RSS Subscription 168 Posts and 2,769 Comments

Exchange 2010 Site Resilience, Multiple DAG IPs, and Cluster Resources

Exchange 2010 allows us to have Database Availability Group (DAG) members in several AD Sites.  For every subnet a DAG member’s MAPI NIC is in, we must obtain a DAG IP.  This DAG IP is a separate IP than is located on the MAPI NICs themselves. We take this DAG IP to the DAG using the Set-DatabaseAvailabilityGroup command.

Multiple DAG IPs

Let’s take a look at an example of how the architecture may look.

Taking a look at the above Visio diagram, we have two sites, Primary Site and DR Site, with one node in each.  The MAPI NIC in the Primary Site has an IP Address of  That means that we’ll need to have a DAG IP that lives in this same subnet.  We choose a DAG IP of  The MAPI NIC in the DR Site has an IP Address of That means that we’ll need to have a DAG IP that lives in this same subnet.  We choose a DAG  IP of

In order to add these MAPI IP Addresses, we’ll need to run the following the command.

Note: IPs on Replication NIC’s subnet do not get added to the Database AvailabilityGroupIPAddresses. Only MAPI NIC Subnets get added.

Keep in mind, when adding additional IPs in the future, it is important that you include all existing DAG IPs.  The Set-DatabaseAvailabilityGroup -DatabaseAvailabilityGroupIPAddresses property is not additive.

To verify the DAG IPs were added successfully, let’s check out our DAG Properties.

In Exchange 2010 SP1, we have the ability to add our DAG IPs via the GUI. If we go to the DAG Properties, we now see we can manage our Witness Server and Alternate Witness Server.

This allows us to do our IP Address configuration right from the GUI instead of needing to use Set-DatabaseAvailabilityGroup  with the DatabaseAvailabilityGroupIPAddresses property and needing to worry about all previous IP Addresses being included since the property isn’t additive.

Cluster Resources

So, let’s take a look at what really happens to the cluster resources and what determines which DAG IP is active.  Let’s open the Failover Cluster Manager.  Start > Administrative Tools > Failover Cluster Manager.

After selecting our DAG, let’s take a look at the cluster resources.  We can see from here that we have two Network IP Resources.

But let’s take even a deeper look.

Select the DAG from within the Cluster Core Resources > Right-Click > Choose Properties.

Now let’s take a look at the Dependencies Tab.

As we can see, the two DAG IPs are set up with an OR dependency which means that the cluster can activate either DAG IP at any given time.  As we saw earlier, the IP is the existing DAG IP that is online which means the DRSiteNode’s DAG IP is currently the online Network IP resource.

Let’s run a cluster command so we can failover the default “Cluster Group” from one cluster node to another.

We now see the PrimarySiteNode is the node that has the “Cluster Group.”  Let’s go ahead and take a look at the Cluster Resources again and see which Network IP Resource is online.

Looks like the PrimarySiteNode’s DAG IP is now Online instead of the DRSiteNode’s DAG IP.  This means that the Network IP Resource that is online depends on which DAG Node has the “Cluster Group.”  If you recall from my previous articles, the DAG Node that has the “Cluster Group” is the DAG Node that acts as the Primary Active Manager.  The Primary Active Manager is the DAG Node responsible for choosing what databases get activated in a failover.  For more information on Active Manager, click here.


44 Responses to “Exchange 2010 Site Resilience, Multiple DAG IPs, and Cluster Resources”

  1. […] Exchange 2010 Site Resilience, Multiple DAG IPs, and Cluster Resources | Elan Shudnow’s Blog Posted on September 27, 2010 by johnacook… […]

  2. on 01 Oct 2010 at 7:49 amChris Lehr

    Good article. The cluster.exe command needs to be documented more. However, your article starts with a MAPI and a DAG network, and then your DAG networks only cover/address one of the networks you started the article with.

  3. on 10 Nov 2010 at 6:42 amJohnson

    I was searching for this document. Thanks alot for the explanation.

  4. on 03 Jun 2011 at 2:03 amTariq.Muhammad

    Nice posting…… this is helpful document……. Thanxxxxs.

  5. on 09 Jul 2011 at 5:47 amadmin2010

    Thanks for the article. I would like to know that the MAPI NIC ip is belongs to the LAN network and Replication NIC is belongs to the heartbeat???? File sharing option should be enabled on heartbeat connection or not???

