Re: OWA front end server in the DMZ



"Al Mulnick" <amulnick_No_SPAM@xxxxxxxxxxx> wrote in message
news:%23zP4yp$pFHA.748@xxxxxxxxxxxxxxxxxxxxxxx
> Pretty much you just open all ports from the FE server to the AD, DNS, and
> Exchange servers on your lan. You could narrow it down to about 8 ports
> and protocols, but at that point why bother? May as well just allow TCP
> 443 all the way to the trusted network FWIW. Of course, if you leave OWA
> in a DMZ, you do limit some of the traffic that machine can get to by not
> allowing it to attack other resources outside of AD, DNS, and Exchange
> servers.
>
> Have you considered what ISA can do for you?
>
> As for a white paper, see the FE/BE information at
> http://www.microsoft.com/exchange/library
>
> Al
>
>
> "Tim Gordon" <tim@xxxxxxxxxx> wrote in message
> news:7sHOe.37$hR5.2@xxxxxxxxxxxxxxxxxxxxxxx
>> Hi,
>>
>> Quick question: We are currently running Exchange 2003 Enterprise inside
[snipped quoted]

Thanks Al,

Can't really consider ISA. This is at a site that is secured by another
party and any changes to the firewalls I must run past them in advance -
hence my post.

Tim

--
I never wish I was not what I was not when I didn't wish what I was not was
not what I am not.


.



Relevant Pages

  • Re: Problem sending email out of Exchange 2003
    ... My problem was resolved last night when it was found that Exchange was not ... referring DNS queries to SBS but instead had been given specific DNS ... Exchange SMTP was no longer able to query these servers. ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange cant send email to one of the domains
    ... Specifying the smarthost as the remote mail exchanger won't be considered ... Exchange will route the message to this BH server and deliver the message to ... DNS, ... Most mail servers have no problem sending messages via SMTP ...
    (microsoft.public.exchange.admin)
  • Re: Exchange cant send email to one of the domains
    ... Specifying the smarthost as the remote mail exchanger won't be considered ... Exchange will route the message to this BH server and deliver the message to ... DNS, ... Most mail servers have no problem sending messages via SMTP ...
    (microsoft.public.exchange2000.connectivity)
  • Re: Exchange cant send email to one of the domains
    ... Specifying the smarthost as the remote mail exchanger won't be considered ... Exchange will route the message to this BH server and deliver the message to ... DNS, ... Most mail servers have no problem sending messages via SMTP ...
    (microsoft.public.exchange2000.admin)
  • Re: Exchange cant send email to one of the domains
    ... Specifying the smarthost as the remote mail exchanger won't be considered ... Exchange will route the message to this BH server and deliver the message to ... DNS, ... Most mail servers have no problem sending messages via SMTP ...
    (microsoft.public.exchange2000.general)

Loading