Presentation is loading. Please wait.

Presentation is loading. Please wait.

MEC 2014 4/5/2017 10:23 PM © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.

Similar presentations


Presentation on theme: "MEC 2014 4/5/2017 10:23 PM © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks."— Presentation transcript:

1 MEC 2014 4/5/ :23 PM © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

2 Troubleshooting Hybrid Mailflow
4/5/ :23 PM MNGIN301 Troubleshooting Hybrid Mailflow Vincent Yim Premier Field Engineer Microsoft Services © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

3 Agenda Refresher/Overview of Hybrid Routing Mailflow Options
4/5/ :23 PM Agenda Refresher/Overview of Hybrid Routing Mailflow Options EOP in Hybrid Review tools to assist in mail flow troubleshooting Issues Other fun stuff Questions © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

4 Refresher/Overview of Hybrid Routing
4/5/ :23 PM Refresher/Overview of Hybrid Routing 2 Distinct Exchange organizations HCW creates connectors in each Exchange org. # of connectors vary based on Exchange version Secure Mail © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

5 Refresher/Overview of Hybrid Routing
4/5/ :23 PM Refresher/Overview of Hybrid Routing All messages that are sent between on-premises and ExO are sent over a secure connection using TLS The Hybrid Configuration wizard creates a dedicated send connector on-premises scoped to the coexistence domain (tenant.mail.microsoftonline.com) An outbound connector in EOP is also created and is scoped to the default SMTP domain (contoso.com) Each organization is configured to treat messages sent from the other organization as internal This allows messages to bypass anti-spam settings and other services The TLS connection for on-prem server must be a minimum of Exchange 2010 SP1 Any other SMTP end point accepting the messages will cause the required headers to be lost which will impact secure mail functionality © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

6 Refresher/Overview of Hybrid Routing
4/5/ :23 PM Refresher/Overview of Hybrid Routing domain sharing Both orgs will accept “contoso.com” authoritative How do we prevent mail loops? Actually, it’s all about how addressing works Requires a coexistence domain for “Backboning” mailflow © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

7 Refresher/Overview of Hybrid Routing
4/5/ :23 PM Refresher/Overview of Hybrid Routing Coexistence Domain Based off of the Microsoft Online Default Routing Domain The coexistence domain is a domain created for each Office 365 tenant in the format of <your tenant>.mail.onmicrosoft.com domain For example, if your Default Routing domain is “tenant.onmicrosoft.com” then your coexistence domain would be “tenant.mail.onmicrosoft.com” Created when you activate DirSync in your Office 365 tenant AutoDiscover and MX records created automatically for this domain Provides the backbone of all coexistence features Added as an on-premises address policy when the HCW is run Mailboxes moved to Exchange Online will have the coexistence domain stamped on their user object as a target address © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

8 Demo DirsyncStates Pre/Post Migration 4/5/2017 10:23 PM
© 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

9 On-premise Active Directory Exchange Online
On-premise Active Directory Exchange Online After initial Dirsync UserPrincipalName homemdb/homeMTA/ msexchhomeservername proxyaddresses External Address(targetaddress) present (Mailbox) others <NULL> <NULL> (Mail enabled User) After running Hybrid Configuration Wizard others After moving Alex' mailbox to Exchange Online <NULL> (Remot box/Mail-enabled User) 1) Kim sends to Alex. 2) Exchange on-prem receives message routed to: 3) Exchange on-prem reroutes the message to 4) Exchange on-prem finds a connector that has address space "contoso.mail.onmicrosoft.com" and sends it over to target server. 5) Exchange online receives message addressed to 6) ExO server finds recipient with a proxy address of and delivers into mailbox 6) Alex sees Kim's message and replies. (The mail from: address is always the capitalized SMTP address) 7) Kim receives message , and sees it comes from

10 On-Premises Organization Exchange Online Protection
4/5/ :23 PM MX resolves to on-premises gateway MX is switched to Exchange Online Protection Outbound Exchange Online traffic is delivered direct You can choose to route outbound on-premises mail via EOP Mailflow Options External User On-Premises Organization Internet Third Party Security System Exchange Exchange Online Protection Secure Mail Encrypted & Authenticated Mail Flow “David” On-premises Mailbox Exchange Online “Chris” Cloud Mailbox 10 © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

