CERN - European Organization for Nuclear Research Exchange 2000 Pilot at CERN HEPiX-HEPNT Fermilab, October 2002 Frédéric Hemmer Frédéric Hemmer – CERN.

Slides:



Advertisements
Similar presentations
Managing Incoming Chapter 3 Bit Literacy. Terminology client – program which retrieves s from a mail server, lets you read the mails,
Advertisements

IBM Software Group ® Accessing Domino via Outlook iNotes Access for Microsoft Outlook - Notes Domino 5.5 – Domino Access for MS Outlook - Notes Domino.
How Clients and Servers Work Together. Objectives Web Server Protocols Examine how server and client software work Use FTP to transfer files Initiate.
Collaborative tools in NICE Alex Lossent - CERN IT/IS Hepix Fall 2005.
Exchange server Mail system Four components Mail user agent (MUA) to read and compose mail Mail transport agent (MTA) route messages Delivery agent.
Installing and Maintaining ISA Server. Planning an ISA Server Deployment Understand the current network infrastructure Review company security policies.
Introduction to UTORexchange For IT support providers.
Exchange deployment at CERN and new ideas for SPAM fighting Michel Christaller, Emmanuel Ormancey, Alberto Pace.
Microsoft Exchange Exchange is more than just Electronic Mail The server that embraces Internet standards and extends rich messaging and collaboration.
-I CS-3505 Wb_ -I.ppt. 4 The most useful feature of the internet 4 Lots of different programs, but most of them can talk to each.
CT NIKHEF Nov Mail NIKHEF CT system support.
Winter Consolidated Server Deployment Guide for Hosted Messaging and Collaboration version 3.5 Philippe Maurent Principal Consultant Microsoft.
Securing Exchange Server Session Goals: Introduce you to the concepts and mechanisms for securing Exchange Examine the techniques and tools.
IT:Network:Applications Fall  Running one “machine” inside another “machine”  OS in Virtual machines sees ◦ CPU(s) ◦ Memory ◦ Disk ◦ USB ◦ etc.
Section 6.1 Explain the development of operating systems Differentiate between operating systems Section 6.2 Demonstrate knowledge of basic GUI components.
TNQ Microsoft Exchange Server ® 2000: Microsoft Outlook ® Web Access John Gardner Cyberstreams, Inc. John Gardner Cyberstreams, Inc. Portland,
 2:00 pm - 2:15 p.m. ◦ Intro, Welcome and Overview of Agenda  2:15 p.m. - 3:00 p.m. – Admin Training ◦ Introduction to Live at EDU and roadmap.
Chapter 7: Using Windows Servers to Share Information.
SCO Insight Connector Training. The SCO Insight Connector  Product Overview  Technical Specifications  Installation  Using the Components  Target.
Backup Local Online For secure offsite storage of your , and making it available from any computer or smart phone. Backup accessed with.
The Linux Operating System Lecture 7: Tonga Institute of Higher Education.
Module 8: Managing Client Configuration and Connectivity.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Four Configuring Outlook and Outlook Web Access.
©Kwan Sai Kit, All Rights Reserved Windows Small Business Server 2003 Features.
Webmail. Agenda Why use webmail? Why use webmail? What is webmail What is webmail – basic » system MDA MDA MTA MTA MUA MUA »Protocol SMTP SMTP.
Module 6: Manage and Configure Messaging. Configuring Internet Mail Using Small Business Server (SBS) 2008 Console Configuring Protection Configuring.
IT:Network:Applications.  How messaging servers work  Initial tips for success Exchange management  Server roles  Exchange Server Management  Message.
MIGRATING FROM MICROSOFT EXCHANGE SERVER AND OTHER MAIL SYSTEMS Appendix B.
INSTALLING MICROSOFT EXCHANGE SERVER 2003 CLUSTERS AND FRONT-END AND BACK ‑ END SERVERS Chapter 4.
(or ?) Short for Electronic Mail The transmission of messages over networks.
By: Bill Stevenson Jose Plancarte Erik Magsino. Overview Messaging and collaboration server Send and Receive electronic mail and other forms of interactive.
The Internet 8th Edition Tutorial 2 Basic Communication on the Internet: .
SMS 2003 Deployment and Managing Windows Security Rafal Otto Internet Services Group Department of Information Technology CERN 26 May 2016.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Seven Configuring and Managing Exchange Server.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Two Installing and Configuring Exchange Server 2003.
advantages The system is nearly universal because anyone who can access the Internet has an address. is fast because messages.
Microsoft Office Outlook 2013 Microsoft Office Outlook 2013 Courseware # 3252 Lesson 6: Organizing Information.
1 Adding Secure and Collaboration to Your Business with SCOoffice Server 4.1.
Exchang ing. Ex-mail Ex mail is windows base mailing service where With Microsoft Exchange and Users can do more than send and receive. Exchange.
Update on  Mail Gateways  Servers  Spam Tagging  Anti-Virus  IMAP  Web Mail  LISTSERV  POP.
Module 6: Integrating ISA Server 2004 and Microsoft Exchange Server.
Module 6: Managing Client Access. Overview Implementing Client Access Servers Implementing Client Access Features Implementing Outlook Web Access Introduction.
Exchange Pilot as a new Messaging infrastructure at CERN Alberto Pace, for the IT/IS group - April 2002
Status of Exchange deployment Alberto Pace for the IT/IS group Desktop Forum, April 3 rd 2003.
CERN - IT Department CH-1211 Genève 23 Switzerland t OIS Deployment of Exchange 2010 mail platform Pawel Grzywaczewski, CERN IT/OIS HEPIX.
CERN - European Organization for Nuclear Research Beyond ACB – VPN’s FOCUS June 13 th, 2002 Frédéric Hemmer & Denise Heagerty- IT Division.
NetTech Solutions Microsoft Outlook and Outlook Express Lesson Four.
1 Adding Secure and Collaboration to Your Business with SCOoffice Server 4.1 Marc Modersitzki.
Hosted Microsoft Exchange & Collaboration Emergic nextGenMail Hosted Microsoft Exchange & Collaboration Presented By: Sales Person Name ID: Mobile:
Plan for the Exchange 2000 Deployment Proposal Desktop Forum IT/IS 30/10/02.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter One Introduction to Exchange Server 2003.
Microsoft Windows Small Business Server 2003 Technical Overview Byron Hynes Microsoft Corporation
11 MICROSOFT OFFICE OUTLOOK 2003 AND MICROSOFT OUTLOOK EXPRESS Chapter 4.
The New CERN Mail Services Information for group Administrators Alberto Pace for the Internet Service Group and the Mail Migration Task Force.
A leap ahead... Darren Kearney Don Miller Ilya Pinchuk.
Office 365 is cloud- based productivity, hosted by Microsoft. Business-class Gain large, 50GB mailboxes that can send messages up to 25MB in size,
Outlook / Exchange Training. Outlook / Exchange: Agenda What Can Microsoft Exchange Do / How works at UST? and Inbox Mailbox Quota Archiving.
– Protocols 21 – Protocols 21. – Protocols 21 Now we’ll move on to more technical aspects of This means protocols Remember.
Chapter 7: Using Windows Servers
Nat 4/5 Computing Science Software
3.1 Types of Servers.
Office 365 is cloud-based productivity, hosted by Microsoft.
3.1 Types of Servers.
TNQ
MICROSOFT OUTLOOK and Outlook service Provider
3.1 Types of Servers.
CompTIA Server+ Certification (Exam SK0-004)
Emmanuel Ormancey - Michel Christaller
HEPiX-HEPNT Fermilab, October 2002
has many aspects that work together to give people almost instant communication from any computer on the internet to any other computer There.
Presentation transcript:

