Exchange 2013 Site Resilient / DR setup; remove DR CAS server from serving DR-local users

%3CLINGO-SUB%20id%3D%22lingo-sub-2701828%22%20slang%3D%22en-US%22%3EExchange%202013%20Site%20Resilient%20%2F%20DR%20setup%3B%20remove%20DR%20CAS%20server%20from%20serving%20DR-local%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2701828%22%20slang%3D%22en-US%22%3E%3CP%3Ewe%20got%20exchange%202013%20deployment%20in%20our%20primary%20data%20center%20with%20AD%20Domain%20%3D%20domain1.com%20and%20AD%20site%3D%20primary-Site%20and%26nbsp%3B%20with%20two%20exchange%202013%20servers%20each%20with%20CAS%2Bmailbox%20roles%20(srv1.domain1.com%20%2B%20srv2.domain1.com)%20setup%20as%20DAG%20and%20file-share%20witness%20server%20in%20same%20data%20center%20filesrv.domain1.com.%20each%20mailbox%20database%20has%202%20copies%20one%20active%20and%20one%20passive.%20both%20CAS%20servers%20are%20load-balanced%20by%20a%20separate%20dedicated%20load%20balancer%20for%20all%20exch%20services%20like%20OWA%2C%20ECP%2C%20EWS%2CMAPI%2C...%3C%2FP%3E%3CP%3Ein%20this%20office%20the%20owa%20namespace%20is%20%3D%20%3CA%20href%3D%22https%3A%2F%2Fowa.domain1.com%2C%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fowa.domain1.com%2C%3C%2FA%3E%20where%20all%20users%20Outlook%20clients%20connect%20and%20discovers%20to%20their%20mailboxes%20using%20MAPI%2FHTTP%20to%20%3CA%20href%3D%22https%3A%2F%2Fowa.domain1.com%2F..%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fowa.domain1.com%2F..%3C%2FA%3E.%20which%20is%20fine%20since%20the%20outlook%20clients%20are%20in%20the%20same%20LAN%20of%20the%20exchange%20servers%20data%20center%201%20and%20belonging%20to%20domain1.com%20AD%20domain.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20wanted%20to%20achieve%20Site%20Resiliency%20(a.k.a%20DR)%20to%20our%20exchange%20setup.%20we%20have%20already%20a%20working%20data%20center%202%20in%20another%20country%20with%3A%3C%2FP%3E%3CP%3EAD%20Domain%20%3D%20domain2.com%20and%20AD%20site%3D%20Branch-Site%20and%26nbsp%3B%20with%20two%20exchange%202013%20servers%20each%20with%20CAS%2Bmailbox%20roles%20(srv1.domain2.com%20%2B%20srv2.domain2.com)%20setup%20as%20DAG%20and%20fileshare%20witness%20server%20in%20same%20data%20center%20filesrv.domain2.com.%20each%20mailbox%20database%20has%202%20copies%20one%20active%20and%20one%20passive.%20both%20CAS%20servers%20are%20load%20balanced%20by%20a%20separate%20dedicated%20load%20balancer%20for%20all%20exch%20services%20like%20OWA%2C%20ECP%2C%20EWS%2CMAPI%2C...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Esimilar%20to%20the%20primary%20office%2C%20this%20branch%20office%20has%20local%20LAN%20Outlook%20users%20(belonging%20to%20domain2.com%20AD)%20connects%20to%20their%20mailboxes%20which%20are%20hosted%20on%20the%20domain2%20Exchange%20owa%2FDAG%3C%2FP%3E%3CP%3Ethis%20office%20owa%20namespace%20is%20%3D%20%3CA%20href%3D%22https%3A%2F%2Fowa.domain1.com%2C%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fowa.domain2.com%2C%3C%2FA%3E%20where%20all%20users%20Outlook%20clients%20connect%20and%20discovers%20to%20their%20mailboxes%20using%20MAPI%2FHTTP%20to%20%3CA%20href%3D%22https%3A%2F%2Fowa.domain1.com%2F..%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fowa.domain2.com%2F..%3C%2FA%3E.%20which%20is%20fine%20since%20the%20outlook%20clients%20are%20in%20the%20same%20LAN%20of%20the%20exchange%20servers%20data%20center%202%20and%20belonging%20to%20domain2.com%20AD%20domain.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENotes%3A%3C%2FP%3E%3CP%3Eboth%20domains%20domain1.com%20and%20domain2.com%20have%20full%20trust%20and%20belong%20to%20same%20AD%20forest.%20VPN%20links%20exist%20between%20both%20offices%20and%20functional.%20both%20domains%20are%20at%20the%20same%20level%2F%20no%20child%20domains%20exist.