Exchange 2013: Switch authentication to Kerberos

By default, connections from Outlook to Exchange 2013 are authenticated with NTLM. However, in environments with several CAS servers and many clients, NTLM generates unnecessary load on the DCs, precisely because load balancers no longer have to worry about persistence. It is better to use Kerberos authentication here so that not every CAS server has to re-authenticate the connection ... Read more

The search for a Forefront TMG replacement (The conclusion)

At the end of last year, I started looking for a replacement for Forefront TMG and found a few very interesting solutions: Part 1: KEMP Edge Security Pack Part 2: Sophos UTM 9.1 Part 3: Windows Server 2012 R2 + ARR 2.5 Part 4: Windows Server 2012 R2 + Web Application Proxy Part 5: Debian 7 ... Read more

Exchange 2013: SMTP 421 4.3.2 Service not active

Exchange 2013 has the Managed Availability functions. Among other things, Managed Availability is able to put Exchange services into maintenance mode. This is important, for example, when updates or service packs are installed on Exchange 2013 servers. During the installation of CU3, however, it happened to me that the maintenance mode was not terminated again. Read more

Exchange 2013: Making ActiveSync access more secure with on-board tools

Accessing Exchange mailboxes via ActiveSync is now part of everyday life, but the risks associated with mobile access should not be ignored. Often users have not even protected their smartphone with a PIN, and if the smartphone is stolen or lost, anyone can read the business emails or do worse things. ... Read more

Exchange 2013: Test system with Database Availability Group (DAG) and Kemp load balancers (Part 5)

In the last part of this series of articles, we test the configured HA environment. The environment has not yet been optimized, but the results are quite impressive. Here you can see that Outlook 2013 no longer connects to the Exchange Server FQDN, but to a value consisting of "Mailbox GUID + @ + UPN Suffix" In the ... Read more

Exchange 2013: Test system with Database Availability Group (DAG) and Kemp load balancers (part 4)

In parts 1, 2 and 3 of this series of articles, we have already installed the Exchange servers, configured the load balancers for HA and created a DAG. Now the Exchange configuration for load balancing and the actual load balancer configuration are still missing to make the Exchange CAS role highly available. We will take care of this in this article. So let's take care of ... Read more

Exchange 2013: Test system with Database Availability Group (DAG) and Kemp load balancers (part 3)

Before we set up the DAG, we quickly configure the environment by first logging in to the ECP (https://exchangeserver/ecp) Under Message flow we add a new Accepted domain, in this example it is frankysweb.de Then we create a new send connector And now an e-mail address policy Now we can configure the DAG. ... Read more

Exchange 2013: Test system with Database Availability Group (DAG) and Kemp load balancers (part 2)

The Exchange servers have already been installed in part 1, in this part the Kemp load balancers are configured for HA operation. First, the default IP is changed to an address for the test network And then the default gateway: And the DNS servers I select "LB1" as the host name so that the devices can be identified more easily Then ... Read more

Exchange 2013: Test system with Database Availability Group (DAG) and Kemp load balancers (Part 1)

It's almost like Christmas: 2 new HP servers and 2 Kemp load balancers arrived today. The systems are actually intended for an Exchange 2010 cluster, but since there is still a little time left, it makes sense to test Exchange 2013 high availability with the systems. The following hardware is available for the test ... Read more