Network Configuration/Bandwidth Planning Scope



Similar documents
Client Operating System and Applications Scope

Service Desk Readiness

User identity, Account Provisioning, Directory Synchronization, Federation

Microsoft Premier Deployment. Office 365 Service Description

Microsoft Lync Server 2010

Module 6. Designing and Deploying External Access. MVA Jump Start

Deployment Guide for Enterprises

Setup Guide: Server-side synchronization for CRM Online and Exchange Server

Mod 2: User Management

Migrate to Microsoft Online Services

Before you begin with an Exchange 2010 hybrid deployment Sign up for Office 365 for an Exchange 2010 hybrid deployment... 10

Dell One Identity Cloud Access Manager How to Configure Microsoft Office 365


Mod 3: Office 365 DirSync, Single Sign-On & ADFS

Exchange Server Hybrid Deployment for Exchange Online Dedicated

Redelegate your domain to Office 365

Before you begin with an Exchange 2010 hybrid deployment Sign up for Office 365 for an Exchange 2010 hybrid deployment... 10

MS Configuring, Managing and Troubleshooting Microsoft Exchange Server 2010

Introduction to the EIS Guide

MCSE SYLLABUS. Exam : Managing and Maintaining a Microsoft Windows Server 2003:

MOC 5047B: Intro to Installing & Managing Microsoft Exchange Server 2007 SP1

Build Your Knowledge!

Office 365 deployment checklists

Office 365 from the ground to the cloud

70-662: Deploying Microsoft Exchange Server 2010

Hybrid Architecture. Office 365. On-premises Exchange org (Exchange 2007+) Provisioned via DirSync. Secure Mail flow

Managing Office 365 Identities and Services 20346C; 5 Days, Instructor-led

Office 365 deploym. ployment checklists. Chapter 27

10135A: Configuring, Managing, and Troubleshooting Microsoft Exchange Server 2010

Course 20346: Managing Office 365 Identities and Services

Digital certificates and SSL

MICROSOFT EXAM QUESTIONS & ANSWERS

Managing Office 365 Identities and Services

Configuring, Managing and Troubleshooting Microsoft Exchange Server 2010 Service Pack 2

Course Syllabus. 5053A: Designing a Messaging Infrastructure using Microsoft Exchange Server Key Data. Audience. At Course Completion

Network Configuration Settings

Configuring, Managing and Troubleshooting Microsoft Exchange Server 2010 Service Pack 2

Configuring, Managing and Troubleshooting Microsoft Exchange Server 2010 Service Pack 2

Introduction to Mobile Access Gateway Installation

Managing Office 365 Identities and Services

Owner of the content within this article is Written by Marc Grote

Microsoft Office 365 from Vodafone. Administrator s Guide for Midsize Businesses and Enterprises

Microsoft Office Communications Server 2007 R2

Course Syllabus. About the course. Audience. At Course Completion. Microsoft Lync 2013 Depth Support Engineer. Certification Exams:

Configuring, Managing and Troubleshooting Microsoft Exchange Server 2010 Service Pack 2

Workshop purpose and objective

Configuration Guide. BES12 Cloud

Proxies. Chapter 4. Network & Security Gildas Avoine

Module 4. Planning and Designing Load Balancing

Technical Brief for Windows Home Server Remote Access

Configuring, Managing and Troubleshooting Microsoft Exchange Server 2010 Service Pack 2

QUESTION 1 You deploy a server that has the Exchange Server 2013 Mailbox server role and Client Access server role installed.

MOC 20342B: Advanced Solutions of Microsoft Exchange Server 2013

Configuring Managing and Troubleshooting Microsoft Exchange Server 2010

How To Plan A Desktop Workspace Infrastructure

Microsoft Office Web Apps Server 2013 Integration with SharePoint 2013 Setting up Load Balanced Office Web Apps Farm with SSL (HTTPS)

MICROSOFT OFFICE 365 MIGRATION 2013/05/13

Road2Master Office 365 Hybrid Deployment and Migration Part 1 - Introduction. Ashwin Venugopal

MICROSOFT CERTIFIED SYSTEMS ENGINEER Windows 2003 Track

Exchange Deployment Options: On-premises, cloud, or hybrid? Jeff Mealiffe Principal Program Manager Microsoft

Accenture Company Limited

MS Configuring, Managing and Troubleshooting Microsoft Exchange Server 2010 Service Pack 2

Identity for Enterprises. Service Description

Support for Apple Mac and ios Devices

BlackBerry Enterprise Server for Microsoft Office 365 preinstallation checklist

MS-10135: Configuring, Managing and Troubleshooting Microsoft Exchange Server Course Objectives. Price. Duration. Methods of Delivery

10533A: Deploying, Configuring, and Administering Microsoft Lync Server 2010

Technical Brief ActiveSync Configuration for WatchGuard SSL 100

Course 10135A: Configuring, Managing and Troubleshooting Microsoft Exchange Server 2010

MS 10135B Configuring, Managing and Troubleshooting Microsoft Exchange Server 2010

Microsoft Lync Server Overview

50573: Premier Support for Lync Partners Tier 2. Sobre o curso. Microsoft - Servidores

Statement of Work Office 365 Migration. Gateway Unified School District

NEC Hong Kong Ltd. I. Service Category (A) Productivity Apps


Configuration Guide. BlackBerry Enterprise Service 12. Version 12.0

Outline SSS Microsoft Windows Server 2008 Hyper-V Virtualization

This course is intended for IT professionals who are responsible for the Exchange Server messaging environment in an enterprise.

