Exchange 2010 High Availability Webinar: Eliminating "Disaster" in Disaster Recovery
http://www.trainsignal.com/blog/webin...
This on-demand Microsoft Exchange webinar discusses how High Availability in Exchange 2010 environments is taking the "Disaster" out of Disaster Recovery. Exchange MVP J. Peter Bruzzese covers, DAG (database availability groups), hosted archive solutions, and answers questions from the live viewing audience.
-~-~~-~~~-~~-~-
This channel is an archive! Subscribe to Pluralsight for new IT Pro training
➨ https://www.youtube.com/user/Pluralsi...
-~-~~-~~~-~~-~-
Closed Caption:
hello and welcome to the exchange my
availability eliminating disaster and
disaster recovery webinar presented by J
Peter busy i'm kevin passion trainsignal
i'd like to take a minute to tell you
what to expect the next hour i like to
draw your attention to the questions box
in your webinar control panel heater
will be answering questions today so
please feel free to submit your
questions during the presentation also
if you have any technical difficulties
let us know in the questions box and
we'll do our best with today's
presentation will be recorded and
available to be on our blog will email
you the link after the presentation
after you exit the webinar you'll be
prompted to take a short survey
trainsignal wants to hear from you so
please take a few minutes to complete
the survey will also be choosing one
participant from today's audience
receive a copy of transit most exchange
server 2010 high-availability created by
JP too busy to be eligible to win you
must complete the survey you will
receive after the webinar be sure to
fill it out it only takes a few seconds
also if you have additional comments or
feedback you can email us at webinars
transitional dot-com and with that thank
you for joining us for today's webinar
now here's Peter greetings welcome
everyone
nice to be with everyone today the
subject that we're going to be talking
about is exchanged high-availability
eliminating disaster in disaster
recovery and it's going to be a little
bit different from perhaps an ordinary
discussion of high availability we're
going to be discussing more than just
high-availability itself but how it
works and how you can eliminate the
potential of utilizing the traditional
backup recovery tools that we've used
for years within your environment
without the fear of losing data so stay
tuned on that to start with let me tell
you a little bit about myself and then
I'd like to know a little bit about you
little bit about me my name is JP to
bruise easy
I'm a microsoft MVP for exchange and i
have a list of certifications that you
can see there on the screen
you know I i personally think that
certifications are a good way to provide
some type of proof that you know what
you're talking about
at the same time of course you need to
have some experience you need to have a
way of proving that you have the skills
and not just the cert so you know
obviously I think that certification is
important but you always need to
continue to refine what you know and
show that you have some real practical
world experience and sometimes you get
that through webinar like this because
you get an opportunity to hear about
different viewpoints now I'm a microsoft
certified trainer I'm a technical author
with over a dozen books that have been
sold internationally to my credit
I'm a technical speaker for conferences
like tech mentor tech add connections
and others my latest book actually I
don't have it listed here on the slide
but my latest book is called
conversational geek
it's a real fun book that deals with the
seven chapters that teach all the the
basics and fun things like where did the
operating system come from how does the
internet work fun things like that so
you can check out conversational
geek.com now from the exchange
perspective exchange is my passion
it really is it's something i've been
working with and teaching for 10-plus
years I've been an exchange instructor
for a variety of different training
agencies and private corporations and
with regard to disaster and dead
disaster recovery I was the CommVault
systems exchange disaster recovery
expert for quite a while and taught
agencies around the world how to recover
their exchange data that is one of the
reasons i'm so excited about utilizing
my availability in exchange to eliminate
the need for the traditional backup
recovery solutions because with my
experience I found that too only be a
frustration more than anything else
trying to go to those backup tapes back
in the day or backup media you know
whether it's on magnetic disk or
whatever and and having to get that data
there's gotta be a better way and so
that's what we're going to talk about
you can see a list of some of the other
things that I've been involved in with
regard to exchange but ultimately at
this point i'd really like to get to
know more about you
it helps to really narrow down my
understanding of the audience and then
that will gauge where I should go in the
discussion so let's just throw this
whole out there where are you from
alright people are starting to weigh in
all right let's close it out looks like
everybody pretty much
the chance to vote there and you can see
on your screens
I think you can see on your screens that
we have the majority coming from north
and south america but we do have some
joining us from Europe from Asia from
Africa that's great and then in terms of
your your specific environments
let's talk a little bit about your
environment here let's see which version
of exchange
danger you using there you go you should
be able to see that poll question
very good all right let's close that one
out
chair you can see that actually the
majority of those on the on the line
here are using exchange 2010 summer with
2007 and others are still using exchange
2003 very good
and then let's go to our last question
just a very simple one for those that
are using exchange 2010 are you using
dag in your environment
alright and you can you can see there
that it's 5050 almost many of you are
but a good deal of you or not that's
great so that gives me a chance now to
move along and start discussing where
we're at in terms of exchange itself our
agenda for today we're going to start
with comparing high availability to
aircraft we're going to talk about the
hadr crossroads where these two meet
then we'll discuss the high availability
focus . what high availability is all
about and then we'll talk about how dags
in exchange 2010 eliminate the disaster
in disaster recovery
alright very good let's uh let's start
with this comparison to aircraft this is
just a simple illustration to get us
started and get our minds in the right
place here because the one thing about
aircraft is if you're flying on a plane
the idea of redundancy resiliency and
all these other things hungry
the last thing you want is the final
part of the problem with a plane is the
word disaster being utilized you never
want disaster recovery when you're in a
plane right you don't mind if if there's
some type of redundancy your resiliency
so it's good to know that the wings and
the tail flexibility that there's
resiliency there it's good to know that