%3C%2FP%3E%3CP%3Eall%20users%20primary%20SMTP%20domain%20is%20unified%20%3D%20%3CA%20href%3D%22mailto%3Aname%40email.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ename%40email.com%3C%2FA%3E%3C%2FP%3E%3CP%3Einternal%20DNS%20autodiscover.email.com%20%3D%3D%26gt%3B%20owa.domain1.com%3C%2FP%3E%3CP%3Ethru%20Outlook%20connection%20status%20we%20can%20identify%20which%20CAS%20the%20user%20is%20connecting%20to.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECase%20Scenario%3A%3C%2FP%3E%3CP%3EWe%20wanted%20to%20achieve%20Site%20Resiliency%20(a.k.a%20DR)%20to%20our%20exchange%20setup%20in%20the%20Primary%20Office.%20we%20choose%20the%20branch%20office%20to%20be%20this%20DR%20site%20for%20our%20Exchange%20services%20in%20the%20primary%20office.%3C%2FP%3E%3CP%3EWe%20prepared%20a%20new%20AD%20DC%20%2B%20DNS%20%2B%20GC%20(srv3.domain1.com)%20in%20branch%20office%20in%20AD%20site%20Branch-Site%20with%20dedicated%20IP%20of%20branch%20office%20range%20along.%3C%2FP%3E%3CP%3EWe%20prepared%20a%20new%20Exchange%202013%20server%20(srv3.domain1.com)%20in%20Branch-Site%20with%20branch%20site%20IP%20range%20to%20be%20CAS%2BMBX%20roles.%20we%20joined%20the%20srv3.domain1.com%20to%20DAG%20of%20the%20primary%20office.%20we%20added%203rd%20copy%20of%20the%20databases%20existing%20in%20primary%20office%20and%20got%20replicated%20successfully%20to%20srv3.domain1.com.%3C%2FP%3E%3CP%3Ealso%20same%20virtual%20directory%20names%20we%20configured%20on%20srv3.domain1.com%20similar%20to%20what%20is%20configured%20for%20srv1%2F2.domain1.com%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIssue%3A%3C%2FP%3E%3CP%3Ethe%20strange%20behavior%20after%20deploying%20the%203rd%20exchange%20server%20srv3.domain1.com%20in%20the%20branch%20office%20site%2C%20here%20is%20that%20the%20local%20LAN%20users%20of%20branch%20office%20(whose%20user%20accounts%20belong%20to%20AD%20domain%20domain2.com%20and%20have%20mailboxes%20under%20branch%20exchange%20setup%20DAB%20of%20srv1%2F2.domain2.com%20with%20%3CA%20href%3D%22https%3A%2F%2Fowa.domain2.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fowa.domain2.com%3C%2FA%3E)%2C%20now%20these%20outlook%20LAN%20clients%20connect%20to%20%3CA%20href%3D%22https%3A%2F%2Fowa.domain1.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fowa.domain1.com%3C%2FA%3E%20(which%20is%20hosted%20over%20WAN%20on%20primary%20DC)%20which%20is%20hosted%20in%20the%20primary%20office%20data%20center.%20we%20don't%20want%20our%20branch%20users%20outlook%20clients%20to%20connect%20over%20Internet%20WAN%20link%20to%20the%20primary%20exchange%20CAS%20(%3CA%20href%3D%22https%3A%2F%2Fowa.domain1.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fowa.domain1.com%3C%2FA%3E).%20these%20outlook%20clients%20used%20normally%20to%20connect%20to%20the%20branch%20exchange%20CAS%20owa.domain2.com.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERequired%20to%20achieve%3A%3C%2FP%3E%3CP%3EWe%20want%20srv3.domain1.com%20CAS%2BMBX%20as%20DR%20server%20to%20switch%20over%20to%20it%20from%20primary%20office%20to%20it%20in%20case%20of%26nbsp%3B%20primary%20DC%20is%20down%20and%20to%20keep%20the%20existing%20branch%20users%20connecting%20normally%20to%20their%20exchange%20setup%20owa.domain2.com%20and%20NOT%20to%20use%20the%20owa.domain1.com%20by%20any%20means%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2701828%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%202013%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eexchange%20autodiscover%20outlook%20autodiscover%20CAS%20URLs%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eexchange%20disaster%20recovery%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eexchange%20site%20resiliency%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
New Contributor