F-Secure Messaging Security Gateway. Deployment Guide

Load Balancing Microsoft Exchange Deployment Guide

Microsoft Dynamics CRM 2013 Service Provider Planning and Deployment Guide

DocAve for Office 365 Sustainable Adoption

Deploying F5 to Replace Microsoft TMG or ISA Server

Configuration Guide BES12. Version 12.3

Installation and Deployment in Microsoft Dynamics CRM 2013

Designercity (HK) Ltd.

Microsoft Dynamics CRM 2011 Installation and Deployment

Office 365. Migrating and Managing Your. Business in the Cloud. Matthew Katzer. Don Crawford

Extend your Exchange On Premises Organization to the Cloud

DEPLOYMENT GUIDE Version 2.1. Deploying F5 with Microsoft SharePoint 2010

Configuration Guide BES12. Version 12.1

Deploying the BIG-IP System with Microsoft Lync Server 2010 and 2013 for Site Resiliency

Configuration Guide BES12. Version 12.2

INSTALLATION AND DEPLOYMENT IN MICROSOFT DYNAMICS CRM 2013

Architecture and Data Flow Overview. BlackBerry Enterprise Service Version: Quick Reference


Software Assurance E-Learning

Microsoft Designing and Deploying Microsoft Exchange Server 2016

Web Security Firewall Setup. Administrator Guide

Migrating Exchange Server to Office 365

Transcription:

Network Configuration/Bandwidth Planning Scope

Workshop Focus and Objective Workshop Focus Drive key planning considerations for Office 365 domain and domain name service (DNS) records configuration Network bandwidth and latency Network ports and protocols, and Secure Sockets Layer (SSL) certificates Objectives Plan configuration of internal and external (Internet-facing) DNS records Plan configuration of testing efforts to make sure name resolution is functioning properly Plan to provide the appropriate Internet bandwidth for the services selected and for the migration activities Understand and plan for specific ports and protocols to be accessible to support the use of online services and migration tools Plan for use of third-party SSL certificates to help secure customer s Office 365 deployment 2

Network Configuration and Bandwidth Planning Workshop Topics Domain re-delegation External DNS and thirdparty SSL certificates Ports, protocols, and firewall considerations WAN accelerators, hardware and software load balancing, Reverse Proxy Network topology, bandwidth, and latency Review steps and capture activities to configure Office 365 domain settings Review steps and capture activities to configure external DNS records with custom domain Review steps to properly configure connection to Office 365 Review physical networking infrastructure configuration and supportability for connectivity to Office 365 Review existing network capacity and layout to determine capacity needs for mail migration and run-state 3

Domain Re-delegation Review steps and activities to configure Office 365 domain settings Workshop participants and outcomes Participants Technical Lead (AD DS) Technical Lead (Network) Preparation Public-Facing SharePoint Online Confirm Services Outcome Document plan to ensure customer's domain is properly registered and aligned with appropriate Online Services 4

Preparation Review steps for domain name registration with Office 365, including policies for multiple domains, ensuring ownership of the custom domain, and how to add a domain Registered domain name is required (can be scripted if multiple domains. TXT is required) Verify sign-in credentials are known at domain name registrar Multiple domain considerations Add and verify domain by: The Add your domain wizard The Microsoft Online Services Modules for Windows PowerShell A Windows PowerShell cmdlet Follow-up actions and additional information from prior assessments Service Enablement Plan Document steps (if applicable) for acquiring the domain name if one is not already established Document plan for adding and verifying domain [List specific issues uncovered or context from prior assessments] 5

Confirm Services Review and confirm the Office 365 Services that are in scope for the custom domain name Available services: Microsoft Exchange Online Microsoft Lync Online Microsoft SharePoint Online for configuring SharePoint Online public-facing websites Follow-up actions and additional information from prior assessments Service Enablement Plan Document which Online Services will be configured with a custom domain name Review and document approach if SharePoint Online website is to be public facing and use the same custom domain [List specific issues uncovered or context from prior assessments] 6

Ports, Protocols, and Firewall Review steps to properly configure organization s network connection to Office 365 Ports and Protocols Firewall Workshop participants and outcomes Participants Technical Lead (Network) Proxy Device Outcome Document plan to enable network access to Office 365 7