there are more than one engines on a
plane right because it's good to know
that obviously if one engine goes down
you still have another engine it's good
to know that in the event birds fly into
the engines that you're still good to go
or that there are three layers of
windows so that the windows don't break
all of that is really great you prove
you like knowing that there's some kind
of Brazilian city and as far as
redundancy you like knowing that there's
more than one pilot there's a pilot and
co-pilot you like knowing there's two
ways to lower landing gear that there
are multiple few lines and hydraulics
you know that you have if it's
fly-by-wire systems like they have with
the new boeing 787 that the system's
quadrupled therefore independent
channels so that makes you feel good
that there's all of this resiliency and
redundancy you prefer that to the word
recovery because when it comes to a
plane things fly along if there's a
disaster
that's not really it's it's typically
something that is is a major disaster so
the same is true when it comes to your
environment the last thing you want to
deal with is a disaster as far as the
crossroads of high availability and
disaster recovery I availability goes
beyond uptime of a server it's more
about being accessible to users ready to
work for example when it comes to
exchange knowing that your server is up
and running is not good to know the you
know this
servers out that's great but what if you
can't access your exchange services if
you can access your mailbox
well then just having uptime of the
server is not going to be what you need
instead you need to make sure that those
services are accessible so high
availability is all about keeping your
environment accessible while disaster
recovery is all about recovering your
environment should go down now you might
say well these two how do they meet they
seem like they're so different but you
know you want your systems to be as
available as possible unless the
unthinkable happens and the unthinkable
can be anything from a nuclear disaster
to as a major storm coming through to a
blackout you know that takes down all of
these service servers in your site you
know those are those are all disasters
that can prevent a user from accessing
their mailbox data so when that happens
you may still have high availability and
play it may still be part of your
solution but at some point if enough
things go wrong
much like a plane if enough things go
wrong you switch from having a
high-availability situation to a serious
situation that involves disaster
recovery now the to meet at some point
if you have planned properly they don't
have to necessarily be separated by
miles and miles of nothing in between
the value of using high availability to
mitigate disaster recovery is easy to
see when you consider your archeo and
your RPO let's talk about those terms
for a little bit because maybe they're
new to you
so our recovery time objective the fancy
definition is it's the duration of time
and a service level within a business
process within which a business process
must be restored after a disaster or
disruption in order to avoid
unacceptable consequences associated
with breaking in business continuity
ok that's the wikipedia fancy definition
the simple definition for RTO is the
acceptable time without service being
available now for some you would say
well no there is no acceptable time here
you know there if I don't want my
services ever being down but let's face
it some of you are listening and you're
thinking well you know that's what I
need I can't have even a second of
downtime
but others are listening and you're
realizing you look at your environment
and you say you know little downtime is
not going to kill anybody if it's at the
right time if it's you know a time when
no one's using the services or were not
really expecting people to have to
access their mail so depending on the
size of your environment the type of
environment is it is whether or not
their branch offices that go across
multiple time zones and so on
you may have circumstances where you
don't need one hundred percent of time
even though that's the that's the hype
these days though you have to have it up
24-7 ok but you know your environment
and you know whether or not that's
actually what you need
so the RTO is something to consider the
recovery point objective is the other
thing to consider now the fancy
definition from wikipedia is the maximum
tolerable . in which data might be lost
from an IT service due to a major
incident
ok the simple definition is how much
data past and present must be restorable
in the recovery point objective in the
recovery time objective so in other
words how much data do you need to get
back now again here's where the
extremists say i need all of the data we
want all of the data back alright that's
true
you know you want all of your data and
most likely if you have a variety of
different options in place you're not
going to lose your data but when you're
thinking about recovery time objective
in some cases you're so interested in
getting email services back up and
running that you don't really care about
the past data to start with and that's
where you start doing dealing with
things like dial tone recoveries and so
on because that's the fastest way to get
people back up and running get
themselves sending and receiving email
again and you'll worry about getting
their data restored and then merging it
back into their mailboxes you know when
you have the time and when you have the
ability so a lot of times it really does
come down to what your organization
needs so RTO and RP or very important
when we talk about redundancy resiliency
and recovery so the keys for making a
solution like exchange more highly
available include the following for
starters redundancy having more than one
server power supply site copy this is
all essential for redundancy resiliency
again in thinking about what we have
with them with our planes
it's the ability to keep working despite
a single or even multiple software or
hardware failures so we need to have
this in play with exchange and then of
course
look there's no there's no way I can
convince all of you
there's there's no way I can convince
all of you that recovery is is not
important
recovery is absolutely important so we
need to restore data from a backup
sometimes
sorry just lost volume there for a
moment somewhere in my room I had a
phone that went off and i had to throw
it out of my office so there you go
so the old view of disaster recovery in
the past cost is what prohibited most
organizations from pursuing alternatives
to disaster recovery so the host of
having the alternatives the high
availability alternatives the clustering
alternatives and so on
it's it was just so astronomical that
there is no way for most companies to be
able to provide this and so a disaster
and those times the disaster might be
something simple something like a disk
failure or a server failure back in the
day those were not considered simple
disasters those were those are major
things that this goes bad especially if
you didn't have a raid solution in play
and so there were all these different
