Re: Can SSL version 3 be used on OWA 2003?



I agree there are a lot of ports open between the DMZ OWA IP and the internal network, so I could just put it internal and just have an outside to internal rule for 443 to this FE Exchange?

With ISA do I just have one Exchanege server then and publish this to the ISA?

"Mark Arnold [MVP]" <mark@xxxxxxxx> wrote in message news:7vpve3dfssh5isqehpbdl92hv6fd9ank0q@xxxxxxxxxx
On Tue, 18 Sep 2007 14:23:19 +0100, "Gonzo" <apollo13@xxxxxxxxxxxxxx>
wrote:

What's the problem with it on the DMZ? Should it be "inside"? I just have
port 80/443 open to it on the DMZ to it's external IP and NAT it to it's
iside DMZ IP, wouldn't this be just the same internally?

So, the self ssl isn't a problem. Loads of people have the old basic
self-signed jobbie.
The box should not be in the DMZ because of all the ports that need to
be open between DMZ and internal network. Look at your own rule set
and doesn't it make you concerned that you have ports open and
pointing to your GCs?
443 and 25 should be the only ones open. You have no need for 80 or
anything else. If you are uber-concerned about security then actually
not using a FE but instead putting an ISA in the DMZ and publishing
Exchange through that is even more secure.


.



Relevant Pages

  • [fw-wiz] Exchange 2003 OWA compromise reached
    ... Thanks to all for your answers to my questions regarding Exchange 2003 OWA. ... Since we also want to move our ftp server onto a separate DMZ away from our ... we will attach the Microsoft ISA server outside interface to the ...
    (Firewall-Wizards)
  • Re: Netzschema
    ... ich die DMZ weglasse. ... da OWA auch Exchange bedeutet und der braucht AD. ... Routinggruppe und dann verschluesselter SMTP Replikation, ... Weil der ISA macht ja bei der Installtion alle NICs dicht. ...
    (microsoft.public.de.german.isaserver)
  • Re: Netzschema
    ... wenn Du ein reines Mail Relay betreiben wuerdest, dann koennte man das mit der DMZ machen, zumal der Mailrelay dann auch noch Thirdparty Filter gegen SPAM haben koennte. ... Da Du aber OWA auch haben willst, wird das ganze etwas aufwaendiger, da OWA auch Exchange bedeutet und der braucht AD. ... Weil der ISA macht ja bei der Installtion alle NICs dicht. ...
    (microsoft.public.de.german.isaserver)
  • Re: How to deploy Microsoft OWA without using ISA?
    ... but we haven't deployed it in the DMZ yet. ... server on a perimeter leg in our DMZ via ISA2006 and couldn't be happier. ... allow everything through to your internal network, ... Other options ISA offers that you might like is the ability to perform HTTP ...
    (Focus-Microsoft)
  • Re: Protecting an Exchange server?
    ... >internal network and place some kind of email appliance on our DMZ to ... It's not an appliance, per se, but pretty close. ... >appliance out on the Internet and my Exchange server behind the firewall on ... the box on the DMZ. ...
    (Security-Basics)

Loading