Outbound Internet Mail



Hello All

We have a requirement to route outbound internet email from Exchange
2003.

As a solution I have decided to build 2 Exchange BH servers and install
an SMTP connector wich utilises both these virtual servers.

These 2 BH servers will be on our internal network and will send mail
out directly to the internet. The firewall policy will only allow port
25 from these servers outbound to the internet.

These 2 BH servers will also run Antigen 9.0 for AV protection and
possibly we will inplement either IMF or the Antigen spam module for a
second level of spam protection for the Internet mail we receive via
our parent company.

Does this sound like a good solution?

I have gone through loads of other possible designs but have settled on
this. One of the other designs included having an SMTP gateway on our
DMZ which the Exchange clusters virtual server relayed too. I decided
that as we do not need to provide for incoming internet email (as that
is routed to us internally by the parent company) it is pointless
installing a box on the DMZ, this would just make it harder to manage
as opposed to providing any security benefit as connections are
outbound only

Incoming mail that we receive from our parent company will also be
routed to the two BH servers, we plan to utilise DNS round robin here
as opposed to deploying NLB.

We also have a single FE server on our internal network that supports
EAS and OWA access to Exchange and this is front ended by ISA which is
in the DMZ.

Any comments on this design?

Much appreciated

AndyJ

.



Relevant Pages

  • Re: How to host email using Exchange 2003
    ... > You Own SMTP Mail using Exchange 2000" and think the instructions will ... So their DNS your company is using is Internet "facing". ... record specific Emails servers. ... The ISP DNS servers will do the job of sending Internet mails out. ...
    (microsoft.public.exchange.setup)
  • RE: IIS6 Security and other web servers
    ... IIS6 Security and other web servers ... I know of no Windows architecture that is exposed directly to ... I know of a number of LAMP-type servers that are ... exposed directly to the Internet with no intervening layers. ...
    (Security-Basics)
  • Re: [fw-wiz] firewall-wizards Digest, Vol 9, Issue 4
    ... Be very careful with outbound traffic from the DMZ. ... Internet access from the servers/DMZ fall very quickly. ... consider pulling updates from internal AV distribution servers instead. ...
    (Firewall-Wizards)
  • Re: Restrict Dynamic Updates
    ... exposed to the Internet is an inherently bad idea, but am in a position where ... my thought was to leave the clients pointing to the BIND/DNS ... servers to resolve all non-AD queries and redirect them to the AD/DNS servers ... internal DNS server host external public data. ...
    (microsoft.public.windows.server.dns)
  • Add new Exchange server behind a firewall to existing site
    ... We have an existing Exchange system that consists on three Exchange ... The Exchange servers have been installed as a single Exchange site even ... What ports do we need to open if I install the server ... I am planning to route Internet email directly to/from the new email ...
    (microsoft.public.exchange.connectivity)