we got exchange 2013 deployment in our primary data center with AD Domain = domain1.com and AD site= primary-Site and  with two exchange 2013 servers each with CAS+mailbox roles (srv1.domain1.com + srv2.domain1.com) setup as DAG and file-share witness server in same data center filesrv.domain1.com. each mailbox database has 2 copies one active and one passive. both CAS servers are load-balanced by a separate dedicated load balancer for all exch services like OWA, ECP, EWS,MAPI,...

in this office the owa namespace is = https://owa.domain1.com, where all users Outlook clients connect and discovers to their mailboxes using MAPI/HTTP to https://owa.domain1.com/... which is fine since the outlook clients are in the same LAN of the exchange servers data center 1 and belonging to domain1.com AD domain.

 

 

We wanted to achieve Site Resiliency (a.k.a DR) to our exchange setup. we have already a working data center 2 in another country with:

AD Domain = domain2.com and AD site= Branch-Site and  with two exchange 2013 servers each with CAS+mailbox roles (srv1.domain2.com + srv2.domain2.com) setup as DAG and fileshare witness server in same data center filesrv.domain2.com. each mailbox database has 2 copies one active and one passive. both CAS servers are load balanced by a separate dedicated load balancer for all exch services like OWA, ECP, EWS,MAPI,...

 

similar to the primary office, this branch office has local LAN Outlook users (belonging to domain2.com AD) connects to their mailboxes which are hosted on the domain2 Exchange owa/DAG

this office owa namespace is = https://owa.domain2.com, where all users Outlook clients connect and discovers to their mailboxes using MAPI/HTTP to https://owa.domain2.com/... which is fine since the outlook clients are in the same LAN of the exchange servers data center 2 and belonging to domain2.com AD domain.

 

Notes:

both domains domain1.com and domain2.com have full trust and belong to same AD forest. VPN links exist between both offices and functional. both domains are at the same level/ no child domains exist.

all users primary SMTP domain is unified = name@email.com

internal DNS autodiscover.email.com ==> owa.domain1.com

thru Outlook connection status we can identify which CAS the user is connecting to.

 

 

Case Scenario:

We wanted to achieve Site Resiliency (a.k.a DR) to our exchange setup in the Primary Office. we choose the branch office to be this DR site for our Exchange services in the primary office.

We prepared a new AD DC + DNS + GC (srv3.domain1.com) in branch office in AD site Branch-Site with dedicated IP of branch office range along.

We prepared a new Exchange 2013 server (srv3.domain1.com) in Branch-Site with branch site IP range to be CAS+MBX roles. we joined the srv3.domain1.com to DAG of the primary office. we added 3rd copy of the databases existing in primary office and got replicated successfully to srv3.domain1.com.

also same virtual directory names we configured on srv3.domain1.com similar to what is configured for srv1/2.domain1.com

 

Issue:

the strange behavior after deploying the 3rd exchange server srv3.domain1.com in the branch office site, here is that the local LAN users of branch office (whose user accounts belong to AD domain domain2.com and have mailboxes under branch exchange setup DAB of srv1/2.domain2.com with https://owa.domain2.com), now these outlook LAN clients connect to https://owa.domain1.com (which is hosted over WAN on primary DC) which is hosted in the primary office data center. we don't want our branch users outlook clients to connect over Internet WAN link to the primary exchange CAS (https://owa.domain1.com). these outlook clients used normally to connect to the branch exchange CAS owa.domain2.com.

 

Required to achieve:

We want srv3.domain1.com CAS+MBX as DR server to switch over to it from primary office to it in case of  primary DC is down and to keep the existing branch users connecting normally to their exchange setup owa.domain2.com and NOT to use the owa.domain1.com by any means

 

0 Replies