Buscar este blog

Mostrando entradas con la etiqueta 2012. Mostrar todas las entradas
Mostrando entradas con la etiqueta 2012. Mostrar todas las entradas

domingo, 4 de agosto de 2013

Install Exchange 2013 on Windows Server 2012

The following section describes a step-by-step guide for the installation of Microsoft® Exchange Server 2013 Preview. The installation considers a single server deployment of Exchange Server 2013 with the Mailbox and Client Access Server roles collocated. Additional details of the topology and architecture of the lab environment which was used in the installation is described here;
Active Directory Domain Controller
Operating SystemWindows Server 2012
Forest Functional LevelWindows Server 2012
Domain Functional LevelWindows Server 2012
Exchange Server 2013
Operating SystemWindows Server 2012
Associated Server RolesMailbox Server Role
Client Access Server Role

1  Operating System Support for Exchange Server 2013 Preview

For a successful Exchange server 2013 preview installation, the following list of supported operating systems should be considered;
ComponentOperating System
Mailbox and/or Client Access Server RoleWindows Server 2012
Windows Server 2008 R2 Standard or Enterprise with Service Pack 1
Windows Server 2008 R2 Datacenter RTM or later
Management ToolsWindows Server 2012
Windows Server 2008 R2 Standard/Enterprise with SP1
Windows Server 2008 R2 Datacenter RTM or leter
Windows 8 Release preview 64-bit edition
Windows 7 64-bit edition with SP1

2  Active Directory Preparation

The first task in the installation of any version of Exchange is to prepare the Active Directory environment where the Exchange Server will be placed.
However, prior to the preparation, it should be checked against the following Network and Directory Server requirements;
ComponentOperating System
The schema master must be running any of the following:Windows Server 2012
Windows Server 2008 R2 Standard/Enterprise
Windows Server 2008 Standard/Enterprise (32-bit or 64-bit)
Windows Server 2003 Standard Edition with Service Pack 2 (SP2) or later (32-bit or 64-bit)
Windows Server 2003 Enterprise Edition with SP2 or later (32-bit or 64-bit)
Each Active Directory site should have at least one global catalog server running any of the following:Windows Server 2012
Windows Server 2008 R2 Standard or Enterprise
Windows Server 2008 Standard or Enterprise (32-bit or 64-bit)
Windows Server 2008 R2 Datacenter RTM or leter
Windows Server 2008 Standard/Enterprise (32-bit or 64-bit)
Windows Server 2008 Datacenter RTM or later
Active Directory forestWindows Server 2003 forest functionality mode or higher
Once the above requirements are verified for consistency, proceed with the following preparation tasks on the server/computer which will be used to prepare the Active Directory using the Exchange Server 2013 Preview Active Directory Prepare module.
Please note that .Net Framework 4.5 and Windows Management Framework 3.0 are already included and is not required for download or installed with Windows Server 2012 therefore skipping steps 1 and 2.
  1. Download and Install Microsoft .Net Framework 4.5
  2. Download and Install Windows Management Framework 3.0
  3. Open a Windows PowerShell session by navigating to Start > All Programs > Accessories > Windows PowerShell and enter the following command;
Install-WindowsFeature RSAT-ADDS

3 Exchange Server 2013 preview Server role prerequisite installation.

The prerequisites for Exchange 2013 preview varies on the facts of the Exchange host server operating system as well as the server role which will be associated with it. The section describes the installation of Exchange 2013 on a server containing Windows Server 2012 Operating System.

