Re: OWA in DMZ

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Your suggestion isn't any cheaper than ISA and I believe compromizes your
security substantially by opening ports that allow malware access into your
AD and security infrastructure. Just configuring the required firewall
entries alone should be enough to make your head spin. Installing an
Exchange 2003 server in your DMZ is tantamount to militarizing it.

ISA or another web publishing appliance is the way to go.
--
Ed Crowley
MVP - Exchange
"Protecting the world from PSTs and brick backups!"

"RichardW" <helpdesk@xxxxxxxx> wrote in message
news:O0$MWzCqHHA.2652@xxxxxxxxxxxxxxxxxxxxxxx
There's a lot of ways to do this. Some people will go to the extreme with
mutiple Firewalls and ISA.
But I guess the easiest and relatively secure method is setting up a
seperate Exchange server in the DMZ in Front-End mode. It will not contain
any mailboxes, it'll just function as OWA server.

Configure the Firewall to forward external HTTPS (don't use
HTTP!!)requests to this sever in the DMZ. And configure the Firewall to
allow traffic on certain ports between this server and the private
network, since that's where the back-end server is located with the actual
mailboxes. There's a couple of ports you need to open. Or just allow any
port but only between Front-End and Back-End server, although this is
less-secure.

When you have this Front-End server in place with OWA you can also use
this same server for Mobile Access, and RCP over HTTPS, which you will
have to enable on both servers and it involves more TCP ports.

A good place to start is here, which also descibes the ports needed.
http://www.microsoft.com/technet/security/prodtech/exchangeserver/secmod44.mspx

You can go to lengths with securing something like this, but it depends on
the situation and risk assement to determine how far you really want to
take it. I wouldn't use anything less then wat I described here, so this
is kind of a baseline.


"Frederik" <Frederik@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:40E1389C-E9F0-4472-9DB0-66C0F0949CC5@xxxxxxxxxxxxxxxx
Hello,

In our company we have one exchange mailserver and a DMZ-zone. We would
like
to enable the outlook web access in this DMZ-zone. So the users should
connect to a pc in the DMZ zone and not to the exchange mailserver.

What's the best way to install this?

Maybe RPC over HTTP?


Thanks




.



Relevant Pages

  • Re: LISTENING, ESTABLISHED, CLOSE_WAIT TCP Ports & UDP Ports?
    ... properties of a process and it will show you what tcp/ip ports and services ... Beyond that I suggest you read the Windows 2003 Server Security Guide to see ...
    (microsoft.public.windows.server.security)
  • Re: What ports to open on firewall?
    ... Internet to Marshall and Exchange should talk with DNS server that it uses. ... Internet should be opened, if DNS Server is external, then DNS ports to DNS ...
    (microsoft.public.exchange.admin)
  • Re: What ports to open on firewall?
    ... In my LAN-->WAN, all outgoing ports are open, my exchange server is in my LAN which we use internal DNS servers. ... My issue is when I NAT, I need to know what ports to I need to NAT so the receippient server can reverse lookup, validate sender... ...
    (microsoft.public.exchange.admin)
  • Re: Source Code to Filter out WindowsMessenger POP-UPS
    ... > time to get the details I did get about the ports and none ... It does not act as a relay server - at least ... To that I will just add that REAL security - ... > port 80 inbound ...
    (microsoft.public.inetserver.iis.security)
  • Re: How to access exchange through a firewall?
    ... The SBS server was an afterthought I suppose, ... There is no "bunch of ports" required.... ... Exchange isn't constantly grabbing them from their hosting provider I ... Don't know what you mean by the users POP connectors - there's one POP ...
    (microsoft.public.exchange.admin)