Re: Ex2K3 access through firewall
- From: "Lanwench [MVP - Exchange]" <lanwench@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Sat, 25 Jun 2005 10:24:24 -0400
In news:DF21BE0F-6B7D-4F60-98FF-F357B44EBED9@xxxxxxxxxxxxx,
Mike Lawson <MikeLawson@xxxxxxxxxxxxxxxxxxxxxxxxx> typed:
> I understand, but I have W2K and WXP clients on the WAN side using
> Outlook 2K, XP, & 2K3. If RPC over HTTP only works with the
> E2K3/OL2K3/WXP combo; what is to be done with clients that don't use
> this combination?
VPN, OWA.
> If I put the Ex2K3 server either on the LAN or DMZ
> I still have to open ports for the non-RPC over HTTP users to get to
> Ex2K3.
Yes, but your Exchange server does not belong in a DMZ. You have to open up
too many ports between DMZ and LAN to make it work - so you don't even have
a DMZ anymore.
> OWA doesn't look like a possibility since many of these same
> users archive data to .pst files which aren't accesssible via OWA.
Not a good idea anyway. Avoid PST files. If the data is important, it
belongs in the mailbox - or perhaps in an archive folder you set up for them
in the PF tree.
>
> And since every user doesn't have a high speed connection VPN would
> be a dog for connectivity. There has got to be a reasonable
> alternative.
POP or IMAP....but I don't recommend it; they don't get the full mailbox,
GAL, PFs, etc. If they don't all have broadband, and can't get it, it's just
not going to be fun for them, no matter what. OL2003 in cached mode makes
life a lot easier regardless of how one connects.
Thanks, Mike Lawson
>
> "Lanwench [MVP - Exchange]" wrote:
>
>>
>>
>> In news:F9110FA7-DB5B-4D38-95D0-1842CCF0821E@xxxxxxxxxxxxx,
>> Mike Lawson <MikeLawson@xxxxxxxxxxxxxxxxxxxxxxxxx> typed:
>>> Scenario: Ex2K3 on W2K3 on firewall DMZ. The users are wan and lan
>>> based. Clients use Outlook 2000, XP, & 2003 running on W2K or WinXP.
>>> Wan clients need access to Ex2K3 on DMZ.
>>>
>>> What ports do I need to open on the firewall in order for the
>>> various Outlook clients running on the two different OSs to have
>>> access to Ex2K3 in order to connect as Exchange corp clients? I've
>>> seen several similar posts that refer to documents on RPC over
>>> HTTP, but then the article says this is a WinXP feature ("RPC over
>>> HTTP on the client-side is a Windows XP feature"); so this config
>>> would not help the W2K OS clients.
>>>
>>> Thanks, Mike Lawson
>>
>> VPN, or RPC over HTTP (which works with E2003 and OL2003 on WinXP
>> SP1/SP2 only).
>>
>> Don't just open ports. Seriously. Also, I do not recommend that you
>> have your Exchange server in a DMZ....you're defeating the purpose
>> of a DMZ by doing this. Stick the server behind the firewall and
>> control access to it therein.
.
- Follow-Ups:
- Re: Ex2K3 access through firewall
- From: Mike Lawson
- Re: Ex2K3 access through firewall
- References:
- Ex2K3 access through firewall
- From: Mike Lawson
- Re: Ex2K3 access through firewall
- From: Lanwench [MVP - Exchange]
- Re: Ex2K3 access through firewall
- From: Mike Lawson
- Ex2K3 access through firewall
- Prev by Date: Re: POP3 Relay From ISP
- Next by Date: Re: Exchange server 2003 not sending smtp mail
- Previous by thread: Re: Ex2K3 access through firewall
- Next by thread: Re: Ex2K3 access through firewall
- Index(es):
Relevant Pages
|