tricks that we were trying to work with
like putting the database on one disc
that was a raid5 putting the transaction
logs on the mirrored set of disks and we
did whatever we could especially those
who are looking you know it costs as
being a big problem with server failures
we were really stuck because without
clustering involved you know there's
really not much that we could do and so
those are some of the simple disasters
that we dealt with and then of course
there were also the more complex ones
like fire and destruction you know so
when we think about disasters in the
past those those were some of the big
things but in terms of the modern view
of disaster again we're looking at big
things like nuclear or some kind of
power outage some kind of you know
Hurricane Katrina coming through and
knocking out our entire city
I mean these are very real possibilities
that affect millions and millions of
dollars worth of data and so in thinking
about that how to how do we resolve
those issues in modern times and how do
we look at it without having to worry
about the backup as our first line of
defense
so that's where high availability is a
real game-changer in exchange if your
data was available 24 7 365 it was
guaranteed would you need disaster
recovery
well you might say yes i still would and
my question back would be Y and so you
would probably say we'll look okay
especially those 50 of the fifty percent
out there that are already using dag in
your environment you're probably
thinking wait a minute meet the dad is
great for high availability for my
existing data my modern data data what's
happening right now today but if folks
have deleted things let's say they
deleted a few messages and you know you
have your your deleted item retention
set to 15 days or maybe even up to 30
days and those 30 days of past well look
i need to have some kind of a backup in
order to recover that data
no you don't why do I say that well
because modern times in modern times the
push has been toward having an archive
solution you need an archive solution
not just the backup recovery solution so
what is an archived solution do for you
well it provides you the ability first
of all to discover any of the data that
you have so if there's legal discovery
that needs to take place let's say
because you know there's some kind of
litigation that's going to take place
against your organization you are
prepared you have been compliant to the
direction you have an archive that goes
back over many years for your
environment and that means that that
data is there if it's a good archive
solution you can quickly reach out to in
fact you don't even have to reach out
for it if it's a good archive solution
the user should be able to reach out and
grab that email that they deleted from
last year if they want to
so that's the beauty of an archive
solution now i'm not here to sell you on
an archive solution i'm here to to
really convince you that you can use
high availability to eliminate disaster
inches in disaster recovery that you
don't have to go reaching for those
backup recovery you know files in order
to now restore your exchange but you
have to at least make the the mental
jump toward high-availability with an
archive solution in order for that to
happen now
the technology has existed for a long
time for high availability as well as
for archiving but the price tag was the
wall between us
exchange 2003 had a shared storage
solution with clustering to provide some
high availability it was called a single
copy cluster or SCC in exchange 2007 and
now we look at exchange 2007 and then
2010 and again some of you are still
working with with 2003 but unfortunately
the new the new methodology to provide
high availability is just not in 2003 so
this is more of a reason than ever to
move toward exchange 2010 some of you
may be asking the questions I haven't
looked at the questions yet but some of
you may be wondering will look upon
exchange 2003 should i wait for the next
flavor of exchange which was when that's
going to be released but let's just
assume it's going to be released at some
point in the in the near future
six months a year who knows should i
wait well the honest truth is you're
waiting for something that's already
available to us in exchange 2010 if your
biggest concern is high availability
you've got those features right there so
you might want to move to 2010 and then
certainly if the next flavor of exchange
is something that you're interested in
then you can certainly consider moving
to that one at some other point in the
future so we're looking at the value
here of 2007-2010 before we go too far
let's take a step into a discussion as
to how all of this actually works in
terms of our concerns so the 33 the
three main concerns for disaster
recovery
there's the disc which on the disk you
have your database itself so the
database is another concern especially
in terms of corruption we don't want to
eliminate that as a potential cause for
concern database corruption is an issue
and we're going to discuss how dads with
exchange 2010 mitigate that but disc is
a key concern than the server itself and
then the entire site
alright so those are the three concerns
when it comes to disaster recovery so
methods within exchange 2007-2010
include looking at with 2007 we had LCR
local continuous replication we had ccr4
the server cluster continuous
replication which required a lot of
extra work in order to get the
yeah the clustering services setup you
had a passive mailbox server an active
mailbox server you have to configure
those when you do the installation there
are a lot of limitations but it was the
best option of exchange 2007 so for
those of you are still working on
exchange 2007 you do have the ability to
have high availability through these
various means and then in terms of sight
resiliency there was a standby
continuous replication now the problem
with those two LCR and scr is that they
didn't use clustering services so if
anything did go down in the case of LCR
if the disk went down you have to
manually switch over to the other discs
in the case of the site going down there
was a lot of manual intervention
involved but in both of those cases
that's just what we had so you know the
amount of time that was actually down we
were down would be minimal compared to
older solutions or no solution certainly
but then with exchange 2010 database
availability groups were introduced and
this isn't just a tremendous solution
it's an amazing solution that's been
provided by the exchange team as well
start with the price tag
it's free it's built writing does that
mean it's going to cost you nothing
well no obviously you're going to need
to spend some money you're going to need
to spend money working with with
multiple servers and getting this setup
and designing and deploying it making
sure that you have it all set up
properly
you're gonna have to spend money on more
software but look that's that's sort of
a given expense of availability that any
for to make anything more highly
available you need to have you no
duplication of it so you have to just
expect that there will be an expense but
compared to the days of old this expense
is really nothing you know in terms of
