Re: Securing Exchange Server



Port forward SMTP and HTTPS. If you want, you can send the SMTP through the
proxy on watchguard. I find going through a secure proxy or daemon a mixed
bag though. For certain versions of PIX, mailguard can do funny things. A
quirk specific to watchguard; if inbound email addresses have an apostrophe
in them, you have to edit the incoming SMTP policy to allow them.


"Tom Bombadil" <Genius_Poster@xxxxxxxxx> wrote in message
news:BB720DF5-A07E-4C90-B41A-DA8EF5AFACF2@xxxxxxxxxxxxxxxx
Hello,

We are a small company and we are looking to implement Exchange as our
main messaging system.

I wanted to ask for your suggestions as to the best method of securing the
Exchange. We have a Watchguard firewall with an embeded DMZ. Is the
front-end server the only way to go? Are there any appliances that do the
job of a front-end server, without the risk of it being hacked or brought
down?

I'm a little weary of opening the firewall ports from past experience. I
had previously forwarded ports to FTP and VPN servers, and they always got
hacked or had rootkits dropped in. I cannot take that chance with the
Exchange.

Thank you for your input.


.



Relevant Pages

  • SMTP service on Cisco VPN Concentrator
    ... I was carrying out a pen-test on a Cisco VPN Concentrator, ... nessus 3.0 scan discovered a number of mail-related ports such as SMTP ... imaps at 993 and https at 443. ...
    (Pen-Test)
  • Re: Security
    ... Pro POP = no ports open ... SMTP is an issue if you use stupid passwords... ... > I haven't as yet set up an SBS box but intend to do so soon. ... > reservations about opening/forwarding ports to allow the SBS box receive SMTP ...
    (microsoft.public.windows.server.sbs)
  • RE: Same prob
    ... place for SMTP proxy line length which you mentioned changing for the ... I did turn on SMTP logging and will see if something turns up ... > The first was the issue with the Watchguard Firewall settings, ... Interestingly our ISP is Earthlink (you ...
    (microsoft.public.exchange.admin)
  • Re: SMTP Relay Exchange 5.5
    ... The Watchguard Firebox firewall can be configured with an SMTP proxy agent. ... with configuring the Firebox firewall with their SMTP proxy. ...
    (microsoft.public.exchange.connectivity)
  • Re: Default SMTP Virutal Server
    ... Be sure those other ports you mentioned are TCP and not UDP. ... You can and should test the outgoing DNS and SMTP connection yourself from ... Also, if your router was blocking anything, it should show up in the logs. ...
    (microsoft.public.inetserver.iis.security)