Re: Can SSL version 3 be used on OWA 2003?



On Tue, 18 Sep 2007 14:23:19 +0100, "Gonzo" <apollo13@xxxxxxxxxxxxxx>
wrote:

What's the problem with it on the DMZ? Should it be "inside"? I just have
port 80/443 open to it on the DMZ to it's external IP and NAT it to it's
iside DMZ IP, wouldn't this be just the same internally?

So, the self ssl isn't a problem. Loads of people have the old basic
self-signed jobbie.
The box should not be in the DMZ because of all the ports that need to
be open between DMZ and internal network. Look at your own rule set
and doesn't it make you concerned that you have ports open and
pointing to your GCs?
443 and 25 should be the only ones open. You have no need for 80 or
anything else. If you are uber-concerned about security then actually
not using a FE but instead putting an ISA in the DMZ and publishing
Exchange through that is even more secure.

.



Relevant Pages

  • RE: Firewalling with a webserver and DB
    ... But the DB on the internal network. ... only allow port 80 into your DMZ IF all you have are ... As clients computers will use these ports dynamically to talk to ... Firewalling with a webserver and DB ...
    (Security-Basics)
  • Re: Setting up 2 domains with one way trust to dmz
    ... What you refer to as the client ports are probably due to the RPC ... why does the DMZ exist? ... a batch process gets started that will survive the accounts logoff. ... I have no problem with the server ports its the client ports that I ...
    (microsoft.public.security)
  • Re: Outbound ports
    ... >> public web server sitting in my DMZ. ... Destination Port 80 outbound ... >> blocking outbound on all but those ports could prevent traffic from ... >> infecting other machines on the internet. ...
    (comp.security.firewalls)
  • Re: [fw-wiz] I wonder, how to test..
    ... This will give you a picture of the ports that you are exposing. ... > measures to make our buisiness secure. ... > locked down, are in DMZ, only http permitted, SQL on inside via data ... > environment is colocated, office is connected via PIX to PIX vpn, ...
    (Firewall-Wizards)
  • Re: SKY USERS
    ... When you set the default DMZ to a non existant IP on the LAN the ... ports register as being stealthed and open if you don't. ... firewall, & I get the anomalous results from all sites mentioned in ...
    (uk.telecom.broadband)