the amount of money you're going to
spend compared to the benefits that
you'll have especially if you can
eliminate the time and effort and money
that's spent on your backup solution
just taking a look quickly in how the
storage architecture works in this
regard so that you're not a loss
regarding your exchange environment you
need to visualize the technology that's
in place so to start with there's a
database file
it's called an EVP file for those of you
already exchanged admins and it sounds
like there's pretty much everyone on the
line is you know that that EDP
file has transaction locks these logs
used to be larger but with exchange
2007-2010 there one megabyte inside in
size and basically what happens is when
email comes into your server it gets put
into a transaction log and then as the
database freeze up in terms of being
available the larger right over into the
database
there's a checkpoint file to make sure
that nothing is missed and the database
then we'll continue to grow
whereas those transaction logs you know
they grow as well and that's why
something like a a backup will
oftentimes call those transaction logs
another way to call those transaction
logs is to to ensure that they don't
continue to accumulate and so you can
accomplish that as well with continuous
replication the database is initially
copied so the first thing that happens
when you set up a second system and you
make it part of your database
availability group and you create a
passive copy of the data is the
databases copied and then log files are
shipped over and they're replayed
constantly to keep that database
up-to-date so this allows you to have a
redundant copy of your data that is
waiting for the opportunity in the event
the first system goes down at second
system can automatically jump into the
mix and can start providing email and
then mail services to your users so
that's a tremendous thing in terms of
providing higher availability database
availability groups these use continuous
replication so there's that constant
shipping of the logs and replaying there
are 2 16 servers that you can use
so for those of you who are working with
exchange 2007 you realize that you have
a limitation you can go from one active
server / 21 passive server and then you
can also establish you know stand by
continuous replication that allows the
data to be moved off-site to other
locations but with a dag you can have 16
different servers in the mix so that's
impressive
it uses clustering features like
heartbeats and like a file share witness
and disconnects members of a dag so the
heartbeat basically it's a simple method
of servers checking in with one another
to ensure that they're still alive
this heartbeat goes back and forth
between these systems the witness server
or file share witness this is a method
for providing a referee between dag
members in the event it appears that one
has gone down now
did we mention this the witness server
as a it's really not something that's
always necessary only necessary in the
event where you have an even number of
mailbox servers in play because you need
them to have a tiebreaker to establish
what's called quorum now quorum is an
interesting thing because with quorum or
basically saying is that there's a way
to break a tie if you only have two
servers like here we'll go back here for
a second if you only have two servers in
the mix and let's say the system one
goes down and system 2 says well I don't
get the heartbeat anymore i really need
to go into action here and become the
the active copy here
well the problem is is what if system
one didn't really go down
what if they're simply a problem between
the communication of system one and
system two Howard system to know that if
system to goes live then system to now
could you know could run the risk of
being active when system one is active
and this creates a problem called split
brain syndrome it's also termed world
world chaos
obviously these terms are not good
things in the whole world chaos not a
good term for your exchange environment
and what's basically happening is your
you have two systems that think they
have the active copy of the database so
how does system to how do we prevent
system to from jumping the gun and
deciding that it should step up when
that's all that it's actually designed
to do here it's ready to go
well that's where you need to have
another third server in the mixed now
that third server could be a third
mailbox server in which case you don't
need the file share witness or it could
be a third server that's not an exchange
server it could be a third server that's
perhaps a hub transport server and is
waiting there with a way of saying to
system to look I'm in contact with
system one there's no need for you to
involved everything's good and so then
it gives you time to correct the issue
without having split brain syndrome so
there's the file share witness and it
provides this quorum or referee between
dad members in the event it appears that
one has gone down now we're just going
to take a look at visual dad here for a
moment we're not going to get into a
discussion of the different design and
deployment aspects of a dagger at this
point every environment and I see we've
got about a hundred people you know
listening in at this point every
environment is going to be a little
different so if you have let's say a
single-site environment within a single
office structure you can have a deck if
you have multiple sites within the same
city within the same country you can
have it back if you have multiple sites
straight across the globe you can have a
bag and that's the only other option
that's built right into exchange and it
satisfies all of the different types of
scenarios out there now the only thing
that doesn't get satisfied in every case
is the concept of an automatic failover
and we'll talk about that in a moment
after we discuss this particular slide
and the way things are mapped out so for
starters you've got multiple systems and
the way you establish a dag is you
create the database availability group
which is not something that you know is
too difficult to do in the exchange
management console you just say i want
to create a database availability group
and give it a name then you add members
to that database availability group so
in our case here we would have to add
system one and system two in system32
that deck and then at that point we we
might have three different databases one
on each system we may not we may not
have that many databases at all
we might simply want system tools system
34 the passive copies of the data base
I'm using the term replica that simply
too to help you to visualize what's
happening with the data but the term
itself is is not really appropriate in
this case we think of replicas when we
think of public folders and we create
replicas here when it comes to the dag
copies
there's the active copy of the database
as you can see in with system to
database to we have our active
copy that is the live copy of the
database that's working for users and if
something happens there there's a
passive copy on system one the passive
copy is kept up-to-date with continuous
replication then you can see over in
