Add new Exchange server behind a firewall to existing site



We have an existing Exchange system that consists on three Exchange
2003 servers distributed across our WAN (no internal port blocking).

The Exchange servers have been installed as a single Exchange site even
though they are geographically distrubuted..

I am looking to add a new Exchange server for a different part of our
company, but for security they are hidden behind an internal firewall
on their own LAN.

We have Windows 2003 domain controllers on either side of the firewall
and the ports have been opened to allow these to communicate.

My question is: What ports do we need to open if I install the server
on the Exchange site or on a different Exchange site.


* The servers will be sending internal email to each other.

* Client "may" need the ability to view each others calanders, but
typically they will only be opening their own mailbox on their own LAN
(ie not across the firewall)

* I am planning to route Internet email directly to/from the new email
server and not via the internal firewall and existing email servers.

Can anybody help?

I have a copy of MS article Q278339 listing ports used by Exchange 2000
server.... but I'm not sure if I require all of these and what should
talk to what.

.



Relevant Pages

  • Re: Tool to find hidden web proxy server
    ... policy for Internet access says it is through IP ... > default ports and distributed the internet access to their friends. ... - analyse the outgoing HTTP traffic through the firewall from those IP ... This will allow you to determine which servers ...
    (Pen-Test)
  • Re: How to host email using Exchange 2003
    ... > You Own SMTP Mail using Exchange 2000" and think the instructions will ... So their DNS your company is using is Internet "facing". ... record specific Emails servers. ... The ISP DNS servers will do the job of sending Internet mails out. ...
    (microsoft.public.exchange.setup)
  • Outbound Internet Mail
    ... We have a requirement to route outbound internet email from Exchange ... As a solution I have decided to build 2 Exchange BH servers and install ...
    (microsoft.public.exchange.design)
  • Add new Exchange server behind a firewall to existing site
    ... We have an existing Exchange system that consists on three Exchange ... The Exchange servers have been installed as a single Exchange site even ... What ports do we need to open if I install the server ... I am planning to route Internet email directly to/from the new email ...
    (microsoft.public.exchange.connectivity)
  • Re: OWA front end server in the DMZ
    ... > Exchange servers on your lan. ... You could narrow it down to about 8 ports ... > allowing it to attack other resources outside of AD, DNS, and Exchange ...
    (microsoft.public.exchange.design)