Microsoft
®Exchange 2013
Referent: Daniel Glomb
System Architect
Agenda
•
What‘s new
•
Architecture
•
Client Access Server
•
Mailbox Server
•
Migration
What‘s new in Exchange 2013
Exchange Administration Center (EAC)
•
https://{fqdn}/ecp
Public Folder
Security in Exchange 2013
•
Data Loss Prevention (DLP)
•
eDiscovery
Updates
•
Cumulative Updates (CU)
•
Security Updates
Exchange 2013 Prerequisites
•
Server Operating Systems
Windows Server 2008 R2 (Enterprise with DAG) Windows Server 2012
•
Supported Client Access Methods
Outlook 2013, 2010, 2007
RPC over HTTP is only method of connectivity for Outlook clients Web Services
Entourage 2008 for Mac, Outlook for Mac 2011
•
Supported Coexistence scenarios
Exchange Server 2010 SP3, Exchange Server 2007 SP3 (+ coexistence RU 10)
No Exchange 2003 or older Exchange systems are supported, No in-place upgrades
•
MAPI / CDO
Administration Tools
•
Exchange admin center (EAC)
Webfrontend
URL: https://{fqdn}/ecp Mailbox Server required Public Folder integration
•
Exchange Management Shell (EMS)
PowerShell with CMDlet for Exchange
•
Exchange Toolbox
Templates Editor
Remote Connectivity Analyzer Queue Viewer
DEMO
Exchange 2010 Server Role Architecture
Client Access
for client connectivity and web servicesMailbox
for storage of dataHub Transport
for internal routing and policy enforcementEdge Transport
for routing and anti-malware from the edge of the organizationUnified Messaging
for voice mail and voice accessInternal Network
Phone system (PBX or VOIP)Web browser
Outlook (remote user) Mobile phone
Line of business application
Mailbox Stores mailbox and
public folder items
Unified Messaging Voice mail and
voice access
Client Access Client connectivity
Web services
Outlook (local user)
Layer 7 LB
AD
Edge Transport Routing and
AV/AS
Hub Transport Routing and policy Forefront Online
Protection for Exchange
External SMTP Server
Exchange 2013 Server Role Architecture
2 building blocks
Client Access Array
Evolution of E2010 CAS Array SMTP Front-End
Database Availability Group
Evolution of E2010 DAG
Includes core server protocols
Internal Network
Phone system (PBX or VOIP)
Web browser Outlook (remote user) Mobile device
Line of business application AD DAG Lay er 4 LB CAS Array Exchange Online Protection Outlook (local user) External SMTP Server
Functional Layering
AuthN, Proxy, Re-direct Protocols, API,
Biz-logic
Assistants, Store, CI
E2010 Architecture
AuthN, Proxy, Re-direct
Store, CI
Protocols, Assistants, API,
Biz-logic
E2013 Architecture
CAS2013
MBX2013 CAS, HT,
UM
MBX
Exchange access path
Protocols, Server Agents Business Logic Storage EWS RPC CA Transport Assistants MRS MRSProxy EWS RPC CA Transport Assistants MRS MRSProxyServer1 (Vn) Server2 (Vn+1)
XSO MailItem Other API CTS Store ESE Content index File system XSO MailItem Other API CTS Store ESE Content index File system SMTP MRS proxy protocol EWS protocol Custom WS Banned E2010
Load Balancer MDB HTTP Proxy IIS
Client
Access
RPC CAMailbox
IISRPS OWA, EAS, EWS, ECP, OAB
POP,
IMAP SMTP UM
POP
IMAP Transport UM
SMTP POP, IMAP HTTP MailQ RpcProxy SMTP SIP Redirect
SIP + RTP POP/IMAP
Outlook Web App Outlook EAS EAC PowerShell
Load Balancing
•
4 LB (protocol layer)
no IP/Cookie affinity required
no Layer 7 LB required (application layer) availability probe
•
Connection forwarding / proxy
independent from Client Access Server LB detects CAS maintenance
•
DNS Round Robin
CAS consequences
13
•
Outlook Anywhere is default
•
No RPC between Client and CAS
•
No RPC between CAS and MBX
•
CAS Array exists no longer
Mailbox Server - Database
14
•
Extensible Storage Engine (ESE)
•
own worker process
multiple store threads
•
I/O reduction, since Exchange 2003 ca. 97 %
•
Mailbox100GB+
Mailbox Server - High Availability
•
Database Availability Group
Can have a maximum of 16 Mailbox Servers DAG members can be in different sites
50% I/O reduction on the passive copy Auto Reseed Feature
•
Managed Availability
Self Monitoring
Workload Management
Restart
Failover / Reboot
Escalate
Public Folders
•
Architectural bet
Public folders are based on the mailbox architecture
•
Details
Hierarchy is stored in PF mailboxes (one writeable)
Content can be broken up and placed in multiple mailboxes The hierarchy folder points to the target content mailbox Uses same HA mechanism as mailboxes
No separate replication mechanism Single-master model
Similar administrative features to current PFs (setting quota, expiry, etc.) No end-user changes (looks just like today’s PFs)
Get instant statistics Use proximity searches to
understand context
Query results across Exchange, Lync &
SharePoint Laser focused refiners to
help find the data you need
Fine tune complex
Who
Where
Upgrading to Exchange 2013
from an existing
Exchange 2010
environment
SP3 E2010 CAS E2010 HUB E2010 MBX Clients
Internet facing site – Upgrade first
autodiscover.contoso.com mail.contoso.com Intranet site Exchange 2010 Servers SP3 1. Prepare
Install Exchange 2010 SP3 across the ORG Prepare AD with E2013 schema
Validate existing Client Access using Remote
Connectivity Analyzer and test connectivity cmdlets
4. Switch primary namespace to Exchange 2013 CAS
E2013 fields all traffic, including traffic from Exchange 2010 users
Validate using Remote Connectivity Analyzer
5. Move Mailboxes
Build out DAG
Move E2010 users to E2013 MBX
6. Repeat for additional sites 2. Deploy Exchange 2013 servers
Install both E2013 MBX and CAS servers
SP3 SP3
E2013 CAS
E2013 MBX
3. Obtain and Deploy Certificates
Obtain and deploy certificates on E2013 Client Access Servers
1 2 4
3
Upgrading to Exchange 2013
from an existing
Exchange 2007
environment
RU E2007 SP3 CAS E2007 SP3 HUB E2007 SP3 MBX Clients
Internet facing site – Upgrade first
autodiscover.contoso.com mail.contoso.com Intranet site Exchange 2007 Servers RU 1. Prepare
Install Exchange 2007 SP3 + RU10 across the ORG Prepare AD with E2013 schema and validate
5. Switch primary namespace to Exchange 2013 CAS
Validate using Remote Connectivity Analyzer
6. Move Mailboxes
Build out DAG
Move E2007 users to E2013 MBX
7. Repeat for additional sites 2. Deploy Exchange 2013 servers
Install both E2013 MBX and CAS servers
RU RU E2013 CAS E2013 MBX
3. Create Legacy namespace
Create DNS record to point to legacy E2007 CAS
4. Obtain and Deploy Certificates
Obtain and deploy certificates on E2013 Client Access Servers configured with legacy namespace, E2013 namespace and autodiscover namespace
Deploy certificates on Exchange 2007 CAS
legacy.contoso.com 3
1 2 5
4