Re: Firewall issue? Can nobody help me?

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: john doe (nomail_at_nomail.com)
Date: 05/28/04


Date: Fri, 28 May 2004 09:20:21 -0400

Exactly.

"Ray" <reply_in@newsgroup.only> wrote in message
news:uFjbf2lQEHA.3476@tk2msftngp13.phx.gbl...
> I know you've heard of Code Red II and others. :-)
>
> Is it better to get a remote command prompt on a server on a DMZ that can
> only access certain internal boxes over certain ports and protocols
> (assuming you have an intelligent firewall that enforces the traffic on
the
> port and not just a port filter)?
>
> or
>
> Is it better to get a remote command prompt on a server on the LAN that
has
> unrestricted access to every other LAN device and the LAN authentication
> traffic?
>
> My vote is for the former if I'm a sysadmin and the latter if I'm a
hacker.
>
> Open ports are not "holes" that let just anything through, unless you use
a
> firewall that doesn't understand and enforce what should be running on a
> given port, like a PIX.
>
> Ray
>
> "Lanwench [MVP - Exchange]"
> <lanwench@heybuddy.donotsendme.unsolicitedmail.atyahoo.com> wrote in
message
> news:%23po1s66PEHA.3944@tk2msftngp13.phx.gbl...
> > Ray wrote:
> > > Well, you don't open things up to the LAN, you open only what is
> > > necessary and only you those hosts.
> >
> > As opposed to opening up only minimal ports to the FE server in the LAN
> (443
> > or 80)?
> >
> > >
> > >> By virtue of opening up all the necessary ports for communication
> > >> between FE/BE servers from DMZ to LAN & back again, you're really no
> > >> better off here.
> > >>
> > >>> I personally could care less for the DMZ and the ports necessary for
> > >>> this to work.
> > >>
> > >> Don't you mean you *couldn't* care less? :-)
> > >>>
> > >>> "Lanwench [MVP - Exchange]"
> > >>> <lanwench@heybuddy.donotsendme.unsolicitedmail.atyahoo.com> wrote in
> > >>> message news:%23DWowDpPEHA.1644@TK2MSFTNGP09.phx.gbl...
> > >>>> john doe wrote:
> > >>>>> Typically yes, the front end server should be in a DMZ.
> > >>>>
> > >>>> I respectfully disagree - you have to open up so much between DMZ
> > >>>> and LAN that it effectively renders the DMZ useless. I put FE
> > >>>> servers behind the firewall, lock them down tightly, open up port
> > >>>> 443 to that internal IP only for OWA...
> > >>>>
> > >>>>> It would tell
> > >>>>> you right of the bat if it was your server or the network
> > >>>>> connectivity. "Jim Rodgers" <jim.rodgers@bataviatrans.com> wrote
> > >>>>> in message news:fc1501c43e85$0cc90690$a301280a@phx.gbl...
> > >>>>>> No, I have not taken the server out of the DMZ to see if
> > >>>>>> that would solve the problem; I was under the
> > >>>>>> understanding that this setup is the right way to go;
> > >>>>>> should the front end server be in the DMZ or not?
> > >>>>>> What way is right?
> > >>>>>>
> > >>>>>>
> > >>>>>>
> > >>>>>>> -----Original Message-----
> > >>>>>>> Have you tried removing the server from the DMZ to see if
> > >>>>>> that solves the
> > >>>>>>> problem?
> > >>>>>>> "Jim Rodgers" <jim.rodgers@bataviatrans.com> wrote in
> > >>>>>> message
> > >>>>>>> news:fa8e01c43e5c$b6578980$a001280a@phx.gbl...
> > >>>>>>>> OK - I've asked this question before and nobody ever
> > >>>>>> seems
> > >>>>>>>> to respond, so I'll try once again.
> > >>>>>>>>
> > >>>>>>>> Here's my layout:
> > >>>>>>>> W2K3 Domain <two domain controllers> <approx 1200 users>
> > >>>>>>>> EX2K3 Backend server hosting approx. 800 mailboxes
> > >>>>>>>> EX2K3 Front End server in DMZ
> > >>>>>>>>
> > >>>>>>>> It seems that all works flawlessly for several hours,
> > >>>>>> then
> > >>>>>>>> for who knows what reason, the Front End
> > >>>>>> servers "Messages
> > >>>>>>>> awaiting directory lookup" queue goes into "retry" state
> > >>>>>>>> and then a couple dozen messages queue up in the
> > >>>>>>>> C:\ProgFiles\Exchsrvr\Mailroot\vsi 1\Queue folder.
> > >>>>>>>> It seems that this inability to communicate causes
> > >>>>>>>> messages to queue up for a few minutes (10-15?) but any
> > >>>>>>>> new messages coming in or out will go right on thru.
> > >>>>>>>> When that queue reaches it's retry time, those messages
> > >>>>>>>> waiting in the queue go on out as they should.
> > >>>>>>>> If that were as severe as it ever gets, I guess I could
> > >>>>>>>> live with it, but it seems as though sometimes (every
> > >>>>>>>> second or third time or so) it gets even worse where the
> > >>>>>>>> System Manager won't even load and then things are just
> > >>>>>>>> totally dead until I stop all the Exchange services and
> > >>>>>>>> then restart them. After that, things work fine again
> > >>>>>> for
> > >>>>>>>> a while (few hours) then I can expect it to happen
> > >>>>>> again.
> > >>>>>>>>
> > >>>>>>>> If anybody can give me ANY clues on what I can check or
> > >>>>>>>> modify, I can't tell you how much I would appreciate it.
> > >>>>>>>>
> > >>>>>>>> Thanks in advance.
> > >>>>>>>> Jim Rodgers
> > >>>>>>>> jim.rodgers@bataviatrans.com
> > >>>>>>>>
> > >>>>>>>
> > >>>>>>>
> > >>>>>>> .
> >
> >
>
>



Relevant Pages

  • Re: Can only connect to local RWW, over internet cannot
    ... This if from my working LAN. ... I am testing this tool from my own lan and says 4125 port is closed, ... It has a hardware sonicwall firewall. ... move to the server. ...
    (microsoft.public.windows.server.sbs)
  • RE: Some technical errors
    ... If the SMTP server is not running on port 25 TCP it is not a public ... Manager - Computer Assurance Services BDO Chartered Accountants & ...
    (Security-Basics)
  • Re: SRV RRs support in Internet Explorer?
    ... The port number could be implicit (i.e. ... At any point in time, a server could fail ... can't effectively LB or backup because NSs cache the records for the TTL ... I still don't see how SRV records would help backup or LB. ...
    (microsoft.public.win2000.dns)
  • Re: DNS Server Name
    ... You should NOT have port 80 forwarded to anything on your LAN. ... I would enable NetBIOS over TCP/IP since the single NIC should be your LAN ... When you run the CEICW, on the Web Server Certificate page, you should enter ... telnet SBSserverNetBIOSname 25 ...
    (microsoft.public.windows.server.sbs)
  • Re: Still cant connect to RWW or OWA remotely
    ... I get 'cannot find server or dns error' on both ... TCP [port number]> to open the ports. ... As for error messages when I fail to access RWW with the laptop, ... network, no connection seems possible. ...
    (microsoft.public.windows.server.sbs)