3.1 Windows Server 2012 prerequisites for Mailbox Server Role

The following section instructs the prerequisite installation that should be performed in a server running a standalone Exchange 2013 server with the Mailbox Server Role.
  1. Open a Windows PowerShell session by navigating to Start > All Programs > Accessories > Windows PowerShell.
  2. Run the following command to install the required Windows components.
Install-WindowsFeature AS-HTTP-Activation, Desktop-Experience, NET-Framework-45-Features, RPC-over-HTTP-proxy, RSAT-Clustering, Web-Mgmt-Console, WAS-Process-Model, Web-Asp-Net45, Web-Basic-Auth, Web-Client-Auth, Web-Digest-Auth, Web-Dir-Browsing, Web-Dyn-Compression, Web-Http-Errors, Web-Http-Logging, Web-Http-Redirect, Web-Http-Tracing, Web-ISAPI-Ext, Web-ISAPI-Filter, Web-Lgcy-Mgmt-Console, Web-Metabase, Web-Mgmt-Console, Web-Mgmt-Service, Web-Net-Ext45, Web-Request-Monitor, Web-Server, Web-Stat-Compression, Web-Static-Content, Web-Windows-Auth, Web-WMI, Windows-Identity-Foundation
  1. After installing the required server roles and features, Download and Install the Microsoft Unified Communications Managed API 4.0, Core Runtime 64-bit software.
  2. For Exchange Server 2013 preview, Microsoft Visual C++ 11 beta redistributable (x64) component should be removed from the system. To do that navigate to Control Panel > Program and Features.
  3. Select Visual C++ 11 Beta Redistributable (x64) – 11.0.50531 component from the program list and click Uninstall.
  4. In the Microsoft Visual C++ 11 Beta setup, click Uninstall.
  5. Click close once the uninstallation wizard completes.
  6. Download and Install the Microsoft Office 2010 Filter Pack 64 bit software.
  7. Download and Install the Microsoft Office 2010 Filter Pack SP1 64 bit.

3.2   Windows Server 2012 prerequisites for Client Access Server role

The following section instructs the prerequisite installation that should be performed in a server running a standalone Exchange 2013 server with the Client Access Server Role.
  1. Open a Windows PowerShell session by navigating to Start > All Programs > Accessories > Windows PowerShell.
  2. Run the following command to install the required Windows components.
Install-WindowsFeature AS-HTTP-Activation, Desktop-Experience, NET-Framework-45-Features, RPC-over-HTTP-proxy, RSAT-Clustering, Web-Mgmt-Console, WAS-Process-Model, Web-Asp-Net45, Web-Basic-Auth, Web-Client-Auth, Web-Digest-Auth, Web-Dir-Browsing, Web-Dyn-Compression, Web-Http-Errors, Web-Http-Logging, Web-Http-Redirect, Web-Http-Tracing, Web-ISAPI-Ext, Web-ISAPI-Filter, Web-Lgcy-Mgmt-Console, Web-Metabase, Web-Mgmt-Console, Web-Mgmt-Service, Web-Net-Ext45, Web-Request-Monitor, Web-Server, Web-Stat-Compression, Web-Static-Content, Web-Windows-Auth, Web-WMI, Windows-Identity-Foundation
  1. After installing the required server roles and features, Download and Install the Microsoft Unified Communications Managed API 4.0, Core Runtime 64-bit software.

