Dedicated "Exchange Hybrid Server"

%3CLINGO-SUB%20id%3D%22lingo-sub-329879%22%20slang%3D%22en-US%22%3EDedicated%20%22Exchange%20Hybrid%20Server%22%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-329879%22%20slang%3D%22en-US%22%3E%3CP%20class%3D%22s90z9tc-10%20fHRkcP%22%3EHi%20all%2C%3C%2FP%3E%3CP%20class%3D%22s90z9tc-10%20fHRkcP%22%3EWe%20will%20be%20migrating%20about%202000%20users%20to%20Office%20365.%20How%20do%20you%20prepare%20the%20Hybrid%20Server%3F%20I%20suppose%20this%20should%20be%20new%20Exchange%20server%20with%20no%20mailboxes%20and%20just%20the%20CAS%20role%20(Exchange%202016)%20and%20not%20part%20of%20the%20DAG.%3C%2FP%3E%3CP%20class%3D%22s90z9tc-10%20fHRkcP%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22s90z9tc-10%20fHRkcP%22%3ELets%20say%20I%20set%20up%20two%20Hybrid%20servers%20(VM)%20with%202-4%20cores%2C%208-12GB%20of%20RAM%2C%20and%20100GB%20of%20disk%20space%20and%20install%20the%20SSL%20certificate%20-%20same%20one%20used%20across%20the%20Exchange%20org%3C%2FP%3E%3COL%3E%3CLI%3E%3CP%20class%3D%22s90z9tc-10%20fHRkcP%22%3EHow%20do%20I%20create%20a%20DNS%20namespace%20eg.%20hybrid.abc.com%20and%20publish%20this%20to%20the%20public%20DNS%3F%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%20class%3D%22s90z9tc-10%20fHRkcP%22%3EIs%20this%20the%20namespace%20I%20need%20to%20put%20in%20as%20the%20FQDN%20name%20in%20the%20HCW%20setup%3F%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%20class%3D%22s90z9tc-10%20fHRkcP%22%3EI%20suppose%20this%20namespace%20-%20hybrid.abc.com%20needs%20to%20be%20in%20the%20certificate%20SAN%3F%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%20class%3D%22s90z9tc-10%20fHRkcP%22%3ECan%20I%20add%20multiple%20hosts%20A%20record%20for%20hybrid.abc.com%20in%20the%20public%20DNS%20if%20I%20have%202%20or%20more%20hybrid%20servers%3F%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%20class%3D%22s90z9tc-10%20fHRkcP%22%3EDo%20I%20need%20to%20manually%20create%20the%20send%20connectors%20on%20the%20Hybrid%20servers%20to%20my%20Trend%20Micro%20IMVSA%3F%20This%20is%20the%20first%20hop%2C%20after%20Trend%20IMVSA%2C%20the%20next%20hop%20is%20the%20Cisco%20Email%20Security%20-%20our%20mail%20gateway%20to%20the%20internet.%20We%20have%20a%20Edge%20transport%20(ET)%20server%20for%20address%20rewriting%20for%20outgoing%20mails%20only.%20We%20will%20pass%20the%20address%20rewrite%20job%20to%20the%20Cisco%20instead.%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%20class%3D%22s90z9tc-10%20fHRkcP%22%3EShould%20I%20create%20a%20bypass%20in%20Trend%20IMVSA%20for%20hybrid%20traffic%20since%20this%20is%20only%20meant%20for%20mailbox%20migrations%3F%20create%20a%20rule%20a%20rule%20to%20bypass%20all%20traffic%20from%20hybrid%20server%20to%20Office365%20endpoints%3F%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%20class%3D%22s90z9tc-10%20fHRkcP%22%3EHow%20do%20I%20make%20sure%20that%20the%20Hybrid%20servers%20only%20do%20mailbox%20migrations%20and%20it%20will%20not%20process%20any%20email%20traffic%3F%3C%2FP%3E%3C%2FLI%3E%3C%2FOL%3E%3CP%20class%3D%22s90z9tc-10%20fHRkcP%22%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-329879%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMigration%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%20Groups%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOn-Premises%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-329894%22%20slang%3D%22en-US%22%3ERe%3A%20Dedicated%20%22Exchange%20Hybrid%20Server%22%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-329894%22%20slang%3D%22en-US%22%3EWith%20that%20number%20of%20questions%20your%20best%20advice%20is%20to%20get%20in%20expert%20help.%20Each%20answer%20to%20each%20question%20above%20is%20considerable%20work%20and%20your%20exact%20design%20matters.%20If%20you%20don't%20have%20any%20one%20who%20can%20help%20give%20me%20a%20call%20via%20the%20%3CA%20href%3D%22http%3A%2F%2Fwww.nbconsult.co%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ewww.nbconsult.co%3C%2FA%3E%20and%20the%20UK%20office.%3CBR%20%2F%3E%3CBR%20%2F%3EBrian%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi all,

We will be migrating about 2000 users to Office 365. How do you prepare the Hybrid Server? I suppose this should be new Exchange server with no mailboxes and just the CAS role (Exchange 2016) and not part of the DAG.

 

Lets say I set up two Hybrid servers (VM) with 2-4 cores, 8-12GB of RAM, and 100GB of disk space and install the SSL certificate - same one used across the Exchange org

  1. How do I create a DNS namespace eg. hybrid.abc.com and publish this to the public DNS?

  2. Is this the namespace I need to put in as the FQDN name in the HCW setup?

  3. I suppose this namespace - hybrid.abc.com needs to be in the certificate SAN?

  4. Can I add multiple hosts A record for hybrid.abc.com in the public DNS if I have 2 or more hybrid servers?

  5. Do I need to manually create the send connectors on the Hybrid servers to my Trend Micro IMVSA? This is the first hop, after Trend IMVSA, the next hop is the Cisco Email Security - our mail gateway to the internet. We have a Edge transport (ET) server for address rewriting for outgoing mails only. We will pass the address rewrite job to the Cisco instead.

  6. Should I create a bypass in Trend IMVSA for hybrid traffic since this is only meant for mailbox migrations? create a rule a rule to bypass all traffic from hybrid server to Office365 endpoints?

  7. How do I make sure that the Hybrid servers only do mailbox migrations and it will not process any email traffic?

Thanks

1 Reply
Highlighted
With that number of questions your best advice is to get in expert help. Each answer to each question above is considerable work and your exact design matters. If you don't have any one who can help give me a call via the www.nbconsult.co and the UK office.

Brian