Discussion:
Exchange 2k3 transition to 2k7
(too old to reply)
Teeves
2008-04-08 19:26:02 UTC
Permalink
Scenerio

1 2007 mailbox server (test mailboxes and actual test subject mailboxes)
1 2007 HT and CAS server
1 2003 exchange server (production)

have mail flowing as it should between all 3 servers, users can log into 2k7
OWA to access their
2k7 mailboxes just fine.

have a redirect set up as per MS documents, user accesses 2k7 server owa
via http://2k7server and it redirects to https://2k7server/exchange.

the problem is that when a users whose mailbox is on 2k3 logs into 2k7, it
will not
present the 2k3 OWA experience and I don't know why....

it just sits there and churns as if it were trying to find the 2k3 owa web
page.

iis logs on exchange 2k3 show:


2008-04-05 18:15:34 <2k3ipaddress> GET /exchange - 80 - <2k7HTCASserver-ip>
Exchange-Server-Frontend-Proxy/6.5+Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+5.1;+.NET+CLR+1.1.4322;+InfoPath.1;+.NET+CLR+2.0.50727;+.NET+CLR+3.0.04506.30;+.NET+CLR+3.0.04506.648;+MS-RTC+LM+8) 302 0 5
2008-04-05 18:15:34 <2k3ipaddress> GET /exchange - 80 - <2k7HTCASserver-ip>
Exchange-Server-Frontend-Proxy/6.5+Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+5.1;+.NET+CLR+1.1.4322;+InfoPath.1;+.NET+CLR+2.0.50727;+.NET+CLR+3.0.04506.30;+.NET+CLR+3.0.04506.648;+MS-RTC+LM+8) 302 0 5

2k3 is not in a FE/BE setting, it was a standalone server

we use SSL and forms based authentication....

HELP ME, my head hurts from banging it against the wall
Oliver Moazzezi [MVP]
2008-04-09 13:36:30 UTC
Permalink
Post by Teeves
2k3 is not in a FE/BE setting, it was a standalone server
we use SSL and forms based authentication....
HELP ME, my head hurts from banging it against the wall
Have you still got SSL and FBA enabled on the stand alone E2K3 Server?

Oliver
Teeves
2008-04-09 13:45:00 UTC
Permalink
SSL yes and FBA yes
Post by Oliver Moazzezi [MVP]
Post by Teeves
2k3 is not in a FE/BE setting, it was a standalone server
we use SSL and forms based authentication....
HELP ME, my head hurts from banging it against the wall
Have you still got SSL and FBA enabled on the stand alone E2K3 Server?
Oliver
Oliver Moazzezi [MVP]
2008-04-09 14:49:11 UTC
Permalink
Take the SSL off, I can't remember off the top of my head if FBA will cause
an issue.

Let the CAS handle all SSL connections

Oliver
Teeves
2008-04-09 15:36:01 UTC
Permalink
Ohhhh TY TY TY....

We are heading down the right street...
I've also had to change the SSL on the Public Virtual directory as well

my next question for those that use ActiveSync (ie smartphones)
will I have to remove the SSL on the Microsoft-Server-ActiveSync Virtual
directory as well?

We have another 'subject alternative' Certificate already on the new 2k7 box
and how will the smartphone react when their mailbox is still on 2k3 when I
switch the public address over to 2k7?

You've been a ton of help so far.
Post by Oliver Moazzezi [MVP]
Take the SSL off, I can't remember off the top of my head if FBA will cause
an issue.
Let the CAS handle all SSL connections
Oliver
Oliver Moazzezi [MVP]
2008-04-09 15:49:09 UTC
Permalink
Apply your SAN cert to the CAS server/s and remove any SSL settings from
your Exchange 2003 server.

Change any NAT rules you have to for any Internet facing URLs that were
pointing to the Exchange 2003 box now to your Client Access Server/s.

That should be all you need to do.


Oliver
Teeves
2008-04-11 18:17:01 UTC
Permalink
Active sync issues for smart phones.

OWA is working referring the users back to 2k3 if their mailbox is there.

now however, smart phones worked for a while now they just quit.

those users with their mailbox on 2k3 get 'attention required'
support code: 0x85010004

your account in MS Exch server does not have permissions to sync with your
current settings, contact your exchange server admin (that's me)

those users with mailboxes on 2k7 can sync to smart phones with no problem.
Post by Oliver Moazzezi [MVP]
Apply your SAN cert to the CAS server/s and remove any SSL settings from
your Exchange 2003 server.
Change any NAT rules you have to for any Internet facing URLs that were
pointing to the Exchange 2003 box now to your Client Access Server/s.
That should be all you need to do.
Oliver
Continue reading on narkive:
Loading...