3.3    Windows Server 2012 prerequisites for standalone Mailbox Server Role or Mailbox and Client Access Server role

The following section instructs the prerequisite installation that should be performed in a server running a standalone Exchange 2013 server with either a standalone installation of the Mailbox Server Role or a server that will host both the Mailbox and Client Access Server Role collocated.
  1. Open a Windows PowerShell session by navigating to Start > All Programs > Accessories > Windows PowerShell.
  2. Run the following command to install the required Windows components.
Install-WindowsFeature AS-HTTP-Activation, Desktop-Experience, NET-Framework-45-Features, RPC-over-HTTP-proxy, 
RSAT-Clustering, Web-Mgmt-Console, WAS-Process-Model, Web-Asp-Net45, Web-Basic-Auth, Web-Client-Auth, Web-Digest-Auth, 
Web-Dir-Browsing, Web-Dyn-Compression, Web-Http-Errors, Web-Http-Logging, Web-Http-Redirect, Web-Http-Tracing, 
Web-ISAPI-Ext, Web-ISAPI-Filter, Web-Lgcy-Mgmt-Console, Web-Metabase, Web-Mgmt-Console, Web-Mgmt-Service, Web-Net-Ext45, 
Web-Request-Monitor, Web-Server, Web-Stat-Compression, Web-Static-Content, Web-Windows-Auth, Web-WMI, Windows-Identity-Foundation
  1. After installing the required server roles and features, Download and Install the Microsoft Unified Communications Managed API 4.0, Core Runtime 64-bit software.
  2. For Exchange Server 2013 preview, Microsoft Visual C++ 11 beta redistributable (x64) component should be removed from the system. To do that navigate to Control Panel > Program and Features.
  3. Select Visual C++ 11 Beta Redistributable (x64) – 11.0.50531 component from the program list and click Uninstall.
  4. In the Microsoft Visual C++ 11 Beta setup, click Uninstall.
  5. Click close once the uninstallation wizard completes.
  6. Download and Install the Microsoft Office 2010 Filter Pack 64 bit software.
  7. Download and Install the Microsoft Office 2010 Filter Pack SP1 64 bit.

4  Prepare Active Directory and domains

To prepare the active Directory and the Domains for Exchange 2013, follow the following steps. To execute the commands, the commands should be run using the Schema Admins group and the Enterprise Admins group membership.
  1. Mount/Navigate to the Exchange Server 2013 Preview Installation Media
  2. Open up a Command Prompt session and type the following command followed by an ENTER.
setup /PrepareSchema /IAcceptExchangeServerLicenseTerms
  1. Once the execution completes, run the below command followed by an ENTER.
setup /PrepareAD /OrganizationName:<organization name>
/IAcceptExchangeServerLicenseTerms

5  Install Exchange Server 2013

If you’re installing the first Exchange 2013 Preview server in the organization, and the Active Directory preparation steps have not been performed, the account you use must have membership in the Enterprise Administrators group. If you haven’t previously prepared the Active Directory Schema, the account must also be a member of the Schema Admins group.
  1. Mount/Navigate to the Exchange Server 2013 Preview Installation Media.
  2. Start Exchange 2013 Preview Setup by double-clicking Setup.exe
  3. On the Check for Updates page, select whether you want Setup to connect to the Internet and download product and security updates for Exchange 2013 Preview and click Next.
  4. Once the setup is finished copying files on the Copying File page, click Next.
  5. The Introduction page gives additional guidance for the installation procedure. Review the content and Click next to continue.
  6. On the License Agreement page, review the terms. If you agree to the terms, select I accept the terms in the license agreement, and then click next.
  7. On the Error Reporting page, select whether you want to enable or disable the Exchange Error Reporting feature, and then click next.
  8. On the Checking Required Software page, wait for the Setup to verify for prerequisite software checking to finish. If any applications are listed, install them and then run Setup again. If all required software is found, click next to continue.
  9. On the Server Role Selection page, choose whether to install the Mailbox role, the Client Access role or both roles on the server. For this guide both server roles were installed.
  10. On the Installation Space and Location page, either accept the default installation location or click Browse to choose a new location with adequate storage space.
  11. One of the new features of Exchange 2013 preview is the Malware Protection. If installing the Mailbox role a Malware Protection Settings page will appear. Choose whether to enable or disable malware scanning and click Next.
  12. If installing the Client Access server role, on the Configure Client Access Server external domain page, choose an option to suite your deployment. If selecting ‘This Client Access server will be Internet-facing if the Client Access server you’re installing will be accessible from the Internet’. Enter a domain name to use to configure your Client Access servers. If not, keep the space blank and click Next to proceed.
  13. On the Customer Experience Improvement Program page, choose an appropriate option, and then click Next to proceed.
  14. On the Readiness Checks page, view the status to determine if the organization and server role prerequisite checks completed successfully.If unsuccessful, perform the required tasks and click Back, and Next to run the Readiness check again.If successful, click Next to proceed.
  15. The installation will be performed.
  16. Once the setup completes the installation, on the Completion page, click Complete.
  17. Restart the computer after Exchange 2013 Preview has completed.

