Verify that your organization meets the prerequisites for each scenario. The prerequisites are listed in the procedures for each scenario.
Verify that the account that you use to perform these procedures has the required administrative group memberships:
-
To create an Exchange 2007 Send connector, the account you use must be delegated the Exchange Organization Administrator role.
-
To create an Exchange 2007 Receive connector, the account you use must be delegated the Exchange Server Administrator role and local Administrators group for the server on which you will create the Receive connector.
For more information about permissions, delegating roles, and the rights that are required to administer Exchange Server 2007, see Permission Considerations.
Exchange 2007 to Exchange 2007
In this scenario, you create the cross-forest connectors between the Hub Transport servers in two Exchange 2007 organizations that are located in separate Active Directory forests. Basic authentication or external authentication mechanisms provide authentication and authorization between the servers in different forests. If you use Basic authentication, you can select from the following two methods to also use Transport Layer Security (TLS):
-
Set the smart host authentication method to Basic authentication requires TLS. This method provides both confidentiality and authentication of the receiving server. If you select this smart host authentication method, the sending server will validate the certificate of the receiving server as a requirement for mail flow.
-
Set the RequireTLS parameter to
$True. This method provides confidentiality, but does not authenticate the receiving server.
To configure a cross-forest connector between the Hub Transport servers in two Exchange 2007 organizations, you must meet the following prerequisites:
-
Each forest must have an Exchange organization with Exchange 2007 servers.
-
If you use Basic authentication, a domain account must exist in each forest to use for Basic authentication. For example, provide a user account that has the universal principal name (UPN) FourthCoffee@Contoso.com as the credentials that must be used for authentication by the Exchange servers in the Fourth Coffee domain when mail is sent to the Exchange servers in the Contoso domain.
-
If you use Basic authentication over TLS, the target server must be configured to use an X.509 certificate that contains an FQDN that is the same as the FQDN of the Receive connector.
-
If you use external authentication, a trusted network connection must exist between the Hub Transport servers. This connection may be an IPsec association, virtual private network, or the servers may reside in a trusted physically controlled network.
To establish mail flow between the forests, follow these steps:
-
Create a user account in each forest to use for authentication to the receiving server in the second forest.
-
Create a Send connector.
-
Set permissions on the Send connector.
-
For externally secured connectors, create a new Receive connector.
Note: |
|---|
|
If you are using Basic authentication over TLS, you must provide the FQDN of the remote Hub Transport server in the smart host settings. You cannot use an IP address.
|
The following procedure establishes cross-forest mail flow between the Exchange 2007 Hub Transport servers in the Contoso.com and FourthCoffee.com forests. You must perform the reciprocal procedure in each forest.