  6. on 05 Aug 2011 at 6:35 pmElan Shudnow

    Well in Exchange 2010 both NICs do heartbeating. In fact, the Exchange 2010 documentation wants you to ACL the network so MAPI NIC on Node A cannot talk to MAPI NIC on Node B to prevent any heartbeat crosstalk. Here is a good article on NIC configuration:

  7. on 18 Jul 2011 at 2:09 amGuest

    Nice, this is a real good article and saved lot of my time…Excellent work.

  8. on 14 Aug 2011 at 2:03 amIan Salgado

    Hi, I refer u to your diagram above

    Are the 2 Nic for MAPI & Replication 2 different physical NIC’s?



  9. on 15 Aug 2011 at 6:48 amElan Shudnow

    Ian, they are two different physical NICs. One Physical NIC for the MAPI Network and a separate Physical NIC for the Replication NIC.

  10. on 16 Aug 2011 at 12:45 amIan Salgado

    Hi Elan,

    Thank You for your quick response.

    On the MAPI NIC – Obvisouly traffic between the different MAPI connections needs to be open, right ? so that mail flow can occur.


    1. Does this network segment needs to be SEPARATE FROM the MAPI NIC segment ? ie: &
    2. Again all traffic between DAG member on this REP-NIC's will need to be open ?

    Thank You



  11. on 16 Jan 2012 at 5:31 amMOahmed

    Now i have previous DAG should i create new dag to the DR or Branch site or add th DR site Mailbox to the primary site dag.

    Thank You


  12. on 16 Jan 2012 at 8:20 amElan Shudnow

    Without knowing much about your business requirements and what the conceptual design is, it's hard to be definitive. But typically, if you have a Primary Site and a Failover Site you would use the same DAG for both locations so you can replicate databases from Server in Primary Site to Server in Failover Site.

  13. on 18 Jan 2012 at 2:00 amMohamed

    Thank you very Much Elan

  14. on 18 Jan 2012 at 2:19 amMohamed

    So Elan im starting get confused let me tell you what i have


    Domain 2008

    Cas Array 2010 using WNLB.

    HUB on 2 server's Using Fail-over.

    DC1 all ready installed on it certificate after reading information i think will need to buy new San certificate hold primary and secondary site names also auto discovery.

    the Second DC2
    i think i will do the followin ti apply Active Passive Scenario wit the same name

    Install Additional A.D In the Second Data-center.
    add database copy from the primary Data center to the second Data Center ……. here now
    i will run this command

    Set-DatabaseAvailabilityGroup -DatabaseAvailabilityGroupIPAddresses [ Primary Dag IP only !!!!! ]

    that what i think only one DAG with one witness share …… that wht i understand from you

    so what i do next

    thank you


  15. on 26 Jan 2012 at 12:11 pmLuis Chavez

    Thanks Elan, Excellent Article really this is helpful document.

  16. on 29 Feb 2012 at 8:35 amConfluence: Exchange 2010

    Questions for Bill…

    Exchange 2010 questions WMWare rosala: After some further investigation I want to suggest we consider turning on DRS and leaving it in manual mode…….

  17. on 01 Mar 2012 at 5:05 amSean O'Farrell

    Super post. Thanks.

  18. on 25 Jul 2012 at 5:24 pmAdrian

    So if I have a three node DAG across two subnets and I have NOT configured multiple DAG IP's is my configuration incorrect?

  19. on 25 Jul 2012 at 9:08 pmElan Shudnow

    Not necessarily. If no IP Addresses are entered, it will use DHCP to obtain a cluster IP for each segment just as long as DHCP is available to on the same subnet that hosts the MAPI IPs. Many environments don't have DHCP on the subnets. Since your DAG is working, it sounds like DHCP is available. But while it may be available for the MAPI Network that is hosted in one site, it may still not be available in the other site that hosts that MAPI Network.

    I typically assign static IPs.

  20. on 26 Jul 2012 at 3:57 pmAdrian

    Thanks Elan, here is my setup with single DAG IP set statically. Will I need to set multiple DAG IP Addresses?

    server1 at site A IP address: and GW
    server 2 at site A IP Address and GW
    server 3 at site B IP Address and GW

  21. on 26 Jul 2012 at 4:37 pmElan Shudnow

    Site B is a different network. Therefore, you need one DAG IP in the subnet located at Site A and another DAG IP in the subnet located at Site B. The way it's set up right now is potentially incorrect. The reason I say potentially is the same as the reason I gave in my previous comment to you.

