Cloud Relay Solution Whitepaper
Abstract Cloud-based email is an attractive solution for organizations looking to provide optimum email service for their users at predictable costs. However, cloud-based email services may fall short in the areas of archiving and ediscovery, recovery, and data ownership, and may not meet the needs of the organization, leaving IT administrators scrambling for a solution. Barracuda Message Archiver with Barracuda Cloud Relay provides an easy and secure way to archive mail from cloud-based email services. This innovation gives organizations a secure conduit from their cloud email provider to a local archive stored on their network. Unlike methods involving pulling mail from cloud email services using POP or IMAP, Cloud Relay is not susceptible for throttling by the email service providers. In addition, the service is secure, thus preventing the archiver from being targeted by spammers. Cloud-Based Email Challenges Organizations facing pressure to reduce hardware, licensing, and labor costs are deploying cloud-based email services such as Microsoft Office 365 and Google Apps. These cloud services appeal to small and medium-sized organizations that can easily switch their spending for email from capital expenditures to operational expenditures. The move to cloud-based email solves frequent challenges that administrators face with a local email system such as backup and recovery, availability, storage growth, security, and power and cooling. However, cloud-based email has its own set of challenges including archiving and ediscovery, granular recovery, and data ownership. When organizations add features like archiving to their cloud-based email service, it can add complexity and costs. Disabled or shared mailboxes may add to the per-user cost, and bandwidth restrictions may affect how quickly data can be exported from the cloud and available for ediscovery. In addition, migrating large amounts of on-premises data to a cloud archiving service may be a prohibitively long process, further complicating the migration to the cloud service. Migrating to the Cloud Careful planning is crucial to mitigating the challenges associated with migrating to cloud-based email service and archiving. Some organizations will choose to migrate all of their email -- including archives -- to the cloud, while others may choose to continue running both their on-premises email server and cloudbased email service side-by-side and gradually transition to the cloud. Migration of local email to the cloud provider can be a long and painful process because it depends on the version and type of email server, the amount of users and data to be migrated, as well as connectivity to the cloud data center. This process can lead to outages and end-user confusion. Using an on-premises archive is an effective way to switch to cloud-based email services, as it allows organizations to get the best of both worlds: historical emails are preserved on the archiver while new email traffic is transitioned to the cloud. When choosing an archiving product for this task, it is important to make sure that the chosen product can also support ongoing email archiving directly from the new cloud service. This way, a unified archive can then be maintained going forward. Barracuda Message Archiver Simplifies Migration to the Cloud The Barracuda Message Archiver is designed to preserve and index emails for long periods of time, while reducing the amount of storage used and providing end users with complete access to their email at all times. Organizations can deploy the Barracuda Message Archiver to import all on-premises historical and current mail through journaling, mail-server import and PST collection. After an import is complete, email is deduplicated and compressed to ensure optimal storage utilizations. Administrators can then cut over to their cloud-based email solution with little change to how their end users access email. End users are able to access all current and historical email as they did before, using the Barracuda Message Archiver Outlook add-in, mobile apps, or web-based search interface.
E-mail can be imported onto the Barracuda Message Archiver before migration. Mail imported is deduplicated and indexded for quick search and recovery. With a local copy of all archived mail, administrators, compliance teams, legal teams, and auditors can quickly search the Message Archiver for both historical and real time email. Barracuda Message Archiver provides speedy search and retrieval of emails and attachments. Legal holds can be easily implemented with no user impact while offering the ability to easily search the held emails or export them to a PST or the Barracuda Copy file sync and share service. Organizations with a Barracuda Message Archiver have complete ownership of their email and can retrieve individual emails that have been deleted past the default retention of the cloud-based email service. Additionally, large amounts of email data can be exported from the Barracuda Message Archiver to an end user or someone needing to perform additional searching. Barracuda Cloud Relay Most cloud-based email services provide customers with message archiving functionality, but this functionality may introduce additional costs and may not address all requirements. Barracuda s Cloud Relay is an easy and secure way to archive mail from cloud-based email services to on-premises Barracuda Message Archiver. It is available to all Barracuda Message Archiver customers at no additional cost. With Cloud Relay, there is no need to pull messages from the cloud email service, which may be subject to throttling by the email service and may require opening ports on the firewall. Instead, email is journaled directly from the cloud service to the Barracuda Cloud Relay, and then securely sent to the on-premise Barracuda Message Archiver. In addition, Cloud Relay allows organizations to queue some amount of email to help prevent loss of email in case of problems with either the cloud service or the internal network. Email sent to the onsite appliance indexed and deduplicated, thus increasing storage efficiency. This process adds no overhead to the cloud service or the Barracuda Message Archiver. Mail is journaled and sent to Barracuda Cloud Relay Mail is queued in Barracuda Cloud Relay and sent to local Message Archiver Corporate Firewall using port 2500 While cloud-based email solutions may provide some ways to migrate email to their services (although the process can still be complicated and lengthy), they do not make it easy to migrate away from their services. As an organization grows or requires more control over their environment, they may look at moving away from a cloud-based solution leading to the task of migrating away from the solution. Migration from these services can be very Mail is received, deduplicated, and indexed for quick search and recovery. costly and time consuming, and may lead to months or years of maintaining subscription to the service while moving historical mail from the hosted solution to an on-premises solution or another provider.