6   Review Exchange Installation

Once all the above tasks are performed, proceed with the below steps to verify the installation using the Exchange 2013 Administrative Center and PowerShell.
One of the cool and new feature of of Exchange 2013 is the all new ‘Exchange Admin Center’. The Exchange Administration Center (EAC) is the web-based management console in Microsoft Exchange Server 2013 Preview that allows for ease of use and is optimized for on-premises, online, or hybrid Exchange deployments. The EAC replaces the Exchange Management Console (EMC) and the Exchange Control Panel (ECP), which were the two interfaces that were used to manage Exchange Server 2010.
To navigate to the Exchange Admin Center;
  1. Open the web browser.
  2. Navigate to the bellow URL.
    https://<fully qualified domain name (FQDN) of Client Access server>/ECP
  3. Enter your username and password in Domain\user name and Password and then click sign in.
  4. Review the tabs and sections in the new Admin Center.
Time to play! Hope this guide helped you. Don’t forget to keep on checking for some exiting new posts on how to play around with the all new Admin Center as well as a step by step guide for installing Lync Server 2013 preview in the next couple of days.

Windows Server 2012 Anywhere access

This guide will explain how to install and configure DirectAccess on a Windows Server 2012 behind a NAT router with one adapter. To keep this guide as simple as possible, I will not explain the different steps and why it must be like that. Simply follow the guide and you will have a working DirectAccess.

Prerequisites

If you are following this guide, you will need:
- A domain administrator. For this guide I am always logged in as a domain administrator.
- A domain controller
- A Remote Access server (also called DirectAccess)
- One public IP
- An external DNS record that points to your public IP. I used DynDNS.
- If behind a NAT device, forward port 443 from your public IP to the Remote Access server (internal IP)
DynDNS is free for two weeks, so give it a try. Edit: Someone mentioned freedns.afraid.org which is completely free, and is actually easier to use! Make a new account and click add a subnet!

Setup

All my servers are running Windows 2012, and all my clients are running Windows 8. This guide is for Windows 8 clients, and will be edited soon to support Windows 7 clients. I just want to see DirectAccess work! I do not have a PKI nor do I have a NLS (for those who have worked with DirectAccess before, you know what this is.)
I have one domain controller and one Remote Access server. That’s it. My domain is called syscomworld.local, and everything is behind a NAT router. The firewall is very strict here. Both servers are actually virtual machines running on the same physical machine. 

Installation

Open Server Manager and click add server roles. Scroll down to Remote Access and install it with the default settings.

Configuration

Before we configure Remote Access, we will have to do a couple of things:
- Make a security group in Active Directory. Mine is called DA_Klienter. Your client machine has to be a member of the domain and the security group.
- Make sure your firewall is correctly configured. Port 443 has to be open, and your external IP should be forwarded to your Remote Access server.
- Remove ISATAP from the global blocking list on the domaincontroller, you can do this by running this command
dnscmd /config /globalqueryblocklist wpad
Open Remote Access Management from the metro menu. In the console, click Run the Getting Started Wizard and choose deploy DirectAccess and VPN. Select behind a NAT device with a single adapter and type in your external DNS.


Let us start by configuring step 1. This guide will deploy full DirectAccess for clients and remote management.

 

Remove Domain Computers and add the security group you made earlier. Since my clients are virtual machines, I have to uncheck Enable DirectAccess for mobile computers only.
In this lab, I will not be setting up a helpdesk. Choose an appropriate name for DirectAccess, I went for SyscomVPN. This will show up on the clients when the user clicks on Network to log into a wireless network.