  22. on 07 Aug 2012 at 5:55 amprakash

    Hi Elan

    my self facing a prob OWA am unable to delete move search the mail.. but in outlook it was fine
    we r running windows2008R2 with exchange 2010sp1 updated rollup1…but on that day on wards am facing these probs

  23. on 24 Sep 2012 at 8:22 amJazManUni

    Hi Elan,
    I f I have a small site of 2000 users, I want to have 2 cas/hub servers in 1 cas array and 2 additional mailbox servers in DAG can I put the FSW on one of the CAS/HT servers?
    Is there an issue putting the FSW on a cas array member?
    Alternatively, if I create a third mailbox server instaed will this be overkill for 2000 users?
    Thanks for your help

  24. on 26 Sep 2012 at 9:55 pmElan Shudnow

    Sure, you can have a FSW on a HUB/CAS. In fact, if you don't manually designate a specific server/share for the FSW, a HUB Server in the same site will automatically be chosen to put the FSW on that HUB in C:\. If you had a separate HUB Server and a separate CAS Server, you could also choose to put it on a CAS.

    I would honestly be reluctant to tel you adding a third server would be overkill. It depends on your business requirements in regards to data retention, high availability, DR, etc… But in simple fashion, a single server can easily handle 2000 users if you spec it to have the necessary cpu, memory, and disk requirements.

    And by the way, I would opt to deploy multi-role servers with a hardware load balancer. I'm not a fan of separation of roles. Either is Microsoft.

  25. on 04 Oct 2012 at 1:42 pmJames

    Hi Elan

    I think I have this almost figured out. I just have two questions. I have 2 mailbox servers in subnet A and both are members of DAG1. I am adding a 3rd mailbox server in subnet B. Do I add the DAG Ip address for subnet B then add the third server to the DAG? or add the server to the DAG and then add the subnet B address to the DAG. Second question, do I add the subnet B DAG IP to DNS? We use Netbackup which does query DNS for the DAG IP address.

  26. on 06 Oct 2012 at 6:46 amElan Shudnow

    Add the DAGIP beforehand. You do not need to manage DNS manually for your DAG. When the DR Server becomes the Primary Active Manager (Default Cluster Group is on DR DAG Server), DNS is updated to point to that Cluster IP. But, clients don't connect to that Cluster IP like they did in Exchange 2007. They connect to the CAS Server's RPC Client Access FQDN which then makes the appropriate MBX connections.

  27. on 17 Jul 2013 at 12:44 pmRusty Shackleford

    If the DAG is running from production site then the DAG Name IP address will be registered in DNS (such as However, the disaster recovery site DAG IP ( will not be registered in DNS. However, how do I prevent other hosts (and administrators) from using the IP address I entered in the DAG properties for the disaster recovery site ( Thank you kindly.

  28. on 19 Jul 2013 at 7:08 amElan Shudnow

    A DAG still creates a Network Name and Network IP Resource in the cluster. If a cluster fails over, DNS is updated and the DAG Cluster IP for the second site is brought online.

  29. on 19 Jul 2013 at 12:16 pmRusty Shackleford

    Currently, if I ping our DAG (, I will get a reply and host name, such as….
    Pinging [] with 32 bytes of data:
    Reply from bytes=32 time<1ms TTL=128

    However, if I ping the secondary site DAG IP address it does not reply and does not provide a hostname, such as…..
    C:Users…..>ping -a

    Pinging with 32 bytes of data:
    Request timed out.

    I certainly understand that the ping to the second IP address would not reply but I am concerned that no hostname is provided either. If another adminstrator is building an unrelated server in that subnet they could grab and assign it to their server. The other adminitrator would not think anything of it because there is no name or ping reply are associated with and assign it to their server. The other adminitrator would not think anything . All is well until I fail over the DAG.

    Any suggestions how to prevent someone or something else from grabbing the secondary site IP address when the DAG is hosted in the primary site?

    As always, thank you for sharing your knowledge with us.

  30. on 08 Oct 2012 at 2:06 amAdrian

    Hi James, we use arcserve r16 and when backing up the DAG it's best to use the DAG DNS name although you can use IP addresses or HOSTS file when backing up pre-prod DAG via a production backup server.