system three there's another type of
passive copy but it's called a lag copy
now this is something that's very
helpful for ensuring any type of
database corruption or virus things of
that sort don't get copied automatically
through the continuous replication
process so you can establish a lag on
the copy you can determine how long you
want for that you know there's various
time periods that you might want
in fact you might want multiple Lacs
copies one that lags for you know so
much time you know you're shorter period
of time and then one that lasts for an
even longer period of time just to make
sure if something harmful did come
through that you have this time to stop
the process and switch over to the leg
copy it sounds easier than it actually
is so we're not going to get into the
the intricate you know step by step of
accomplishing this but the lag copy
process is something that you'll need to
take some time to design properly within
your organization
ok so hopefully you have the visual
understanding as to what's going on here
the next part here is to start thinking
about how does this actually eliminate
disaster recovery
um well just looking at this here on the
one hand back in the day if you did have
a problem with your desk or your server
or whatever you didn't have a passive
copy to resort to so for those of you
who have been in this business for a
while you know you have to get those
backup tapes out right and what a
nightmare
the other frustration there is that you
know everything was was this tremendous
block-level restore you were restoring
the entire database and then companies
came out with the ability to do brick
level backups and you could literally
backup a mailbox a specific mailbox but
that involved deploying agents and you
have to have these mailbox agents from
the company and this was ten years ago
we were doing this kind of thing but you
could back up
the mail messages from you know the
highest you know people in the company
the partners the vice presidents and so
on and you pay a hefty price for doing
this with the backup solution you used
back in the day veritas was like the
biggest thing going
commvault systems have their own
solutions and you would do that but the
frustration there of course was that you
know you have to be an expert and you
have to make sure everything works
properly and tested it but here what a
nice thing you don't even have to think
if system to goes down system was gonna
take over right if these two are in the
same building system one goes down
system to you know system to go down
system one takes over everybody keeps
working and you're you're good to go
that's how we eliminate disaster a
disaster recovery now we don't have to
care so much about the disaster so much
as the fact that all of our people are
still up and running and now of course
we need to get things back into a better
balance and make sure that we have the
another passive copy and play just in
case that disaster grows a bit where
this becomes still a disaster to worry
about is if we lose both system to end
system one you might say well then we
have system three well that's true but
let's say system 3 is not located in the
same location at that point we're
looking at a different type of recovery
and this is where you know we need to
talk about that type of scenario so
again if you lose too many servers in a
dag you can lose quorum
so in r3 dag situation that you're
looking at there if we lose both system
one and system two with lost quorum
we've lost the ability to to really
prove to system three that it's the one
that should be up and running and
handling all of the workload and so
that's product a problem whenever you
lose quorum that's going to be a problem
so if you lose quorum you have to
manually intervene in the process now
does that mean am I saying that I you
know high availability has a limitation
and it's it's such a great limitation
that you should always make sure you
have backup tapes or backup media ready
and so on
no that's not what's being said there
has to be you know some given take on
this because the manual intervention is
going to be necessary at some point but
ask yourself the honest question is the
manual intervention
in more difficult with a
high-availability solution or is it more
difficult with a backup and disaster
recovery solution
well just from experience I can tell you
it's a whole lot easier to get to switch
over to another server that it has lost
quorum than it is to get the back up
back up and running so now some consider
the manual intervention to be a break
from the true concept of high
availability but really whether your
system fails over or has to be switched
over manually the recovery time and the
availability of those services is still
dramatically reduced through dags in
comparison with traditional backup
recovery and why am I trying to sell you
on this idea you know i mean it sounds
like i have some kind of stake in this
look there I have no profit to gain on
this it's simply a matter of
understanding that you're you're
duplicating your efforts as exchange
administrators when you have a solid i'm
not talking about a lame
dag deployment we're talking about a
solid DAC deployment you have enough
servers that microsoft says at least
four that are handling your data and if
you have this deployed properly and if
you have considered the design aspects
of it for your environment and you have
the servers in play then you are
duplicating efforts to also now have an
archiving solution which many of you
also have because you're fully aware of
your need to be compliant you've already
been hit with various litigation and no
such so that you know you need discovery
and you know you need to be compliant
and all that and now you also have your
disaster recovery backup solution which
you say you never need and you never go
to of course you don't
it's it's redundancy that's unnecessary
so at some point you know it's it's kind
of like a waste of time to even have
that backup recovery solution and even
many companies have decided to start
dropping that and to go with just high
availability and archive you know the
archive gives them that ability that
they have from the disaster recovery
side from a backup will it work for you
will where I don't know you know it's a
lot of times it comes down to your
mental outlook on on how all this works
it's a leap of faith it really is is it
working for others for my understanding
Mike
soft is running a full shop without full
exchange shop without worrying about
backups so it works for them how many
bags you know how many redundance
systems are they using obviously more
than four maybe as many as 16 who knows
but you know they actually have
published their full layout for for
their high availability deployment and
you can find that online they're willing
to give you the whole step by step how
they did it in house so they're pretty
confident you think about Microsoft's
you know their exchange environment and
what they provide especially to the
outside world with providing solutions
like that that if they're willing to
give it a shot
you know you might be willing to do it
as well you know and other large