Move over to step two. Companies that looked into DirectAccess and decided not to implement it into their system probably did so because DirectAccess required a specific topology to work. Now we have three different choices, where I find behind an edge device (with a single adapter) the easiest one. Insert your external DNS (I do like pie) you made with DynDNS and click Next.
Certificates has become significally easier to handle (for windows 8 clients that is). I will bring up later on how to make this work for Windows 7 clients. Check the box Use a self-signed certificate created automatically by DirectAccess.
My clients will be logging in with their Active Directory credentials. If you look at the bottom, you will see where we need to check if we want Windows 7 clients to use this configuration. If I enable this, I will have to insert a certificate on the NLS, which I do not want to at this moment.

I will be deploying the NLS on the Remote Access server. However, the NLS should, and is recommended, be deployed on a different server. For now, check the mark the network location server is deployed on the Remote Access server. This will be using a self-signed certificate.
*Check comments for why you should install Network Location Server on a different server.
Click next until you finish the wizard.

If you do not want DirectAccess users to access certain servers, you can make a security group in AD that contains those servers you want them to be able to access. Since this is a lab environment, I just clicked Finish with the default settings.
Now we are done with all the steps, click Finish, which you will find at the bottom right hand side of the configuration page.
Review of all the settings we just configured. Click apply when done looking it over.
Open the Dashboard page and wait until you see green checkmarks popping up. You might have to click refresh now and then.

Test a Win8 client

If the client already is a member of the domain, logg out and back in again. The client will then configure itself to use DirectAccess because it says so in the GPO.
When logged in, open your desktop and check Available Networks. You should see an extra connection there, that’s your DirectAccess. I called mine for SyscomVPN (you change the name in Step 1).
My client is connected to the domain right now. When outside the domain, it will say Connected (or Connecting if it doesn’t work). You can get the logs if you right click it, so no need for DirectAccess Connectivity Assistant anymore.
I just used my cellphone to test if this worked.
If it is working, then you can test this by making a shared folder on one of the servers and see if you can access it outside the domain.

Windows Server 2012 setting up DNS and reverse DNS

In this guide, Im going to show you how to install DNS in its own dedicated server. Ideally, you would want to install DNS with your Domain Controller on the same server and configure another secondary DNS server, or configure another secondary Domain Controller with secondary DNS for redundancy.
Notes before installing DNS:
- Make sure you have a static IP. You should not install DNS on a dynamic IP (you should have all your servers configured as static IPs anyways)
- Your preferred DNS should be the server itself, either 127.0.0.1 or whatever your server IP address is.
- In this guide, we will only talk about installing DNS, there will be another guide detailing how to configure a secondary DNS server in Windows Server 2012 .
Launch your Server Manager if it is not already up
capture_02272013_095847
On your Dashboard, click on “Add roles and features”
capture_02272013_123216
You will get the “Add Roles and Features Wizard”, click Next
capture_02272013_123229
Select “Role-based or feature-based installation”, click Next
capture_02272013_123240
In “Select destination server” screen, most likely you will only see one selection, which is the server you are on, if not, select the server you want to add the DNS role to and click Next
capture_02272013_123250
Check the “DNS Server” box
capture_02272013_123307
A smaller window will launch to confirm that there are other features that needs to be installed with your DNS role, click on “Add Features” then click Next
capture_02272013_123312
You do not have to select anything in the “Select features” screen, click Next
capture_02272013_123327
In the “DNS Server” screen you can read what DNS is and what it does, but we already know that, read the “Things to note:” part, once done, click Next
capture_02272013_123333
Here we just have a confirmation of what we are installing and what features, click Install
capture_02272013_123344
You will see the installation progress, once done, click Close
capture_02272013_123413
Once the installation is done, DNS should be installed, you will also notice a new “DNS” tile in your Start screen.
capture_02272013_140425

Creating a Windows Server 2012 Failover Cluster

Creating a cluster on Windows Server 2012 is easy experience!
After installing the Failover Clustering feature, and validating a configuration, the next step is to create a new cluster. There are some minor changes in the create cluster experience in Windows Server 2012, but it is very similar to creating a cluster in Windows Server 2008 R2.
For details on installing the Failover Clustering feature, see this blog posting:http://blogs.msdn.com/b/clustering/archive/2012/04/06/10291601.aspx
To learn more about validation, see this TechNet article: http://technet.microsoft.com/en-us/library/cc731844(v=ws.10).aspx
You can create a cluster using the Failover Cluster Manager UI, or using PowerShell.  Both of these can be installed on Windows Server 2012 or Remote Server Administration Tools (RSAT) for Windows Server 2012.

Creating a Failover Cluster using Failover Cluster Manager

1. Open Failover Cluster Manager - it can be opened from Server Manager using the Tools menu:
2. In the Failover Cluster Manager, choose the “Create Cluster…” action, which can be found in 3 places:
3. The Create Cluster Wizard initializes. Review the information on the Before You Begin screen. Click Next
4. Enter the names of all the servers that will be part of the cluster. Note: More that none node can be specified at a time using comma separation.
Example: MyServer1, MyServer2, MyServer3
5. If the nodes specified have not been validated, the following page in the wizard will be shown.  It’s highly recommended to validate the configuration before you create the cluster.  This will help ensure that the servers are connected and configured correctly and that it can be supported by Microsoft:
6. In the “Cluster Name” field, provide a NetBIOS name to be used as the cluster name. This cluster name is also the name that can be used to connect to the cluster to manage it.  During cluster creation, a computer object will also be created in the Active Directory domain and Organizational Unit where the cluster nodes computer objects are located. If the servers have no NICs configured for DHCP, then this page will also prompt for a static IP address.  If any of the networks are configured for DHCP, then this will not be shown and an IPv4 DHCP assigned address will be used.   Click Next:
Note:  If you do not want the Active Directory object for the cluster to be placed in the same Organizational Unit (OU) as the servers, the specific OU can be designated by specifying the full distinguished name like screen shot below:
For additional details on using a full distinguished name, please see “How to Create a Cluster in a Restrictive Active Directory Environment” (http://blogs.msdn.com/b/clustering/archive/2012/03/30/10289577.aspx)
Review the Confirmation screen. If all eligible storage will be added to the cluster, check the box Add all eligible storage to the cluster.  Click Next
Note: This ability to choose whether all eligible storage will be added to the cluster or not is new for Windows Server 2012.  In previous versions all storage would always be added to the cluster.  If you choose not to add all eligible storage to the cluster, you can add specific disks after the cluster is created: 
7. The cluster should be successfully created. Review the Summary report if desired. Click Finish
8. A Failover Cluster Manager will automatically connect to the cluster when the wizard finishes:

Creating a Failover Cluster using PowerShell

An alternate way to create a Failover Cluster is to use PowerShell.  This can be accomplished with the New-Cluster PowerShell cmdlet.  The following command creates 2-Node cluster (Contoso-FC1) and it assumes that a DHCP assigned address can be assigned and all eligible storage is added.
 PowerShell:
 New-Cluster -Name Contoso-FC1 -Node Contoso-N1,Contoso-N2

The following command is an example of specifying a static IP address for cluster to use for its management connection, and if you don’t want any storage to be automatically added to the cluster.
 PowerShell:
 New-Cluster -Name Contoso-FC1 -Node Contoso-N1,Contoso-N2 –StaticAddress 10.0.0.14  -NoStorage

The following command is an example that would put the cluster account put into an existing Active Directory OU called “Clusters” that is in the Contoso.local domain.
 PowerShell:
 New-Cluster -Name CN=Contoso-FC1,OU=Clusters,DC=Contoso,DC=local -Node Contoso-N1,Contoso-N2