CERN - European Organization for Nuclear Research Exchange 2000 Pilot at CERN HEPiX-HEPNT Fermilab, October 2002 Frédéric Hemmer Frédéric Hemmer – CERN IT DivisionCERNIT Division

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Outline Motivations What is Exchange Current Infrastructure and Architecture Tools developed (Demo) Security Remaining problems Next steps

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Initial Motivations User requests for “shared” calendar –Delegation Secretary reading the Boss calendar to know where he/she is or his/her availability Secretary accessing the Boss calendar to manage his time Secretary and Boss both take appointments and want to avoid conflicts –Sharing E.g. publishing software release schedules together with a collaboration schedules –Replacement of Schedule+ Some part of divisions will not migrate to Windows 2000 without a shared agenda Traveling user requests –Web Mail Access to mail and calendar from anywhere, without complicated setup Traveling user managing his time with the PDA, synchronizing with Outlook late in the evening and want the secretary to be up to date

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Initial Motivations (II) Cost reduction of mail service –Hardware costs Largely based on (expensive) SUN’s Regular reminders for people to cleanup their mail folders to free up disk space –Manpower costs Service run by a small number of highly skilled people Does not scale for LHC Era requiring a 24x7 coverage Secure the mail environment –Mail password changes were not enforced –With ADSL becoming more popular, password and data is crossing public networks in clear –Virus checked at the smtp gateways only FStarted to investigate EOY 2001 Came up with the conclusion that Exchange 2000 might well do the job. So a pilot was proposed in 1Q2002.

