The most common method of distributing engine and definition updates is to use UNC updating where one Exchange server (the redistribution server) downloads updates from the Microsoft HTTP server and then hosts those updates for the rest of the Exchange servers in your environment (the receiving servers). After the redistribution server downloads an update, any receiving server whose update path points to the redistribution server can download the updates from the redistribution server.
Note: |
---|
UNC updating is the only supported method for redistribution. Also, antispam updates can only be downloaded from the Exchange Edge and Hub roles. |
Configuring servers to receive and distribute updates
Before distributing updates, you must configure both the distributing server and receiving servers.
To configure servers to receive and distribute updates-
To prepare a server to act as an update redistribution server, you need to establish a Windows share for its Engines folder. For information about the location of the default Engines folder on your operating system, see Default folders.
-
On the chosen server, enable the redistribution server functionality, and optionally set up UNC authentication user credentials:
- In the Global Settings - Engine Options pane, in the
Additional Options section, select the Enable as an
update redistribution server check box, and then click
Save.
This configures FPE to save the two most recent engine update packages instead of the usual single engine package. FPE also downloads the full update package rather than performing an incremental update. The multiple engine packages enable the receiving servers to continue pulling updates from the redistribution server while a new update is being downloaded.
- Optionally, create UNC authentication user credentials. It is
recommended that you use credentials with the minimum privileges.
These should not be domain credentials, and the user should only be
granted access to the share.
- In the Global Settings - Engine Options pane, in the
Additional Options section, select the Enable as an
update redistribution server check box, and then click
Save.
-
Configure each receiving server to point to the shared folder:
- In the Global Settings - Engine Options pane, in the
UNC Authentication section, to enable UNC updating, select
Enable UNC.
- Optionally, click Edit UNC Credentials in order to
display a dialog box where you can specify your UNC authentication
user credentials. After specifying your credentials, click
OK and then click Save.
- In the Global Settings - Advanced Options pane, in the
Intelligent Engine Management section, using the Engine
management drop-down list, select Manual.
- In the Update scheduling section, select the engines and
then click the Edit Selected Engines button.
- In the Edit Selected Engines dialog box, in the
Primary update path field, enter the redistribution server's
UNC path (\\ServerName\ShareName).
Note: The use of static IP addresses within the update path is not recommended or supported. Also note that you can enter the Microsoft download location in the Secondary update path field. Then, if updating by means of the redistribution server fails, the latest updates can still be retrieved from Microsoft by using the secondary update path. - Click Apply and Close to return to the Global
Settings - Advanced Options pane, and then click
Save.
- In the Global Settings - Engine Options pane, in the
UNC Authentication section, to enable UNC updating, select
Enable UNC.
Example: Server Ex1 downloads its updates automatically from the Microsoft HTTP server. Ex1 has FPE installed in the following location:
C:\Program Files(x86)\Microsoft Forefront Protection for Exchange Server
You have created a share, called AdminShare, which begins at the Engines folder. Another server, Ex2, receives its updates from Ex1 by using the following primary update path:
\\Ex1\AdminShare