Re: outlook through a firewall

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Tim Hackbart [MSFT] (Timhack_at_online.microsoft.com)
Date: 09/10/04


Date: Fri, 10 Sep 2004 12:14:23 -0500

That is a good question.

Many companies, ISP's etc will block TCP Port 135 for security reasons.
Unfortunately there is no way to get OL2002, 2000, 98 to connect over the
internet with TCP Port 135.

So you will need to make sure you are fully patched on all your exposed
servers from Windows Update and then evaluate whether you want to expose
your servers at all.

I would really consider using OWA, or POP-IMAP-SMTP access if you can not
get all your clients to RPC over HTTPS

For more info, or just as a good resource check out
http://www.microsoft.com/technet/prodtechnol/exchange/default.mspx
and then the Security link
http://www.microsoft.com/technet/prodtechnol/exchange/2003/security.mspx

-- 
Tim Hackbart M.C.S.E.
This posting is provided "AS IS" with no warranties, and confers no rights.
Please do not send email directly to this alias. This alias is for newsgroup
purposes only.
"Mike C" <anonymous@discussions.microsoft.com> wrote in message
news:006f01c49756$8ad764d0$a401280a@phx.gbl...
> Thanks Tim for all of your help.  What about security
> concerns opening up port 135?
>
> Thanks again,
> Mike
>
> >-----Original Message-----
> >The KB was written for 5.5 servers, it sounds like you
> are either 2000 or
> >2003
> >
> >If you are running 2000 or 2003 you need to review
> >270836 Exchange 2000 and Exchange 2003 Static Port
> Mappings
> >http://support.microsoft.com/?id=270836
> >
> >-- 
> >Tim Hackbart M.C.S.E.
> >This posting is provided "AS IS" with no warranties, and
> confers no rights.
> >
> >Please do not send email directly to this alias. This
> alias is for newsgroup
> >purposes only.
> >
> ><anonymous@discussions.microsoft.com> wrote in message
> >news:87ad01c495fa$74b443b0$a301280a@phx.gbl...
> >> It does help, however, following that kb article (which
> >> I'd like to try), I don't have the
> >> HKLM\...\MSExchangeDS\Parameters.  I have a
> >> MSExchangeDSAccess (I think w/o checking) so I don't
> know
> >> if I should add it under here or create the MSExchangeDS
> >> key.
> >>
> >> Any help clearing this confusion is appreciated.
> >>
> >> Thanks,
> >> Mike
> >>
> >> >-----Original Message-----
> >> >It is possible to statically map your Store and
> Directory
> >> Service and then
> >> >open up the corresponding ports on your firewall.
> >> >
> >> >Please be aware that we also require TCP port 135 to be
> >> open as well for the
> >> >TCP End Point Mapper.  This port is commonly blocked by
> >> ISP's, firewall and
> >> >routers on the internet.  So even though you may have
> all
> >> your settings
> >> >correct your clients may not be able to connect from
> the
> >> internet.
> >> >
> >> >I would suggest internet friendly clients like Outlook
> >> Express and OWA for
> >> >your older stations.
> >> >
> >> >Hope this helps.
> >> >
> >> >-- 
> >> >Tim Hackbart M.C.S.E.
> >> >This posting is provided "AS IS" with no warranties,
> and
> >> confers no rights.
> >> >
> >> >Please do not send email directly to this alias. This
> >> alias is for newsgroup
> >> >purposes only.
> >> >
> >> >"Mike C." <anonymous@discussions.microsoft.com> wrote
> in
> >> message
> >> >news:872301c495ef$29af1940$a301280a@phx.gbl...
> >> >> Can I do this http://support.microsoft.com/?
> kbid=155831
> >> >> rather use rpc over http?  I have to support some 98
> and
> >> >> 2000 stations.
> >> >>
> >> >> Thanks,
> >> >> Mike
> >> >
> >> >
> >> >.
> >> >
> >
> >
> >.
> >


Relevant Pages

  • Re: TCP port 5000 syn increasing
    ... I have noticed the TCP port 5000's also, and I'm getting a fair amount from ... > Security Linux, the comprehensive security solution that combines six ...
    (Incidents)
  • Re: outlook through a firewall
    ... Mike ... security reasons. ... >internet with TCP Port 135. ... >Please do not send email directly to this alias. ...
    (microsoft.public.exchange.connectivity)
  • Re: how to close a port
    ... > I made a security checker in the security online cheker by Norton ... > inernet security, and in the result I got that my TCP port is open ... A port would be, for example, TCP port ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Windows 2003: Netstat results mention microsoft-ds
    ... I was just trying to figure out whether something I saw in the netstat results was a likely security concern. ... Microsoft-DS TCP port is TCP port 445. ...
    (microsoft.public.windows.server.security)