Ports and Protocols Protocol/ Port TCP 443 TCP 25 TCP 587* TCP 5223 Applications AD FS (federation server role) AD FS (proxy server role) Microsoft Online Services Portal My Company Portal Microsoft Outlook 2010 and Outlook 2013 Microsoft Outlook 2011 for Mac Outlook Web App SharePoint Online Lync 2010 client and Lync 2013 client (communication to Lync Online from on-premises Lync Server) Mail routing Simple Mail Transfer Protocol (SMTP) Relay Lync Mobile Client Push notifications Protocol/ Port TCP 143/993 TCP 995** TCP 80 and 443* PSOM/TLS 443 STUN/TCP 443 STUN/UDP 3478 RTC/UDP 50000-59999 Applications Simple IMAP4 migration tool POP3 Windows Azure Active Directory Synchronization Tool Simple Exchange Migration Tool Simple IMAP Migration Tool Staged Exchange Migration Tool Exchange Management Console Exchange Management Shell Lync Online (outbound data sharing sessions) Lync Online (outbound audio, video, application sharing sessions) Lync Online (outbound audio and video sessions) Lync Online (outbound audio and video sessions) *SMTP Relay with Exchange Online requires TCP port 587 and requires TLS. See TechNet for details on how to configure SMTP Relay with Exchange Online. Note: you will need to provide the SMTP server which is specific to the mailbox used for relay. See the TechNet article Set Up Outlook 2007 for IMAP or POP Access to Your E-Mail Account. **POP3 access with Exchange Online requires TCP port 995 and requires SSL. See TechNet for details on how to configure POP3 with Exchange Online. Denotes optional Service Enhancement features 8

Firewall Review network capability for standard DNS lookups. Determine if location of target Microsoft Online Services data center requires firewall configuration to accept connections based on wildcard domain names. Computers on the network must be able to perform standard Internet DNS lookups. Depending on the location of Microsoft Online Services data center, network firewall devices must be configured to accept connections based on wildcard domain names. Note: Microsoft data center IP addresses are subject to change at any time. Office 365 does NOT notify customers of IP address range changes. Recommendation: Configure wildcard namespaces on the firewalls. Follow-up actions and additional information from prior assessments Service Enablement Plan Document firewall configuration approach [List specific issues uncovered or context from prior assessments] 9

Proxy Device Review current proxy configuration and capture required configuration changes to allow for connectivity to Office 365 services Microsoft recommends that traffic bound for Office 365 bypass proxies. Most proxy servers are scaled for casual, single client connection browsing. Outlook can open 3-20 sustained HTTPS connection per workstation On-premises outgoing Internet proxy settings also affect connectivity to Office 365 services for client applications Suggest excluding Office 365 URL s/ip s using PAC files to send Office 365 traffic to Firewall. Configure firewall to allow exceptions to Office 365 IP s Follow-up actions and additional information from prior assessments Service Enablement Plan Document proxy device configuration approach [List specific issues uncovered or context from prior assessments] 10

WAN Accelerators Review Microsoft s current support model around WAN Accelerators WAN Accelerators are not supported by Microsoft. Support may ask that WAN acceleration be temporarily turned off during troubleshooting Many customers use WAN Acceleration successfully, some WAN Accelerators have partnerships with Microsoft that spoof certificates, examine payload, optimize traffic. Partnerships with content delivery networks. Follow-up actions and additional information from prior assessments Service Enablement Plan Document proxy device configuration approach [List specific issues uncovered or context from prior assessments] 11

Hardware Load Balancers and Reverse Proxy Hardware Load Balancers (HWLB) are the preferred mechanism to allow high availability of ADFS, ADFS Proxy, Hybrid Review Hardware Load Balancing, Reverse Proxy, Security Requirements Microsoft ISA, UAG, and TMG are end-of-life products, mainstream support ends in April 2015 Microsoft Windows 2012 R2 provides Application Proxy for most Microsoft products, still requires HWLB for best use Most customers have moved to Load Balancers providing multiple capabilities including reverse proxy. Be careful with modules Life in a Post TMG World Is It As Scary As You Think? Follow-up actions and additional information from prior assessments Service Enablement Plan Document proxy device configuration approach [List specific issues uncovered or context from prior assessments] 12

Bandwidth and Latency Bandwidth for migration. Depends on method Hybrid vs. staged Outlook re-sync Bandwidth, migration and steady state Latency and client location Bandwidth steady state: Workloads, Lync, SharePoint, Exchange Capture peak utilization on all exchange servers Add peak exchange utilization to internet access utilization Derive peak bandwidth requirements per site Latency effects Outlook client and cached mode SharePoint file upload scenarios Lync sharing, voice, video Follow-up actions and additional information from prior assessments Service Enablement Plan Capture current peak utilization for existing legacy systems, Derive bandwidth based on peak utilization per site and look for weak spots where congestion could occur 13

Questions? 2013 Microsoft Corporation. All rights reserved. Microsoft, Access database software, Active Directory directory service, ActiveSync technology, ActiveX controls, Excel spreadsheet software, InfoPath information gathering program, Internet Explorer Internet browser, Lync communications software, Office 365 hosted productivity software, OneNote note-taking program, Outlook 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or messaging and collaboration client, PowerPoint presentation software, RoundTable communications and archival system, SharePoint services, SQL Server software, Windows operating system, other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must Windows Azure technology platform, Windows Intune software and services, Windows Server operating system, and Windows Vista operating system and other product names are or may be respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION