Formula una domandaFormula una domanda
 

Con rispostainstall question

  • giovedì 26 novembre 2009 9.53Shahin Medaglie utenteMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utente
     
    Hi,

    I have a question regarding where to install the forfront security for exchange,

    we have a new network, with ISA 2006 and Exchange 2010, we did install the CA role mail box Role,... on a server and then Install Edge transport role on the same server as ISA 2006, now we want to install the forfront for Excahnge as wel.
    Can some one tell me that where is the best location to install it? should we install it on the exchange server or on the ISA server that has Edge Transport server on it.

    Thanks,

    Shahin
    Shahin

Risposte

  • martedì 1 dicembre 2009 9.52Christian Groebner [MVP]MVPMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utente
     Con risposta
    Hi Nick,

    I prefer to install FPE 2010 on all machines (hub transport and mailbox). On the edge (TMG) I do all the antispam and av-scanning with maximum bias settings and on the mailbox servers I do only av-scanning with neutral bias settings and different av-engines. So this is in my eyes the best thing you can do to get a maximum of security.

    With TMG you can easily manage the egde-role and FPE 2010.

    Greetings

    Christian
    Christian Groebner MVP Forefront
    • Contrassegnato come rispostaShahin martedì 1 dicembre 2009 11.09
    •  

Tutte le risposte

  • venerdì 27 novembre 2009 7.03Nick Gu - MSFTMSFT, ModeratoreMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utente
     

    Hi,

     

    Thank you for the post.

     

    As far as I know, You cannot install ISA Server 2006 on 64-bit versions of Windows Server. So it is impossible to install ISA with Exchange 2010. But you can subscribe the Edge Transport server installed on Forefront TMG. For more information, please refer to the following link.

     

    http://technet.microsoft.com/en-us/library/dd897094.aspx

     

    Regards,


    Nick Gu - MSFT
  • venerdì 27 novembre 2009 8.18Shahin Medaglie utenteMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utente
     

    Hi Nick,

    Thanks for your info,

    my mistake, we did install the TMG instead of ISA 2006, I did also install the Edge Transport on the TMG server, but the Question is where to install the Forfront Security 2010  on the Hub Transport server or on the server that has edge (on TMG) Server?

    Thanks,

    Shahin


    Shahin
  • venerdì 27 novembre 2009 10.25Nick Gu - MSFTMSFT, ModeratoreMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utente
     

    Hi,

     

    Thank you for the update.

     

    You can deploy FPE 2010 on any role of the Exchange server(Hub Transport or Mailbox).

     

    Regards,


    Nick Gu - MSFT
  • venerdì 27 novembre 2009 11.30Shahin Medaglie utenteMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utente
     
    Hi Nick,

    I understand I can install it on the HUB Transport or Mailbox, normally the HubTransport and Mailbox are on the same server, in our network is Hub Transport and Mailbox both are on the same server, but I want to know in the case of Edge Transpoert rule that is installed on the TMG, where is the best place to install FPE 2010?


    Shahin
    Shahin
  • martedì 1 dicembre 2009 9.44Nick Gu - MSFTMSFT, ModeratoreMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utente
     

    Hi,

     

    Thank you for the update.

     

    I think you may install FPE 2010 on the all the roles of the Exchange Server. And you may refer to the following link.  

     

    http://blogs.technet.com/fss/archive/2009/11/12/fpe-11-0-rtm-capacity-planning-guidance.aspx

     

    Regards,


    Nick Gu - MSFT
  • martedì 1 dicembre 2009 9.52Christian Groebner [MVP]MVPMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utenteMedaglie utente
     Con risposta
    Hi Nick,

    I prefer to install FPE 2010 on all machines (hub transport and mailbox). On the edge (TMG) I do all the antispam and av-scanning with maximum bias settings and on the mailbox servers I do only av-scanning with neutral bias settings and different av-engines. So this is in my eyes the best thing you can do to get a maximum of security.

    With TMG you can easily manage the egde-role and FPE 2010.

    Greetings

    Christian
    Christian Groebner MVP Forefront
    • Contrassegnato come rispostaShahin martedì 1 dicembre 2009 11.09
    •