Forum Discussion
Andyhud0_5004
Sep 05, 2011Nimbostratus
2 Site Exchange 2010 CAS Array - Active/Active with GTM
Hi All
My first post so go easy on me.
I have a conundrum I can't get my head around and would appreciate any thoughts/advice
Simple put we have 2 BIGIP's with GTM. 1 in ...
Michael_Koyfma1
Sep 06, 2011Cirrus
Andy,
I am assuming you have those two DCs in two different AD sites - that's why you can't use CAS in US to send traffic directly to mailbox in Europe and vice versa.
We do have a solution for you, but that involves using another module - APM - Access Policy Manager. You can read up on how to setup APM in front of Exchange 2010 in our latest Exchange deployment guide available on f5.com/microsoft. That would be our Exchange remote access proxy setup - pretty much equivalent to Microsoft's own ISA/TMG.
The premise is that you will authenticate your users on F5 device, validate them, make access/loadbalancing decision, and then SSO them to the CAS.
So, the way it would work is that when the user hits either site - US or Europe - we will present them with your own FBA page(which you can customize to look a lot like OWA's own logon page), authenticate them, lookup which site their mailbox lives in(via AD query), and then send them to the right CAS pool based upon where their mailbox lives - problem solved!
This approach(user authentication, mailbox lookup, and then sending user to the proper CAS array) also works great in the migration scenario, and we've had customers implement it when migrating between different version of Exchange(2007->2010, 2003->2010, etc). while preserving a single internet-facing namespace for access(e.g. https://mail.contoso.com).
Let me know if you have any additional questions.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects