Can CAS array include server in DR site

Hi, there:
Our current Exchange 2010 environment:
1): Two HUB/CAS Exchange 2010 server running on Windows 2008 R2 use NLB to form a CAS array.
2): Two Exchange 2010 Mailbox server with one DAG.
Please note all of these Exchange 2010 servers are on our datacenter, now we would like to add the DR capability to our Exchange environment.
In regards to the CAS array design for the DR site, is it possible to add one HUB/CAS Exchange 2010 to current CAS/HUB array (this server need to be on SR site), this way when the two HUB/CAS server on the datacentre is not available user can still connect
the HUB/CAS server on the DR site?
If the subnet for the Datacentre and DR site is different is this possible?
If the subnet for the datacenter and DR site is the same is this possible?

Hi,
Firstly, I’d like to explain, CAS array’s members cannot be located in different sites. If all CAS servers are in the same site, CAS array can load balance MAPI request.
And if all mailbox severs are in the same site, DAG can apply failover while it may apply switchover if they are in different sites:
http://technet.microsoft.com/en-us/library/dd298067(v=exchg.141).aspx
A failover is an automatic activation process that can occur at either the database or server level. Switchover is manual activation process.
If you have any question, please feel free to let me know.
Thanks,
Angela Shi
TechNet Community Support

Similar Messages

  • Outlook Profile Not Updated to New CAS Array After Mailbox Move Between Sites

    I am working on a large mailbox migration from one AD site to another. 
    Exchange version at both sites:Exchange 2010 SP2
    Two Mailbox Servers: MBX01 in site A / MBX02 in site B
    (There is a DAG but keeping this simple)
    Two CAS Arrays: CASA.domain.com / CASB.domain.com
    The RPCClientAccessServer property is set accordingly.  Where MBX01 is set to CASA.domain.com and MBX02 is set to CASB.domain.com
    Clients:Outlook 2010 SP1
    Scenario: I successfully move a mailbox from Site A to Site B.  The Outlook client does not automatically update its server settings to point to the new cas array (CASB.domain.com) and continues to connect to the old CAS server (CASA.domain.com).
    I have seen a few articles regarding this pointing to workarounds such as:
    - repairing the outlook profile on the client
    - delete the existing outlook profile
    - run a script to update the prf file (re-cache's email at the client)
    I am interested in knowing if anyone else has experienced this, what their solution was for a large migration and if any roll-ups or service packs have possibly fixed this problem.
    I would also like to know if you have seen this affect ActiveSync devices.  I am getting mixed results in my tests and thought it may be contributed toward different device types, mobile os versions, etc...
    I have posted this to the Outlook forum as well, just wasn't sure where to start.
    Thanks.
    Mike

    Hi,
    Firstly, I’d like to say, in Exchange 2010 and prior to SP2 CU3 version,
    when we move mailboxes between AD sites, users will not receive any notice about restarting Outlook and their RPC endpoint won’t update to reflect the RPC Client Access Server array associated with the mailbox database in the AD site where the mailbox now resides.
    Depending on repairing or recreating profile, we can force Outlook to use the new RPC endpoint.
    If you have any question, please feel free to let me know.
    Thanks,
    Angela Shi
    TechNet Community Support

  • Can't find the server for a site, multiple browsers, multiple computers

    In recent weeks, possibly coinciding with updates in Firefox (running 3.6.10), Safari (5.0.2) and iTunes (10.0.1), I have only received the prompt, "can't find server" when attempting to connect to the site kcrw.com. Others can get it on their computers in other places, and my iPhone can access when on 3G, but our network here seems affected because all the computers [All macs, some laptops and some desktops, running on OS 10.5.8] here receive this message. I used to be able to go to this site, a radio station, and stream audio or download podcasts. My ISP ran a ping test to the site's server and said that went through, but the browsers and iTunes don't seem to be able to make the transformation to anything I can read. What kind of a problem is this? Apple care was no help either.

    HI Alice,
    From your Safari menu bar click Safari / Preferences then select the Advanced tab. Now click: Change Settings. That will prompted your System Preferences / Network pane. Make sure the Proxies tab is selected.
    If any of the boxes are checked under: Select a protocol to configure.
    That could be a factor. If there are, deselect, then click the OK button.
    Quit Safari. Relaunch Safari and see if that made a difference.
    If it's not a proxy issue, go to a website. If you see the "can't find the server" try reloading the page.
    Command + R
    Also, try Open DNS - Free / Basic . Includes anti phishing filters.
    And help here to manually add DNS. Topic : Manually provided DNS server addresses are higher priority than DHCP's
    Carolyn

  • Firefox keeps saying can't connect to server for every site but internet explorer can

    I was using firefox before and it worked fine. But then yesterday firefox updated itself and since then it wouldn't work. its not the firwall, not a proxey problem, I had uninstalled it and reinstalled it but that didn't work either. Internet explorer still works and so does the wireless for the laptop but just for my desktop firefox doesn't work. Now everytime I open firefox or try any other site it says "can't connect to the server at ..." what do I do.

    Did you check your security software (firewall)?
    A possible cause is security software (firewall) that blocks or restricts Firefox or the plugin-container process without informing you, possibly after detecting changes (update) to the Firefox program.
    Remove all rules for Firefox from the permissions list in the firewall and let your firewall ask again for permission to get full unrestricted access to internet for Firefox and the plugin-container process.
    See:
    * [[Server not found]]
    * [[Firewalls]]

  • Can't access FTP server OR the SITE!

    I installed dreamweaver and succesfully mapped it to my FTP server. I was in the middle of a sync between my remote and local folders when the connection was dropped! It would not reconnect, I found out a few minutes later that I could not even access the web page itself, or the hosting server, of the ftp directory. NOTHING! However, my roommate can access all of the fine from his PC. I am a new MAC user and was wondering if there was some bandwidth limit I have exceeded or something. I turned the firewall off and everything! AHHH. I'm losing my mind here. Someone pleasse tell how to fix this.

    Problem solved. The issue was the FTP Client I was using *****. It opened over 50 simultaneous connections with the server and the server firewall blocked my IP.

  • Safari can't connect to server

    Hi, I'm encountering an error when I try to access specific sites. Safari tells me "Safari can't connect to server". Some sites work fine and for others (that I was previously able to visit) it tells me Safari can't connect to the server. These same websites I'm also not able to open with FireFox (so I don't think it's Safari related). A previous post suggested checking if i had any proxies selected, which I don't. Any suggestions? Thanks in advance.

    Hi again Vera
    I also created another account on this machine and the same page were also not able to load there.
    Thanks for trying, the other account as I recommended.
    Same results indicates a system wide issue. Check your router, with the update of the os 10.4.8, the firmware updates for said items are lagging behind.
    It would work on your other machine because it does not run the same os.
    Please note that this is for a firmware updates for routers
    not your Mac, as otherwise suggested by Hope.
    Here are three popular routers,
    Airport Firmware updates
    Linksys FirmWare
    Netgear
    Your feedback would be appreciated.Thanx
    Eme;~[)

  • TCP packet out of state: First packet isn't SYN & Outlook is trying to retrieve data from the Microsoft Exchange Server [CAS-ARray]

    We are transitioning from Exchange 2003 to Exchange 2010.  We found Outlook online mode (non-cached mode) have many warning "Outlook is trying to retrieve data from the Microsoft Exchange Server [CAS-ARray]", usually happen when users tried to open
    address book but sometimes even normal operation like click the Send button.  The problem does not affect OWA and extremely rare when Outlook is running in cached mode.  Check the firewall logs, we notice a lot of "TCP Packet Out of State" drops.
    We have a lot from the CAS/HT to DC/GC on TCP_3268 and LDAP.  And the errors are "TCP packet out of state: First packet isn't SYN" with tcp_flags FIN-ACK, PUSH-ACK.
    We also have a lot from CAS/HT to the Outlook Clients on the static RPC port (TCP_59933).   And the errors are "TCP packet out of state: First packet isn't SYN" with tcp_flags FIN-ACK, PUSH-ACK and RST-ACK, ACK.
    This happens even on Outlook 2010 which I though it has TCP Keep Alive implmented to keep the session active within 1 hour. 
    Can somebody tell me if these out-of-state are the cause of our problem?  And how to fix it?
    THANK 1,000,000

    Hello AndyHWC,
    I did some consulting with our CAS team and received the following feedback to your post:
    It is difficult to determine what is causing resets without seeing the captures first hand however, the concern is that you are seeing dropped packets on the firewall logs.  Where is this firewall located?
    Based on the description "Check the firewall logs, we notice a lot of "TCP Packet Out of State" drops." and "We have a lot from the CAS/HT to DC/GC on TCP_3268 and
    LDAP." indicates to me that the firewall is between CAS and GC.  This not supported under any circumstances and would explain the issue they are seeing with clients trying to "retrieve data from the GC".
    If there is not a firewall between the GC and CAS then a Microsoft support engineer would need to have concurrent Netmon Captures from client, CAS, GC during the
    issue to analyze.  If only one GC exists consider adding another GC to handle the client requests and for fault tolerance.
    Also verify that all NIC card drivers are updated to the latest driver version
    More information about firewalls with Exchange 2007/2010
    http://msexchangeteam.com/archive/2009/10/21/452929.aspx
    http://technet.microsoft.com/en-us/library/bb232184(EXCHG.80).aspx
    You can install the Client Access server role on an Exchange 2007 computer that is running any other server roles except for the Edge Transport server role. You
    cannot install the Client Access server role on a computer that is installed in a cluster. Installation of a Client Access server in a perimeter network is not supported.
    http://technet.microsoft.com/en-us/library/dd577077(EXCHG.80).aspx
    “The Installation of a Client Access Server in a Perimeter Network Is Not Supported
    Issue You may want to install an Exchange 2007 Client Access server in a perimeter network. However, this type of installation is not supported in Exchange
    2007.
    Cause The Exchange 2007 Client Access server role is not supported in any configuration in which a firewall is located between the Client Access server
    and a Mailbox server or a domain controller. This includes firewall devices, firewall programs, or any program or device that is designed to restrict traffic between two network locations.
    For correct operation, Client Access servers require typical domain connectivity to domain controllers and global catalog servers. Because any devices
    or programs that restrict or reduce access to domain controllers or global catalog servers may affect the correct operation of the Client Access server, we do not support this type of configuration.
    Resolution To resolve this issue, move the Client Access servers to the internal network. For more information about the ports that Exchange 2007 uses
    for various services, see Data Path Security Reference.”
    Thanks,
    Kevin Ca - MSFT
    Kevin Ca - MSFT

  • Outlook lost connection when load balanced CAS array name was moved to different AD site and data centre

    At the weekend our F5 load balanced CAS array name was moved to our 3rd datacentre and all users lost access to Outlook.  The databases were running on DAG2 listed below at the time.
    We have 3 DAG servers configured as the following:
    DAG SERVER ONE (DAG1) | Datacentre 1 | Primary AD Site | Multi role server MBX, CAS, HT
    DAG SERVER TWO (DAG2)  | Datacentre 2 | Primary AD Site | Multi role server MBX, CAS, HT
    DAG SERVER THREE (DAG3) | Datacentre 3 | Secondary AD Site | Multi role server MBX, CAS, HT
    We primarlily run from DAG1 or DAG2 - DAG3 is for real DR and loss of Datacentre 1 and 2.  The CAS array "Outlook" is configured for the primary AD site load balanced across DAG1 and DAG2.
    We use an F5 load balancer that balances the connections across DAG1 and DAG2, if both fail then DAG3 is used automatically.   We have tested and it works fine simulating loosing DAG1 and DAG2 and bringing up as a 1 node cluster on DAG3 with a
    FSW and the load balancer pointing at DAG3 for Outlook connections.
    For some reason this stopped Outlook users connecting - can anyone advise me why as I have been asked to test this again and I was expecting it to work?

    Hi,
    As far as I know, For Exchange 2010 before SP2 RU3,the Outlook clients with an existing Outlook profile would continue to use the old RPC endpoint rather than the new RPC endpoint (even though Autodiscover detected the change). Thus, except with Andy's suggestion,
    I recommend you can also repair or recreate the Outlook profile to have a test.
    For more information, you can refer to the following article:
    http://blogs.technet.com/b/aljackie/archive/2013/11/14/outlook-rpc-end-point-and-pf-the-microsoft-exchange-administrator-has-made-a-change-that-requires-you-quit-and-restart-outlook.aspx
    Thanks,
    Angela Shi
    TechNet Community Support

  • CAS Array and DAG Site Resiliency (2 Remote Sites via Point to Point Protocol)

    Hi, we are planning to deploy Exchange HA and Site Resiliency but i had some troubles understanding some concepts.
    Out current configurations settings:
    Datacenter A:
    1 MB/CAS/HT (MB01)
    1 CAS (CAS01)
    1 Point to Point link between Datacenter A and Datacenter B (We create a VLAN in the remote datacenter pointing to the Active Directory site where our Exchange server is).
    1 Active Directory Site with 2 Domain controllers (with VLAN 192.1.3.x in Datacenter A and VLAN 192.1.20.x in Datacenter B)
    Datacenter B:
    We want to install a new Exchange CAS Server (CAS02) in VLAN 192.1.20.x, is it posible to create a CAS Array with this configuration considering the replication network for the cluster in the MS Windows Server NLB, so that our Virtual IP of the cluster points
    to 192.1.3.x VLAN? What are the network considerations to the replication and MAPI network between VLANs? Does we need some third party NLB or this could be achieved with MWS2008R2?
    Same configuration for the DAG, with a new server (MB02) just for the MB role. The idea is to remove the CAS role from MB01 and have 2 Exchange Mailbox servers members of the DAG and 2 Exchange CAS Servers members of the CAS Array, so in case of a disaster
    in Datacenter A our clients automatically failover to Datacenter B in this case all of our clients will be pointing to the CAS Array in their Outlook.
    Hope you can help me with this, i don't know if this is possible with our actual infraestructure.
    Best Regards,
    Gerardo

    Thanks Ed, 
    So in that case we will need at least 4 servers in Datacenter A (2 MB members of DAG and 2 CAS/HUB members of the CAS Array) to get a decent HA solution, Am I correct?
    What about the other server in Datacenter B for DR, it will be a passive node or just another multirole server. So in case of DR (Let's say our Datacenter A is totally wrecked) I will need to switchover manually with my DB backups and switchover the user
    mailbox and outlook clients to point to the DR server? I didn´t get the point of the DR server in Datacenter B, can you explain a little bit more?
    I'm totally agree with you about the false positive failovers because our network doesn't meet that requeriments at all.
    Hope you can help me to clear my mind.
    Best Regards,
    Gerardo

  • Using new computer, existing mailbox user Outlook 2010 Auto-configuration points to the Mailbox Server rather than CAS Array ?

    People,
    I'm having a problem with the current AD user account & mailbox user where they cannot get the Outlook 2010 automatically configured to point into the CAS array ?
    This is happening when the existing user get new computer replaced or login to the Terminal Server where their account never set before, it always points to the Mailbox Server instead of the Client Access Server array virtual name. 
    The work around that I provided is typing the Client Access Array address and then specify Outlook.domain.com to match the Windows NLB name (and Get-ClientAccessArray result).
    Single AD Domain forest
    AD Site DataCenter contains:
    Domain Controllers: PRODDC01-VM, PRODDC02-VM, PRODDC03-VM
    Exchange Server 2010 SP3 - CAS&HT: PRODMAIL01-VM and PRODMAIL01-VM (Configured with WNLB as outlook.domain.com)
    Exchange Server 2010 SP3 - Mailbox: PRODMAILBOX01-VM and PRODMAILBOX01-VM (no DAG is set)
    Terminal Server (RDSH 2008 R2): PRODTS01-VM ... PRODTS60-VM (when user logged in to new TS, it got the same error).
    AD Site HQ contains - This site has no issue:
    Domain Controllers: HQDC01 and HQDC02
    Workstations using Outlook 2010 and 2013
    AD Site SiteOffice1 contains - This site has problem:
    Domain Controllers: none but the majority of the workstations LOGONSERVER is pointing to PRODDC03-VM
    Workstations using Outlook 2010 and 2013
    All of the Exchange environment here is using Exchange Server 2010 SP3 for all server roles.
    Any help would be greatly appreciated.
    Thanks
    /* Server Support Specialist */

    Hi,
    Yes, the RPCClientAccessServer should point to the CAS array. What's more, I would like to clarify the following things:
    1. Run the Get-ClientAccessServer | fl AutoDiscoverServiceInternalUri cmdlet to make sure that it displays the correct Uri.
    2. Run the Get-WebServicesVirtualDirectory | fl Identity,*auth*,*URL to ensure that URL for EWS points to the CAS array.
    Hope this can be helpful to you.
    Best regards,
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected].
    Amy Wang
    TechNet Community Support
    Here's the result:
    [PS] C:\>Get-ClientAccessServer | fl AutoDiscoverServiceInternalUri
    AutoDiscoverServiceInternalUri : https://PRODMAIL02-VM.domain.com/Autodiscover/Autodiscover.xml
    AutoDiscoverServiceInternalUri : https://PRODMAIL01-VM.domain.com/Autodiscover/Autodiscover.xml
    [PS] C:\>Get-WebServicesVirtualDirectory | fl Identity,*auth*,*URL
    Identity : PRODMAIL01-VM\EWS (Default Web Site)
    CertificateAuthentication :
    InternalAuthenticationMethods : {Ntlm, WindowsIntegrated, WSSecurity}
    ExternalAuthenticationMethods : {Ntlm, WindowsIntegrated, WSSecurity}
    LiveIdSpNegoAuthentication : False
    WSSecurityAuthentication : True
    LiveIdBasicAuthentication : False
    BasicAuthentication : False
    DigestAuthentication : False
    WindowsAuthentication : True
    InternalNLBBypassUrl : https://PRODMAIL01-VM.domain.com/ews/exchange.asmx
    InternalUrl : https://PRODMAIL01-VM.domain.com/EWS/Exchange.asmx
    ExternalUrl : https://email.domain.com/ews/exchange.asmx
    Identity : PRODMAIL02-VM\EWS (Default Web Site)
    CertificateAuthentication :
    InternalAuthenticationMethods : {Ntlm, WindowsIntegrated, WSSecurity}
    ExternalAuthenticationMethods : {Ntlm, WindowsIntegrated, WSSecurity}
    LiveIdSpNegoAuthentication : False
    WSSecurityAuthentication : True
    LiveIdBasicAuthentication : False
    BasicAuthentication : False
    DigestAuthentication : False
    WindowsAuthentication : True
    InternalNLBBypassUrl : https://PRODMAIL02-VM.domain.com/ews/exchange.asmx
    InternalUrl : https://PRODMAIL02-VM.domain.com/EWS/Exchange.asmx
    ExternalUrl : https://email.domain.com/ews/exchange.asmx
    The IP address of email.domain.com and outlook.domain.com are the same IP address, this IP address is servec by WNLB.
    /* Server Support Specialist */

  • Do i need a CAS server per AD site?

    Hi!
    So I have been browsing through a lot of Exchange Server documentation, guides and best practice but I have not found (or misunderstanding) the CAS placement for my situation.
    We are currently in the process of upgrading to Exchange server 2013. As we have an Exchange 2003 only deployment, we will first need to move to Exchange 2010 and get rid of all the Exchange 2003 servers and then move on to Exchange 2013. We have a
    single domain with 21 AD sites. 8 of these sites (Vessels at Sea) are connected by vSat the other 13 of these sites a remote offices with a more stable connection than vSat.
    We want to have a MBX server at every site and what I get from the available documentation on the internet I will also need a HUB server per AD site. What I am not sure about is, do I also need a CAS server per site? What I get from this excerpt:
    "A new service was introduced with Exchange Server 2010 to allow these MAPI connections to be handled by the Client Access
    server. The RPC Client Access service provides data access through a single, common path of the Client Access server, with the exception of public folder requests, which are still made directly to the Mailbox server. This change applies business logic to clients
    more consistently, and provides a better client experience when failover occurs." (ref Understanding RPC Client Access.), is that I also
    need a CAS server per site.
    Can somebody give me any definite insights in this one?
    To summarize the question:
    In a multi site AD with a MBX server per site, do I also need a CAS server per site?
    Your help is much appreciated!
    Regards,
    Erik

    (for Exchange 2010) You need CAS and Hub role in each site where Mailbox role deployed
    Understanding Client Access
    "You must install the Client Access server role in every Exchange organization and every Active Directory site that has the Mailbox server role installed"
    Overview of the Hub Transport Server Role
    "You must deploy a Hub Transport server role in each Active Directory site that contains a Mailbox server role"
    Blog - Smtp25.ru

  • One User has wrong Exchagne Server Settings in Outlook, showing Exchange Server Name Instead of CAS Array Name.

    I have one users Outlook settings that is showing the name of the Exchange CAS server instead of the CAS Array Name.   Other users seem to be fine.  I have tried recreating profile and doing an automatic and manual install.  Can
    X500 or X400 addresses have anything to do with it?

    Hi monolithickernal,
    As brenle said, could you please tell us what version of Exchange you are using?
    And you could use following command to check the database configuration parameters.
    Get-MailboxDatabase | Select Name,RpcClientAccessServer
    Best regards,
    Eric

  • CAS Array created but Outlook 2007 still points to first CAS Server

    Hi All,
    I just created a DAG between two servers and CAS Array between two other servers.
    DAG:-       EX01 -Mailbox, CAS,HT (First Exchange Server)
                    EX02-Mailbox
    CAS Array:     CA-HT01 (CAS & HT Role)
                          CA-HT02 (CAS & HT Role)
    I created CAS Array and assigned an FQDN for that array but It does not get changed in outlook 2007 it still uses old server EX01.So when I am shutting down server ex01 for testing all outlook 2007 client
    get disconnected.
    Does this required to change profile for all outlook 2007 users? I am more than 1600 users I am not sure how many users using outlook 2007.
    Please guide.I already configure Autodiscover service as it is suggested somewhere online but no luck.
    Thanks

    Mike,
    I tried with shutdown original RPCCLientAccessServer for two days but still that old value did not
    chnaged to new one.Can you guide me what is the exact method of creating Autodiscover so that outlook 2007 will point to new RPCCLientAccessServe value when
    existing is down/not accessible.
    Thanks
    If the  RPCCLientClientAccess Server referenced in the Outlook profile is not accessible, then Outlook should have found the new one at some point or failed to connect to Exchange entirely. Are you saying the Outlook clients continue to connect to Exchange
    even though the server defined in Outlook was not accessible? 
    If you close and re-open Outlook does it show the new RPCCLientAccessServer value in the profile?
    Twitter!: Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

  • I downloaded Lion OSX and at the end I received a notice that Safari can not connect to Server. All internet connections work including Safari on other user on same computer. I downloaded 13items and installed only 12. What do I do now ?

    I dowloaded Lion OSX and installed. I downloaded 13 iitems and installed only 12. At the end of the insta;;ation I received a notice thst Safart can not connect to Server. Safari does not work on user where installation was made. It work on other user. All internet connections work including google. If I go into Safari the blue line goes up to end of "http" on adress and freezes. Where do I go from here.:::???

    Hi There Linc Davis,
    Wow, you are the best.
    Yip this is what the website looks like. Great job Linc Davis.
    Not surprised that the "Shop" tab is missing. Darn.
    Well can you try to access it's "sister" website: astralmusic.com and astralmusicshop.com?
    Since you are awesome with the "Flash" can you investigate if this website has a issue withis this "Flash" too?
    Please Linc Davis

  • Safari has stopped opening certain webpages and says can't connect to server... This started 3 months ago with FB and now randomly with another site... all other sites are fine.. Help?

    Safari has stopped opening certain webpages and says can't connect to server... This started 3 months ago with FB and now randomly with another site... all other sites are fine.. Help?
    I've tried resetting safari, deleting all webpage data and setting time/date to automatic, but no such luck.
    The message that comes up is: "Safari can't establish a secure connection to the server 'Facebook' "
    I'd be genuinely impressed if anyone were to actually work out what was wrong.

    Hi ..
    Might be a cookies, cache, or extensions issue.
    From your Safari menu bar click Safari > Preferences then select the Privacy tab.
    Click:  Remove All Website Data
    Then delete the cache.
    Open a Finder window. From the Finder menu bar click Go > Go to Folder
    Type or copy paste the following
    ~/Library/Caches/com.apple.Safari/Cache.db
    Click Go then move the Cache.db file to the Trash.
    Quit and relaunch Safari to test.
    If that doesn't help, troubleshoot Safari extensions.
    From the Safari menu bar click Safari > Preferences then select the Extensions tab. Turn that OFF, quit and relaunch Safari to test.
    If that helped, turn one extension on then quit and relaunch Safari to test until you find the incompatible extension then click uninstall.

Maybe you are looking for