11:01 P.M. and 22 seconds, Pacific Standard Time.
This entry header:
Received: from sender (xx.7.239.24) by 
mail.sendingemail.com (Postfix) id 125A56; 
Tue, April 04, 2005 23:01:16 -0800 (PST)
documents the mail transfer between the Sender workstation and the sender's mail server. It is identified by the IP address in parentheses, and we know that mail.sendingemail.com is a Postfix server and has labeled this message with an arbitrary message ID. The date of mail transfer was Tuesday, April 4, 2005, at 11:01 P.M. and 16 seconds, Pacific Standard Time.
The headers derived in this email are legitimate headers. Anytime a system assists in routing an email, an extra Received header will be added on. Notice that the order of Received headers is destination endpoint first, and the bottom header is the starting point (see Figure 2).

Figure 2
Figure 2 Standard Email Process: Multiple Hops Required to Reach Receiver

STEP   2 :


Phishers take advantage of these settings to successfully perform social engineering against the average email user. To understand this concept a bit more, let's take a quick review of the email protocol.
Within the typical setup for email, two ports are typically used: port 25, and port 110. Port 25 is the Simple Mail Transfer Protocol (SMTP), and its job is to transmit and receive mail—basically what is called a Mail Transfer Agent, or MTA. An MTA is comparable to the mail carrier who picks up the mail and sends it off to where it needs to go. Just as the mail carrier drops off and picks up mail, so does the MTA. Port 110 is the Post Office Protocol, version 3 (POP3), and it is essentially the mailbox from which users pick up their mail up. This has an authentication process that allows users to log in and retrieve their email, which, in most cases, depending on your settings, is set to delete the mail from the server once you have completely retrieved it.
Raw SMTP Communication
A quick way to comprehend the operations of SMTP is to send an email using the Telnet protocol. Telnet is a communication protocol that allows you to connect to and communicate with a port in a terminal. In this case, we will Telnet to port 25 of mail.sendingemail.com:
me@unixshell~$ telnet mail.sendingemail.com 25
Trying 127.0.0.1...
Connected to mail.sendingemail.com.
Escape character is '^]'.
220 mail.sendingemail.com ESMTP
We have successfully established a session with the SMTP or ESMTP (Extended STMP) server, and it has given us a return code of 220. We can now send it commands. The commands typically used to send email are HELO, MAIL FROM, RCTP TO, DATA, and QUIT. Basically, five primary commands control the majority of the protocol.
To start, we have to identify ourselves by simply saying HELO:
220 mail.sendingemail.com ESMTP Postfix
HELO sender.sendingemail.com
250 mail.sendingemail.com Hello 
sender.sendingemail.com [xx.7.239.24], 
pleased to meet you
As you can see, the server greeted us back and identified us by displaying our IP address. Technically, we could make up anything describing who we are; most SMTP servers will allow that because they know our IP, and it will mark our IP within the Received headers.
To send email after the meet and greet, we want to tell the mail server who the email is from and where it is going:
MAIL FROM: me@sendingemail.com
250 me@sendingemail.com... Sender ok
RCPT TO: you@receivingemail.com 
250 you@receivingemail.com… Recipient ok
This code states that the inputs we've entered are okay. In the real world, we would be rejected for the RCTP TO: from Telnet, since relaying to another network should be denied. But since we're on our own network and run our own mail server locally, this is allowed. Note that this is a quick and easy way to forge headers right at the MAIL FROM: and RCPT TO: fields. From our local network, we can put anything we want in both those fields and it will be accepted. This is one basis for some forgery; the other is the open relays, which we will get to shortly.
To send our message, we will use the DATA command:
DATA
354 Enter mail, end with "." On a line by itself
Subject: Test Email
Here is my data that I would like to send to you@receivingemail.com. This is essentially the body of the message and we will close by skipping a line and entering "." -me
.
250 I6A2341RR Message accepted for delivery
QUIT
221 mail.sendingemail.com closing connection
Note that the 250 return code revealed an ID for our message; this is the message ID we see in the headers on the way out. Once we tell the mail server QUIT, it will send our message. This is the internal protocol that SMTP works with. As you can see, it's simple and flexible, which is the exact reason the technology enables so many problems while also offering convenience.
The mail server infrastructure works in such an efficient fashion that we did not use only four servers but, at minimum, eight servers to deliver our email. In the process of sending email, we query multiple DNS servers to obtain information about where the mail servers are on the Internet.
Here is an example of the complete process for sending an email (see Figure 4):

Figure 4
Figure 4 Standard Email Infrastructure
  1. Create the email, specifying the From, To, Subject, and content.
  2. After you click Send, the mail client will access the DNS server of your ISP to locate your local mail server.
  3. The local mail server (mail.sendingemail.com in our example) receives your email and uses the local DNS to determine who sent it by doing a reverse IP lookup of Sender.
  4. After verification, the local mail server adds the headers and relays the mail to the mail.receivingemail.com mail server. To do this, mail.sendingemail.com has to look up what is called a mail exchange, or MX, record within DNS. This MX says, "Hello mail.sendingemail.com, mail.receivingemail.com is handling mail for receivingemail.com." Once that has been identified by our mail server, it can relay to the proper mail server.
  5. Once mail.receivingemail.com receives the email, it applies more header information, including routing data and receiving time; checks the DNS server for a reverse lookup regarding mail.sendingemail.com; and looks up the user you for the domain it is handling mail for.
  6. Client email user Receiver contacts mail.receivingemail.com (again, local DNS is used), makes a request to the POP3 port (110), and asks to retrieve its email. The email is delivered to the email client, and Receiver happily reads the email.

Step 3 :






Explaining DNS Concepts - DNS Servers-DNS Queries-DNS Records

3 types of DNS queries— recursive, iterative, and non-recursive 3 types of DNS servers— DNS Resolver, DNS Root Server and Authoritative Name...