companies have done the same so you know
we've moved through this pretty quickly
just to give you my final thoughts and
then we're going to go through some of
the questions the Q&A and make sure that
we we hit all the questions but if done
correctly using the proper number of
servers for more you can eliminate the
need for traditional backups as the
first line of defense in your disaster
recovery strategy
some may not be comfortable with that
and so they may still want to retain
backups which is up to them but many
have jumped forward to the failover
switchover world of dags for their
exchange environment
as for longer-term backups and such
archive solutions have taken over that
role so you can perform individual item
restores business if necessary
along with discovery and have compliance
and so forth also included in the mix so
I think again there's a strong case to
be made her that for this
there's a strong case for eliminating
the redundancy you know i'm not saying
you're not going to need backups for
everything of course there are other
things you'll need to backup but to
eliminate the need for backup a
traditional backup and still eliminate
the concept is a disaster when it comes
to your disaster recovery in the process
you know it's something to consider it
something to really give some deep
meditation to before we conclude I'm
gonna put the kind of contact
information up here on the motherboard
and you can learn more about exchange
through one of the training courses that
have created from trainsignal you can
see we have quite a number there's a
huge epic course the administration
training course then we've got into
design and deployment backup and
recovery high availability and unified
messaging it's all there a ton of
training really and our training doesn't
just focus on certification exams you
know although we do keep that in mind
but our main focuses on making sure you
can perform the tasks in the real world
you can also read my column on
enterprise windows and there's the link
there and you can email me at Peter I
trainsignal com or follow me on twitter
@ JP bruise easy
so I'm going to leave that up and now
i'm going to go over to the questions
that have been asked her out the other
session here and see if we can answer
some of these questions all right and
while we're doing this by all means
continue to add more so the first
question I can't find discovery search
mailbox in ECPI just my mailbox users
okay I'll tell you what whoever asked
that question I can't really see who the
person is this . that's a question you
might want to email me offline because
its side stealing with the discovery
mailbox
ok so you can email that to me and we'll
see if we can work that out
let's see what else we have
a lot of folks are
four copies of the presentation slides I
think that's available that will be made
available not a problem
ok.can high-availability be implemented
in a small business server 2011
infrastructure
unfortunately no it's not it's not part
of that environment because you're only
dealing with a single exchange server so
in order to set up high availability you
need to have at least three servers two
of them being exchange servers and then
a third one for arm so it's not part of
that type of solution conduct be used
across sites absolutely yes it can be
used to cross-site sites so Shane ask
this question very good question
he's saying that he has one side in
austin texas and the home offices in New
Orleans can they have exchange services
of both sides replicating between each
other each other you absolutely can in
fact that's one of the real values to
what dads have to offer because you can
have multiple sites all around the globe
replicating this data and you know the
only thing to keep in mind however is
that if there's a loss of quorum that
you can fail over from one site to
another that's not a problem if the when
connection between the two sites is
still solid and if they're still quorum
meaning that there's still enough
servers in the dag to provide a majority
vote then you would be able to failover
from one server to another and that what
happens there maybe I could just give a
little insight there so when you're
setting up your dag you can establish a
preference in terms of the failover and
you can say i want you know the
preference to be 123 and as far as which
server is going to get the next copy or
of that data the passive copies is now
going to become the active copy
however that setting is not something to
be something to be taken as you know
it's not that it's not too serious but
it's not the end-all and be-all of which
server is going to be failed over to so
there's a thing called the active
manager that is actually taking into
account the the latency between the
different sites that the different
servers and it tries to do what they
call a best copy selection so it looks
at everything and then it chooses the
system that
the best copy selection in order to make
that go live so again if you have
multiple sites and play and you do have
a failure it can utilize another server
in another site and it can fail over if
however you lose quorum and you have a
multi-site environment in play
you're going to need to do a switchover
not a failover and what that involves
pretty much you know you manually have
to shrink the size of the dag and you
have to eliminate the the fact that
perhaps you've lost a whole site maybe
there's been a blackout maybe the web
connection has gone down whatever the
case if that's if that's occurred
you're going to need to do a switchover
not a failover so that's going to
involve some manual intervention
another thing to keep in mind something
we haven't talked about is a feature
called a commode back mode is is
something that's you have to enable on
your dag when you're going to use
multiple sites and this prevents that
split brain syndrome because it prevents
those servers when they come back up
from let's say a blackout situation
it prevents them from thinking that
everything is fine and that they should
you know that the active copy should
resume as the active copy so it prevents
those databases from mounting until you
can intervene and get the situation
worked out so I hope that answers your
question change you might have more
questions regarding this subject
you're welcome to email me and we can
talk about it even more so let's see
what other questions have come in
is there a DAC feature also for
sharepoint Fabio excellent question
no there there isn't that I that I'm
aware of um I'm a sharepoint
administrator and I've worked with a
couple of different things with
sharepoint there are some interesting
things when it comes to sharepoint
utilizing sequel that there may be a way
to to have duplicates of copies of
things in sharepoint but it's not the
same as dad it doesn't work the same as
dag the exchange databases are different
from sequel databases now some of said I
wonder if exchange is ever going to use
sequel as its database you know in the
background and that's just been a debate
for years but up until this point the
exchange team has continued to say that
it's just not something that they think
is is a good move at this point so there
