Re: Need instructions on setting up single-server OWA
- From: "Rich Matheisen [MVP]" <richnews@xxxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 01 May 2007 22:19:46 -0400
"Joe Grover" <grover.joe@xxxxxxx> wrote:
OWA should be installed and operational by default in an Exchange 2003
deployment, so all you need is to have the ports open on your firewall.
It is recommended to have the front-end or proxy server in a DMZ because you
wouldn't generally want port 80 on your Exchange server open to the whole
world. For this reason it is suggested that you install a SSL certificate
on the box and only open port 443 in your PIX. Your users will need to use
https://yourservername/exchange to access OWA. If any of them piss and moan
about having to use SSL you can assure them that such a minor inconvenience
is far more preferable than the downtime the server would have should it be
compromised by some new port 80 exploit. :)
How is HTTP (port 80) different to HTTPS (port 443) w/r/t exploits?
SSL only goes as far as the transport layer in the IP stack. By the
time it hits the application (not the application layer) it's the same
no matter what you used to encrypt the channel. The only thing HTTPS
does for you is to prevent snooping on the data sent over the wire and
part way up the IP stack.
An ISA server can act as an application layer firewall. It inspects
the contents of each packet. A "regular" firewall that doesn't
terminate the SSL connection can't see what's inside those encrypted
packets.
--
Rich Matheisen
MCSE+I, Exchange MVP
MS Exchange FAQ at http://www.swinc.com/resource/exch_faq.htm
Don't send mail to this address mailto:h.pott@xxxxxxxxxxxxx
Or to these, either: mailto:h.pott@xxxxxxxxxxxxxxx mailto:melvin.mcphucknuckle@xxxxxxxxxxxxx mailto:melvin.mcphucknuckle@xxxxxxxxxxxxxxx
.
- Follow-Ups:
- Re: Need instructions on setting up single-server OWA
- From: Joe Grover
- Re: Need instructions on setting up single-server OWA
- From: Joe Grover
- Re: Need instructions on setting up single-server OWA
- References:
- Re: Need instructions on setting up single-server OWA
- From: Joe Grover
- Re: Need instructions on setting up single-server OWA
- Prev by Date: Can I set up a rule for all mailboxes?
- Next by Date: Re: ActiveSync issues (one way sync) Treo 700w
- Previous by thread: Re: Need instructions on setting up single-server OWA
- Next by thread: Re: Need instructions on setting up single-server OWA
- Index(es):
Relevant Pages
|