Category:XTRANET: Difference between revisions
No edit summary |
Add YouTube video summaries and fix broken video embeds (HTML5video -> EmbedVideo) |
||
| (2 intermediate revisions by one other user not shown) | |||
| Line 4: | Line 4: | ||
==Training on Xtranet Project KT. Dated 17 May 2024 - Tetra Support Staff - Alok Singh== | ==Training on Xtranet Project KT. Dated 17 May 2024 - Tetra Support Staff - Alok Singh== | ||
{{#ev:youtube|wgrp1MqsdFE|640}} | |||
'''Video summary:''' Another architecture session for the same MPSDC/XTRANET Zimbra deployment covered elsewhere on the wiki (see the "MPSDC (XTRANET)" page), this one focused on mail flow and network segmentation rather than the OS/version upgrade. Inbound mail lands first on Trend Micro IMSVA (email security/AV scanning) before reaching the two active-active MTA nodes, then the mailbox pair (active-passive cluster, shared storage) and archive server. A load balancer sits in front of the MTA pair for webmail access so a single MTA failure is transparent to users. User authentication is via Active Directory (AD account required for every Zimbra login, integrated directly rather than Zimbra's own local auth). The distinct content here is the network design: servers are split across an Internet-facing zone, a DMZ zone (MTA + Trend Micro, firewalled), and a protected "MZ" zone (mailbox, archive), with a full list of ports that had to be explicitly requested from the client's separate network team to open between zones (389 for LDAP auth, 22, 53/DNS, 514/syslog, plus the standard Zimbra service ports). Also covers connecting to the client's data center via Array Networks' "Motion Pro" VPN client. | |||
==Training on Service-tea-training-1-xtranet-compliances. Dated 30 May 2024 - Tetra Support Staff - Biswajit Banerjee== | |||
{{#ev:youtube|Y6bRDcQijeg|640}} | |||
'''Video summary:''' Interactive team training session ("Service Team Training 1: Xtranet compliances") led for junior engineers (Kasim, Takshay, Manish, Alok), using the Xtranet/MPSDC government tender as a worked example of how compliance documentation works on government projects. Explains that government tenders list specific technical compliance requirements (e.g. "must have mail," "must have archiving") that have to be proven point-by-point with a compliance sheet, supporting documentation, and screenshots/URLs as evidence -- illustrated using Xtranet's own compliance spreadsheet and mail-flow architecture diagram (Trend Micro AV gateway -> two MTAs -> clustered mailbox -> archive server, AD-authenticated, load-balanced). The bulk of the session then turns into general teaching about multi-server Zimbra deployments -- the difference between a single-server all-in-one Zimbra install versus splitting LDAP, MTA, proxy, and mailbox onto separate servers, why certain components (like the antispam/antivirus engine) must live specifically on the MTA and not the mailbox server, and quizzing trainees on what an MTA and a proxy component actually do -- referencing other real deployments (Infosys, NFC) as further multi-server examples. | |||
Latest revision as of 02:53, 25 July 2026
Training on Xtranet Project KT. Dated 17 May 2024 - Tetra Support Staff - Alok Singh[edit]
Video summary: Another architecture session for the same MPSDC/XTRANET Zimbra deployment covered elsewhere on the wiki (see the "MPSDC (XTRANET)" page), this one focused on mail flow and network segmentation rather than the OS/version upgrade. Inbound mail lands first on Trend Micro IMSVA (email security/AV scanning) before reaching the two active-active MTA nodes, then the mailbox pair (active-passive cluster, shared storage) and archive server. A load balancer sits in front of the MTA pair for webmail access so a single MTA failure is transparent to users. User authentication is via Active Directory (AD account required for every Zimbra login, integrated directly rather than Zimbra's own local auth). The distinct content here is the network design: servers are split across an Internet-facing zone, a DMZ zone (MTA + Trend Micro, firewalled), and a protected "MZ" zone (mailbox, archive), with a full list of ports that had to be explicitly requested from the client's separate network team to open between zones (389 for LDAP auth, 22, 53/DNS, 514/syslog, plus the standard Zimbra service ports). Also covers connecting to the client's data center via Array Networks' "Motion Pro" VPN client.
Training on Service-tea-training-1-xtranet-compliances. Dated 30 May 2024 - Tetra Support Staff - Biswajit Banerjee[edit]
Video summary: Interactive team training session ("Service Team Training 1: Xtranet compliances") led for junior engineers (Kasim, Takshay, Manish, Alok), using the Xtranet/MPSDC government tender as a worked example of how compliance documentation works on government projects. Explains that government tenders list specific technical compliance requirements (e.g. "must have mail," "must have archiving") that have to be proven point-by-point with a compliance sheet, supporting documentation, and screenshots/URLs as evidence -- illustrated using Xtranet's own compliance spreadsheet and mail-flow architecture diagram (Trend Micro AV gateway -> two MTAs -> clustered mailbox -> archive server, AD-authenticated, load-balanced). The bulk of the session then turns into general teaching about multi-server Zimbra deployments -- the difference between a single-server all-in-one Zimbra install versus splitting LDAP, MTA, proxy, and mailbox onto separate servers, why certain components (like the antispam/antivirus engine) must live specifically on the MTA and not the mailbox server, and quizzing trainees on what an MTA and a proxy component actually do -- referencing other real deployments (Infosys, NFC) as further multi-server examples.