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer What is Exchange ? Collaboration platform running on Windows 2000 integrating –Mail –Calendar –Tasks –News –Public Folders –Global Address Lists –Workflows –etc…

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer What is Exchange (II) ? Exposes the functions through formal or de facto standards: IMAP4, POP3 for mail –Outlook, Pine, Netscape, Eudora, Evolution, etc... –All platforms incl. Linux, PDA’s, etc. NNTP for News –Netscape, Outlook Express, etc. –All platforms Linux, etc. except PDA’s MAPI for mail, calendar, tasks, etc… –Windows, Mac OS, PDA’s, not Unix/Linux –Evolution (Linux) promises MAPI (Ximian connector for Exchange)Ximian connector for Exchange –Accessed thru Outlook HTTP for everything –All platforms incl. PDA’s WebDAV (RFC 2518 draft standard) –Currently Windows only, but this is changing ( SMTP for mail routing

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Understanding Folders Mailbox folders Public folders

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Current Infrastructure 8 Servers –3 “Mailbox” stores –2 Public Folder Stores –2 Front-end servers –1 Spare IMAP (secure), POP (secure), MAPI and HTTP –MAPI not yet open outside CERN –Web Mail, Calendar etc. fully available and open thru secure HTTP ( –IMAP/HTTP work with almost any client –MAPI with Outlook on Windows/Mac Office XP recommended for collaborative features on Windows –Not possible to switch Outlook 2000 from IMO to CW –Allows for multi protocol –Allows to revert to existing mail solution

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Exchange 2000 Architecture Internet CERNXCHG01 CERNXCHG02 CERNXCHG0x Mailbox Stores CERNXCHG05 CERNXCHG06 CERNXCHG0x Public Stores Backend Servers CERNXCHG98 CERNXCHG99 CERNXCHG0x Frontend Servers WebDAV + … IMAP, IMAPS (143,993) POP3, POP3S (110,995) HTTPS (80, 443) SMTP (25) mmm.cern.ch SMTP https http Imap(s), Pop(s) FireWall CERN.CH MAPI (135+…) CERNXCHG03

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Yes but what if I’m not on Windows …? Exchange limitations include –No Mail forwarding –Limited and slow migration tools –Folder Permissions manipulation only with Outlook –Send on behalf only from Outlook –No real server side spam filtering –Nothing to help better Outlook Users –MAPI requires RPC (135) which can be a source of DoS –Etc… So, we decided to investigate how to extend OWA and Outlook to provide missing or new features Demo

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer OWA – CERN Tools

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer forwarding

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Send on behalf

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Folder permissions

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Instant Messaging

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Instant messaging

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Spam filtering

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Access to News

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Subscribing to news

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer CERN Tools in Outlook

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Outlook AddIn

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Securing Exchange 2000 Remove IMAP, POP protocols from offsite access –Need client reconfiguration Recent clients only (Mozilla, NS6, IE 5/6 OK) Others would needs to upgrade or use http MAPI access (Outlook) –Disabled for offsite access Use it over a VPN –Yes, but… as a minimum requires client configuration –Security Officer does not like this Use ISA Servers

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Exchange 2000 Architecture Internet CERNXCHG01 CERNXCHG02 CERNXCHG0x Mailbox Stores CERNXCHG05 CERNXCHG06 CERNXCHG0x Public Stores Backend Servers CERNXCHG98 CERNXCHG99 CERNXCHG0x Frontend Servers WebDAV + … IMAP, IMAPS (143,993) POP3, POP3S (110,995) HTTPS (80, 443) SMTP (25) mmm.cern.ch SMTP https http Imap(s), Pop(s) FireWall CERN.CH MAPI (135+…) CERNXCHG03 ISA RPC (135)

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Still some problems … PINE –Pine IMAP preauthentication will not work anymore People will have to type their passwords for the session –Pine 3.x does not see folders other than Inbox –Pine 3.x does not support IMAPS Outlook –Some attachments sent from pine are not seen in IMO (Q309493) –Addresses lists handling is very clumsy in Outlook 2002 –Offline access is slow when not used correctly Outlook Web Access –Rather slow over a modem –OWA delegated calendar only read (but not if admin rights!) Procmail –No clear upgrade for procmail apart for simple server side rules Exchange –Backup (or rather Restore) is complicated and difficult to automate –Currently every store is backed up mightly as a PST file But this does not scale Titanium may help –Defragmentation seems to be required (although does not free very much) and needs service interruption.

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Exchange 2000 user base 183 Exchange :05:12 PM - Tuesday, October 22, 2002

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Next Steps Migrate users from our oldest SUN –Users not willing to move will be migrated to another SUN Adapt registration tools to create new users in Exchange 2000 –Under way – first user done yesterday Devise a plan for global migration to Exchange 2000

CERN - European Organization for Nuclear Research HepIX - October 2002Frédéric Hemmer Summary For the user –Exchange 2000 could give opportunity to long outstanding requests: Mail, Calendar and more Web access to most of the features Does not rely on any particular client (browser >= 4) –and allowing group collaboration e-groups and “groupware” For IT –While taking into account the constant search for economy Maintenance/Server replacement at least 30% cheaper (per year) assuming users –And address manpower issues by consolidating on a platform that we have to support anyway reducing diversity requires less specialization mail expertise currently limited to two individuals could expand to 7-8 persons –as well as potential integration of other products/security features FAn opportunity for offering more services & coverage for a global reduced cost FEven better, end user feedback has been very positive