11 4/5/ :23 PM Mail Flow Options In addition to choosing how inbound messages are routed, you can also choose how outbound messages sent from Exchange Online recipients are routed. The following describes the available options: Centralized mail control: This option routes outbound messages sent from the Exchange Online users through on-premises This enables you to apply compliance rules to these messages that must be applied to all of your recipients, regardless of whether they're located in Exchange Online or on-premises Decentralized mail control: This option routes outbound messages sent from Exchange Online directly to the Internet Use this option, if you do not need to apply any on-premises policies or other processing to messages that are sent from recipients in the Exchange Online © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

12 On-Premises Organization Exchange Online Protection
4/5/ :23 PM Mailflow Options MX resolves to on-premises gateway All in and out of the Exchange Online tenant must go via on-premises MX is switched to Exchange Online Protection External User On-Premises Organization Internet Third Party Security System Exchange Exchange Online Protection Secure Mail Encrypted & Authenticated Mail Flow Exchange Online “David” On-premises Mailbox “Chris” Cloud Mailbox 12 © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

13 4/5/ :23 PM EOP When you create inbound/outbound connectors in Exchange Online Admin Center, these are sitting at the edge (EOP) SPAM Filtering Bypassed © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

14 Review Tools for Troubleshooting
4/5/ :23 PM Review Tools for Troubleshooting Delivery reports End user can run. Eliminates some helpdesk calls Somewhat useless to Admin Message Trace Loops NDRs Messages dropped due to virus Export to CSV Use the protocol log Set to verbose © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

15 Review Tools for Troubleshooting
4/5/ :23 PM Review Tools for Troubleshooting Analyze Headers ExRCA has Message Header Analyzer OWA MHA App Telnet (your Exchange server might be using IP that's been blacklisted by SPAMHAUS or one of other RBL services in use by EOP) DLP policy rule Hits found through message trace Or EAC Or (delayed) Mail Protection Reports for Exchange © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

16 Demo Mail Protection Reports for Exchange 4/5/2017 10:23 PM
© 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

17 Other Fun stuff Testing and Tracing Malware Filters
4/5/ :23 PM Other Fun stuff Testing and Tracing Malware Filters Create a file called EICAR.txt with the following text: Attach EICAR.TXT to a new mail message, and send it through the service. Confirm your antimalware filter settings have taken affect (policy changes can take up to an hour to replicate across datacenters) This “EICAR” test attachment will cause the message to be treated as malicious antivirus/antimalware engines © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

18 Other Fun stuff Testing and Tracing Content Filter
A GTUBE message should always be detected as spam by the content filter, and the actions that are performed upon the message should match your configured settings. Include the following GTUBE text in a mail message on a single line, without any spaces or line breaks: XJS*C4JDBQADN1.NSBN3*2IDNEN*GTUBE-STANDARD-ANTI-UBE-TEST- *C.34X

19 4/5/ :23 PM Other fun stuff On prem senders to internet recipients will get SPAM filtering Demo © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

20 Other fun stuff Outbound SPAM filter
4/5/ :23 PM Other fun stuff Outbound SPAM filter Why did the on-prem message route through high risk delivery pool? Outbound spam filtering is needed because malicious programmers and their malware are out there taking over computers inside corporate networks every day. This means that users in your organization can be sending large amounts of outbound spam without your knowledge © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

21 Issues Running a Hybrid server from home?
4/5/ :23 PM Issues Running a Hybrid server from home? ISPs using dynamic IP ranges will connect, but sessions will then be dropped by EOP. " Certificate validation failure." CRL check from hybrid server SMTP fixup/mailguard 220 **************************************************************************** *********************************** The above is a tell-tale sign that mailguard is enabled on a firewall appliance (most likely Cisco PIX), and it prevents either side from seeing the STARTTLS verb. Cannot perform secure mail flow without StartTLS verb © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

22 Issues Changing datacenter IP ranges?
4/5/ :23 PM Issues Changing datacenter IP ranges? Quite possibly need to re-run HCW if datacenter IP changes With Exchange 2010 HCW, point-in-time list is copied © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

23 4/5/ :23 PM Issues With Exchange 2010 HCW, you may need to adjust the EHLO response guessed by HCW © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

24 Issues Missing header? X-MS-Exhange-Organization-AuthAs =
4/5/ :23 PM Issues Missing header? X-MS-Exhange-Organization-AuthAs = Internal or Anonymous If anonymous, your message took another path © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

25

26 4/5/ :23 PM © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.


Download ppt "MEC 2014 4/5/2017 10:23 PM © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks."

Similar presentations


Ads by Google