Exchange 2007 & Edge Server
When running the Best Practices Analyzer on my Exchange 2007 I receive the error that my EDGE server Registry cannot be accessed. This is a brand new installation of Exch 2007 - and my Edge server is not on the domain. Both servers are running Windows 2008 Standard with all updates. The error I am receiving is listed below.
Cannot connect to the registry on server EDGE. This could be the result of a network or permissions problem. Error: Security error.THanks for the assistance!
Scott
July 14th, 2009 10:18pm
As this machine is not part of the domain, I believe this is expected behavior. If you want ExBPA results from the Edge server you can run it locally from the Edge server's EMC.
Mike Crowley A+, Network+, Security+,
MCT, MCSE, MCTS, MCITP: Enterprise Administrator / Messaging Administrator
Free Windows Admin Tool Kit Click here and download it now
July 15th, 2009 6:13am
EXBPA looks for Domain and EDGE is not part of Domain so that is the reason you are getting that error. Have EXBPA run from EDGE local server.
Vinod
|CCNA|MCSE 2003 +Messaging|MCTS|ITIL V3|
July 15th, 2009 1:24pm
Vinod, Thank you for repeating what I have already stated.... on several posts...
Mike Crowley A+, Network+, Security+,
MCT, MCSE, MCTS, MCITP: Enterprise Administrator / Messaging Administrator
Free Windows Admin Tool Kit Click here and download it now
July 15th, 2009 5:33pm
Hi,
I agree with Mike. It is an expected behavior. Let me explain more:
When we run ExBPA on internal servers, we are using the domain (admin) account. When ExBPA trying to connect to edge WMI service and/or Remote Registry service, domain admin account is used. As edge is not a member of the domain, the domain admin account is not trusted, access is denied.
So please ignore this alert in ExBPA.
Regards,
Xiu
July 16th, 2009 10:53am
Hi,Base on my research,the error could be fixed. We can follow the steps in articlebelow to solve the problem.
This Exchange server is down or unreachable
http://technet.microsoft.com/en-us/library/aa998683.aspxRegards,Xiu
Free Windows Admin Tool Kit Click here and download it now
September 7th, 2009 12:52pm
Well, yes you can open the firewall and ports to allow it to be reachable, but this erodes away at the point of having an isolated server in the first place. I do not believe the reduction in security is worth the convenience of running exbpa. Not when you can gather the same information from the server locally.
Mike
Crowley A+, Network+, Security+, MCT, MCSE, MCTS, MCITP: Enterprise
Administrator / Messaging Administrator
Do you still have Exchange 2000? Looking to upgrade to Exchange 2010? Read how.
September 7th, 2009 4:53pm