are there but again there are ways to
have multiple copies of your data for
sharepoint as well that's that's an
absolute but it's not the same in terms
of deck
ok the next question many of my
customers are looking to use exchange
2010 for AJ but they only want to
implement one server insight and 17 site
B is a good design best practices me so
I'm okay that's a good question
um you know you're eliminating your your
most important thing which is immediate
server failover and if you're dealing
with servers into separate sites then
you're you're looking at adding a lot of
complexity to the design because now you
have no qualms in individual site so
that's that's not gonna work out very
well that's that's actually would say
that's a horrible design adding you know
if you want to do that that's fine but
then add in one more server insight a or
site B and and this way you have the
ability I here's the way it's supposed
to work
you want the active copy and the quorum
really to rest with the site that has
the most number of users so let's say it
depends here if let's say your company
has a thousand users and you have 900
insight a and 106 be what you would do
is you would put your two servers
insight a and one server insight be in
sight be really would just be acting as
as a as a backup in a sense in that the
data is being replicated over and you
have this you have a safe backup of all
of your data inside maybe you could call
site be your you know recovery site you
can call it your your cold site you have
a woman cold you can have your your
active site and your passive side
however you want to call it but using
one server in one side one of the other
that's that's not really the smartest
way there are other there's a really
cool article that was written by Scott
channel about some of the misconceptions
22 design actually while while we have a
few minutes let me tell you the name of
that article because I think you'll like
it
I'll pull it up here so that i can i can
tell you the name of it but it's
basically misconceptions misconceptions
in the use of DAG i'll tell you the full
name of it and then you folks will be
able to look for it
alright so i did a I did a search for
dad misconceptions and the article that
came up it was a blog on technet the
full title of the article is exchanged
2010 high-availability misconceptions
addressed
okay everybody get that exchange 2010
high-availability misconceptions
addressed it's from the exchange team
blog it was written by Scotts knoll is
really the master when it comes to all
of these different when it comes to high
availability and you know some of the
questions that folks have asked their
relate to the design things like when I
have a dad with an even number of
members that is extended to two data
centers placing the witness server in a
third data center enhance his reliance
is that true or false and that he
completely explains it that's not
accurate
so this is a great article to answer
those types of questions i recommend
that you give those a look let's see
here let's see what our next question is
and if you have
those if I'm answering questions and you
have more to the question you're welcome
to ask another question we have a little
bit more time here how many data how
many databases can be
dad is there a limit yes 16 is the limit
oho the number of databases that's the
question isn't it
no I don't believe there's a limit in
that respect I'd have to double check on
that I've never asked that question
actually can we switch automatically our
whole exchange to a dr site without any
manual intervention
you can if you haven't lost quorum if
you have there hasn't been a disaster so
that's a great question in the event
let's say that you had a blackout and
column is lost and the LAN connection is
down you're looking at a manual
intervention
there's no way around that that's site
it's a switchover not a failover
everything stopped and running you can
easily switch your active copy over to
any other server even in another site
that's not a problem but even that
you're going it's going to be manual
intervention you can switch it over so
you have no matter what you're looking
at some kind of manual into intervention
in that case how many databases can be
re answer that do you have the same
availability functionality and office
365 as well
office 365 if you're talking about going
with a full office 365 deployment and
then Microsoft is utilizing availability
in order to ensure that your mailboxes
are safe
the nice thing about a hosted solution
is that you don't have to worry about it
it's being done for you automatically
and they're taking care of it
three decks but if you're using a hybrid
solution where you have your in-house
on-premises solution and you have your
in the cloud hosted office 365 solution
well then those mailboxes that are still
in house you're still responsible for
those so what office 365 is doing that
you're protected there but whatever
you're doing in-house may not be what
sort of storage architecture is best to
set up to dad using sand desert
direct-attached storage last I checked
as was not supported by exchange you can
you know as far as the dags to be honest
with you
microsoft has long promoted with
exchange 2010
you know and 2007 there's been a focus
on using jaybob arrays so game on stands
for just a bunch of disks the nice thing
about some of the changes that have been
made with exchange 2010 there are some
frustrations they've eliminated single
instant storage so of course your data
can kind of balloon a bit they recommend
a lot of ways to mitigate that and you
should follow best practices from the
Microsoft Exchange team in order to
accomplish you know keeping your
database sizes in check but it has
increased performance tremendously the
value of that improve performance
increase is that now you can utilize
just standard you know direct-attached
storage or you know jaybob arrays that
provide you the performance you need at
a less cost because I mean look anybody
who is honest and knows how expensive
that can be and so for some of you out
there who are listening you're looking
at at expensive solutions and maybe
you're a small business and you're
looking to just set up to exchange
servers that can handle your dad you
know situation and provide the at least
the disc and server resiliency if not
cite resiliency and in that case you
don't have to go spending thousands of
dollars on a sam so in that solution
again i would recommend you know going
with a.j bad situation
the other thing about this in terms of
cost some have asked about
virtualization can you virtualize all
this you absolutely can you can
virtualize all this here's the problem
with virtualization for those who aren't
just aren't thinking and you know they
get very excited and they say you know
what I'm going to do I'm going to set up
two servers hyper-v on both i'm going to
set of exchange on both with with
mailbox servers and we're gonna have
multiple roles installed on each one
I'll have my my file share with this be
a third server that's the domain
controller so okay I've got this setup
and what I'm going to do is I'm going to
virtualize all of this i'm going to use
one server with three virtual machines