By deploying a Barracuda Message Archiver, organizations can easily cut over to a new email service without worrying about exporting and importing historical email to a new system. The Barracuda Message Archiver stores all email in non-propriety format for easy access and no vendor lock in. How to configure the Barracuda Cloud Relay Step 1. Open Port 2500 on your Corporate Firewall Mail journaled for compliance purposes on Office 365 is sent to the Barracuda Cloud Relay Service on port 25. The Barracuda Cloud Relay Service then sends the mail to your Barracuda Message Archiver on port 2500. Port 2500 must be open inbound on your corporate firewall to allow journaled mail to be sent to the local Barracuda Message Archiver. Step 2. Configure Barracuda Message Archiver Forwarding 1. To allow messages from the Cloud Relay allow listening of port 2500 on Barracuda Message Archiver. 2. Log in to the Barracuda Message Archiver as an administrator, and go to the MAIL SOURCES > SMTP tab. 3. Turn on Enable SMTP Forwarding, and type 2500 in the Additional Listening Ports field. 4. Click Add, and then click Save Changes to add port 2500: Step 3. Create a Non-Delivery Report Recipient Before creating journal rules, specify a journal recipient for non-delivery reports (NDRs) to reduce the risk of losing journal reports. The mailbox you configure to receive NDR receipts should not be subject to other mail rules, otherwise it may prevent journaling from occurring. Contact your Office 365 Technical Support if you have questions or need additional information. To create an NDR recipient: 1. Navigate to Compliance Management > Journal rules 2. Select address 3. In the NDRs for undeliverable journal reports window, click Browse 4. Select a recipient from the address book. You can search for a recipient by typing all or part of a display name, and then clicking the Search icon, or click on either the Display Name or E-Mail Address heading to sort the list. 5. Click OK once you select a recipient, and in the NDRs for undeliverable journal reports window, click Save.
*When creating the journaling rule, depending on your Office 365 configuration, you may be required to send the journaling report to an external email address. For more information, refer to the Microsoft Office 365 community discussion board: http://community.office365.com/en-us/f/158/t/162118.aspx Step 4. Configure Office 365 to Send Journal Mail Verify the following: You have the custom address and token specific to your Barracuda Message Archiver provided to you by Barracuda Networks Technical Support * You have your WAN IP address where you want the journal mail sent A Public WAN IP address accepts journal email on the specified port (default port 2500) A rule on the firewall to route port 2500 traffic to the Barracuda Message Archiver The Barracuda Cloud Relay Service cannot accept your journal mail traffic until Barracuda Support indicates that the Relay Service has been configured for your account. *Set up the journaling mailbox using the external address for the Barracuda Cloud Relay Service based on the custom token received from Barracuda Networks Technical Support, for example, journaling@uuid. bma.cudasvc.com. 1. Navigate to Compliance Management > Journal rules 2. Select + button in Journal rules 3. In the New Journal Rule dialog box, complete the following: - Send journal reports to: Email address provided by Barracuda Support - Name: Define name for rule - If the message is sent to or received from: Apply to all messages - Journal the following messages: All messages 4. Save the rule. Mail will start being journaled to the Barracuda Cloud Relay. For Google Apps please follow this tech library solution. https://techlib.barracuda.com/bma/ DeployGAppsCloudRelay
Conclusion With the Barracuda Message Archiver with Cloud Relay, organizations can dramatically simplify their migration to a cloud-based email service while ensuring continuous access to data, email portability and no vendor lock-in. Barracuda customers benefit from a fixed yearly cost for support and updates and do not need to worry about shared, disabled or added mailboxes. With an on-premises appliance, organizations benefit from redundancy in the case of a cloud outage as well as long-term search capabilities. To learn more about Barracuda s web security solutions, please visit www.barracuda.com/products or call Barracuda for a free 30-day evaluation at 1-408-342-5400 or 1-888-268-4772 (US & Canada). About Barracuda Networks, Inc. Protecting users, applications, and data for more than 150,000 organizations worldwide, Barracuda Networks has developed a global reputation as the go-to leader for powerful, easy-to-use, affordable IT solutions. The company s proven customer-centric business model focuses on delivering high-value, subscription-based IT solutions for security and data protection. For additional information, please visit www.barracuda.com. Barracuda Networks 3175 S. Winchester Boulevard Campbell, CA 95008 United States 408-342-5400 888-268-4772 (US & Canada) www.barracuda.com info@barracuda.com