  31. on 11 Dec 2012 at 3:38 pmConfluence: IT

    Provisioning uk-virt0…

      4GB USB Stick Software Requirements: bootable ES…

  32. on 11 Jan 2013 at 11:56 pmVarun

    Hi, we hv the same simillar setup that ha shown above in diagram. We hv problem whenever network Links to DR unstable then the entire cluster is unstable and all exchange DB's are getting dismounted and getting mounted.. is there any way we can configure all servers in production within cluster and DR shld be used only for replication.

  33. on 31 Mar 2013 at 9:01 amElan Shudnow

    There can only ever be 1 MAPI Network. The DAG chooses the NICs that are configured to register in DNS and have a valid DNS record. All the replication NICs need to have DNS registration disabled. If multiple NICs are registering in DNS, that can potentially cause the DAG to have some issues.

    For proper NIC/Network configuration, see the following link:

  34. on 30 Mar 2013 at 12:05 pmNate

    Varun had an excellent question which has sadly remained unanswered. I am experiencing the exact same issue as Varun, and would like to know if there is anything that can be done about it.

    Any response at all would be greatly appreciated.


  35. on 31 Mar 2013 at 9:01 amElan Shudnow

    I responded to Varun. Hope that information helps.

  36. on 03 Apr 2013 at 2:14 amGanesh

    Hi Elan,

    Nice Article..

    I have a query here, i have site A and Site B and streched DAG members, i dont want database to automatically failover to site b server even if site a server is down. I want only DB & Logs to be copied to another site server.


  37. on 09 Jul 2013 at 8:32 amRick

    Great Article Elan,
    One question for you as I am current setting up this senerio with exchange 2010 Sp1. 2 mailbox servers in subnet A , 2 hub/cas servers in subnet A and a 3rd mailbox server in subnet B. Subnet A is in one AD site and subnet B is in another AD site, will the above still work in my situation? I just want a copy of the DB's off site , clients would still access the hub/cas servers in site A which is hardware load balanced.

    Thanks in advance for your time and the fantastic article!.

  38. on 11 Jul 2013 at 6:44 amElan Shudnow

    Yes, this is the way it's supposed to work. The Mailbox Servers all would be in the same DAG but the offsite Mailbox Server for Site Resilience would be in another subnet which would be assigned another site. Then when you go through the DR procedures and you need to take down the DAG in SiteA/SubnetA, you would specify the SiteA site when removing those DAG members. Then you switchover to that 3rd Mailbox Server.

  39. on 02 Oct 2013 at 2:48 amHGowda

    I have 4 questions.

    1. I ran command as you mentioned (cluster group "cluster group" /move)
    in my environment it is not getting changed to PrimarySiteNode, instead it choosing another node in the DR.

    2. I have three AD sites (single DAG), do i have to provide three IP's from each production NICs for a DAG.

    3. Will they get register in DNS (with DAG name) automatically, or do i have to register them manually?

    4. I guess those IPs should respond to ICMP, if i ping it from my network. ( in my case not pinging)

  40. on 30 Nov 2014 at 10:51 amSteven


    I know this is an old post, I'm sorry to bother you, but I have a quick question. I added a 3rd IP address to my DAG to facilitate moving of passive servers to a new data center. The Set-DatabaseAvaliabilityGroup command worked without issue. I can see all the IPAddresses in both EMS and EMC, but I don't see it in the failover cluster manager.

    I'm not sure if maybe one of the nodes must come online in the other site, but was hoping you may have some input.

    Let me know. Thanks.


  41. on 09 Dec 2014 at 9:51 amSingh

    Hi Elan,

    We have a DAG environment with 4 DAG members in site A and 4 DAG members in site B, we were having only single IP address assigned to DAG which lives in Site A subnet, now as per the article above we had assigned an additional IP to DAG which lives in Subnet of Site B.

    Now the additional IP is only visible in EMC under DAG properties on IP address tab.
    But it is not visible in Failover cluster manager, only existing IP address is visible.

    Any idea what else can be done to fix this.

  42. on 31 Mar 2015 at 9:58 amDrBCG

    What about the DAG´s DNS name? Should I add a record to point the DNS name to DR IP address?

  43. on 13 May 2015 at 7:27 amElan Shudnow

    You don't have to do this. The Clustering Service will take care of all this during the DAG creation process or the failover process.

  44. on 13 May 2015 at 7:38 amSteven

    True dynamic DNS will take care of it. I think the only exception is if you've configured static DNS records. There were some issues with W2k8 dropping DNS records so there are cases where people elected to go static. Those issues were hot-fixed at some point.

Trackback this post | Feed on Comments to this post

Leave a Reply