Re: Front-End on Cisco PIX

From: Ore-Ore (hiroamano_at_comcast.net)
Date: 11/03/04


Date: Wed, 3 Nov 2004 13:51:47 -0600

I think if you have two network cards on the FE, one for external and one
for internal, you can close the ports for external address on PIX except 80
(443).

"manoa" <manoa@discussions.microsoft.com> wrote in message
news:0D03F9DA-2836-47CD-A84E-ACD0585C17D4@microsoft.com...
> I am trying to figure out how to implement a front-end/back-end E2K
solution
> on a Cisco PIX 515 firewall with a DMZ. I have read that it is not
> recommended to put the FE on the DMZ because you have to open a bunch of
port
> for it to communicate with the internal MS network. It is suggested that
an
> ISA be placed in the DMZ so that it can pass communication to the FE
exchange
> server. I need to know if this is the best senerios for users who need to
> access the mail via the internet. Is there any documentation I can
reference
> to guide me in this setup? I am not familar with ISA so I need all the
help
> I can get.



Relevant Pages

  • Re: Port Scanning onWAN IP of Speedtouch 530
    ... That means all ports 65,535 TCP and 65,535 UDP ports are ... exposed to the public Internet opening all the inbound ports for that ... No....the purpose of a DMZ is to create a security zone that can exist ... expose to the internet. ...
    (comp.security.firewalls)
  • Re: Port Scanning onWAN IP of Speedtouch 530
    ... That means all ports 65,535 TCP and 65,535 UDP ports are ... exposed to the public Internet opening all the inbound ports for that ... No....the purpose of a DMZ is to create a security zone that can exist ... expose to the internet. ...
    (comp.security.firewalls)
  • Re: Question about DMZ Domain Member and Virus Membership
    ... restrict access to machine ports from the internet as needed IE port ... Ideally you are building a DMZ to insulate your internal network from ... The Norwich University program offers unparalleled Infosec management ...
    (Security-Basics)
  • Re: Port forwarding to a client for VOIP
    ... the ports aren't doing anything are going anywhere. ... Instant Messaging with ISA Server ... Firewall client can handle complex protocols without an application filter. ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa.configuration)
  • [VulnWatch] 3Com OfficeConnect Remote 812 ADSL router exposes internal LAN computers ports during ou
    ... ports during outbound and inbound TCP and UDP sessions. ... The 3Com 812 is a widely-deployed router, found in many ISPs ADSL lines. ... for internet access. ...
    (VulnWatch)

Loading