and put them all together
ok and that's that's great you're still
you're still safe in terms of perhaps
database if you have databases on
separate discs you're still possibly
safe from database corruption with the
Dagon but you know you've done you've
just eliminated your ability to have
server redundancy because everything is
still on one server
you'd be amazed how often this happens
everything is on a single virtual server
well that's great you save space in your
office with the one server but you've
eliminated the value of a dag because
now you have multiple systems running on
one single server so what's the point
so just keep that in mind you can
utilize virtualization with dags it
works but make sure that you have your
two separate servers on two separate
literal hyper-v server
ok let's see with it with to exchange
servers into databases can one copy be
active at one side and another on the
other side after all
yes actually that's not that's a great
that's a great thought so this is a
design question about the number of
exchange servers and databases and so on
you can have to exchange servers and you
can have two databases one on one side
one on the other
keep in mind though you know that that
now you're protected because if let's
say you have a thousand users and 500 or
setup for the database on the first
server 500 her set up for the database
on the second server that both handling
their workload if server one goes down
then the passive copy on server2 would
kick right into high gear and you have
the ability to now serve all 1000 of
your users nobody would miss a beat and
everyone would be able to continue to
work until you got server1 back up and
running
yes that's exactly a perfect example of
eliminating disaster in disaster
recovery
um ok business continuity test that's a
bigger question than being able to you
answer right now we can scott folic acid
about business continuity by all means
to email me that offline and we'll talk
about it if you do dad is there
information on the Cavs requirements
forecast high availability if the
mailbox service which is over
ok so you're talking about a chasm array
that is those are great questions
actually because we've simply been
talking about high availability of the
mailbox server role through dag that
that is why you know even though this is
a discussion of high availability you
know to a degree were mainly focusing on
disaster a disaster recovery which
typically always focuses on the mailbox
so we focused on deck
but if you're talking more about
high-availability itself then you have
to consider not just your other server
roles the two main ones being your
calves and your help transport servers
which yes you would need to have a
caster eight and you would need to have
a you would need to have for the hub
transport service you need to have at
least more than one when it comes to a
catcher a catcher a be part of a dag be
on the same server as a tack
the answer is No if you're going to
utilize Microsoft's network load
balancing and will be cannot work with
kaz array cannot work with cache servers
if you're also now have that mailbox
server as part of a dag reason for that
is very simple NLB is a form of
clustering and dag is a form of
clustering clustering services are still
installed behind the scenes so you can't
have that server be a member of a of a
clustered situation and then also use
NLB so what do you do you use a hardware
load balancer if your calves is part of
is on the same server you know Microsoft
is recommending that you you deploy
multiple server roles together so you
could very easily have a mat mailbox
server that has calves and have
transport on the same server and it's
part of a deck
what do you do you get a load balancer
you get a hardware load balancer and you
know what I'm just gonna throw this out
there in case you're wondering like hey
what do I get one of these things
there's a couple of them out there i
personally I'm a huge fan of camp
technologies
I think they make some of the best load
balancers out there in the business
really growing so there's at least a
starting point if you're not sure where
to go but again you might have your own
you know options already in play
um let's see what let's see what else we
have here
we're almost towards the end here i'm
going to turn things back over the
cabinet management answer one more
question
Jonas good question any new features in
exchange 15 on this subject
Jonas i'm a member of the tap program
which means that i could answer that
question but if I did I think that
somebody would be knocking on my door in
the next five seconds and I be dragged
away and you never hear from me again
no i don't i hope not I hope that's not
that strict but no there there are
stipulations as far as how much I can
say about exchange 15 let me just say
this I from what I've seen it's it's
it's not i can't say anything nevermind
i just can't say anything I'll just say
that dads are awesome and you don't have
to worry so much about exchange 15 just
get let's see is dat mode enabled by
default in sp2 it's not you have to make
sure it's enabled which of your
trainsignal trainings for exchange
expand on designing a high-availability
get availability setup
actually I have a high-availability
course exchange 2010 my availability
that we just finished and it just went
live so you're welcome to check that out
oh boy there's so many other questions
quick question what if my file windows
server fails if that fails and your
other two servers are still up and
running and still able to talk to each
other then it's no big deal
so you didn't lose quorum because the
final witness server is is just part of
the mix there if it's one of the servers
that fail with the other two then you've
lost quorum in fact you have lost the
whole thing so again that's where manual
intervention is involved so Dagon
cassirer cannot be on the same server by
sanjay I know that's not true
the cassirer can be it just has to be
you have to use a hardware load balancer
you can't use Microsoft network load
balancing
ok who well that's that's that's all we
have time for today folks
any additional questions by all means
you can email me we can work that out
the email and I'd be more than happy to
finish up answering any other questions
that you have at this time I'm going to
turn things back over to Kevin I hope
you enjoyed this session today i hope it
was a lot of fun hope it was interesting
and I hope it gives you something to
think about in terms of the other
features that you have at your disposal
alright Kevin take away
alright thank you Peter that was a great
presentation that's all the time we have
for today thanks again for attending and
for your participation as a reminder
today's webinar was recorded and will be
available to view a train signal . com
/a blog /a webinars will also email you
the link and remember as we please fill
out the survey for a chance to win a
copy of transit most exchange server
2010 high-availability training we will
email the winner by the end of the week
thanks again and have a great day
Video Length: 58:34
Uploaded By: Pluralsight IT - Training Archive
Published: 5/21/2012
View Count: 13,036