Re: Exchange implementation



ISA-Exch BE. Publish Exchange through ISA. Don't let anybody tell you
otherwise, ISA is as stable and secure a firewall as anything else out
there.

[rant]Remember, there ain't no such thing as a 'hardware' firewall. It's
just a specialized computer with an embeded OS. The firewalls are always
software.[/rant]

I use the ISA-Exch solution and I've never had a problem.

"=?Utf-8?B?Ym1hbg==?=" <bman@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
news:03B3A2FE-BD9F-4BB7-8E6D-776203D94621@xxxxxxxxxxxxx:

> Thanks for the quick reply.
>
> Our organization is a finacial institution. So security is a major
> factor. We have about 75 employees. I need a cost effective solution.
> What do you think is the best senerio?
>
> Thanks
>
> "Mark Arnold [MVP]" wrote:
>
>> On Fri, 13 Jan 2006 07:14:01 -0800, "bman"
>> <bman@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>>
>> >Hello,
>> >
>> >Got some general exchange questions. I want to use exchange for my
>> >email solution. I am looking at a couple senerios for deployment. I
>> >want to be able to allow employess to to use OWA. I also want my
>> >enviroment to be secure. I am looking at using a front-end back-end
>> >solution. From the research I have found it looks like the most
>> >secure. I am also looking at just putting the exchange server in the
>> >DMZ without the FE-BE solution. If I just put the server in the DMZ
>> >what kind of limitations will I have and what kind of risks does
>> >that pose for my email service?
>> >
>> >With OWA will the employess still have and be able to create
>> >personnal folders when accessing over the internet?
>> >What kind of limitations will we have with the calendar using OWA?
>> >
>> >If you can point me to some articles, that would be great!
>> >
>> >Thanks for your time.
>>
>> Putting the Exchange server in the DMZ is about the most insane and
>> insecure thing you could do, so it's probably worth discounting that
>> idea.
>>
>> If you want to be secure then you use a 3 box solution. ISA - FE -
>> BE. If you don't have enough users to justify 3 boxes and don't want
>> to use the ISA for other purposes (firewall, proxy etc.) then port
>> forward 443 from the firewall to the FE and put that in a different
>> VLAN. Use IPSec between FE and BE.
>> If you want to use ISA and don't want three boxes then use ISA and a
>> BE, dispense with the FE. Publish SSL on the ISA and have it
>> re-encrypt to the BE.
>> See www.isaserver.org for some help. Also see
>> www.microsoft.com/exchange/library for the FE/BE configuration guide.
>>
>> By all means stop by here again with a supplementary question when
>> you have decided which route you wish to take.
>>
>

.



Relevant Pages

  • Re: Changing ISPs
    ... If you are familiar with the firewall, and changing the ip on the external nic, you might get it working with the present ISP. ... I suggest you go first just change the ip address on the SBS external nic to match the settings the new ISP gives you and run the CEICW and get that to work. ... Then install the edge device but leave ISA in place. ... SMTP mail for Exchange will not be held anywhere, so a POP connector will not retrieve it. ...
    (microsoft.public.windows.server.sbs)
  • Re: Grosse Anhänge werden nicht verschickt!
    ... >> Deinstalliere den ISA von der Maschine und nimm ein anderes Gerät ... Eine Firewall ist eine Firewall ist eine Firewall und hat auf ... >> einem Exchange - Server nix verloren. ... > Das ist mir auch klar das ISA nix auf einem Exchange zu suchen hat. ...
    (microsoft.public.de.exchange)
  • Re: ISA Verses Cisco PIX in Exchange 2003 Front End - Back End Top
    ... pix, but with alot of trial and error, and how many holes in the firewall ... I like the way you put it "extension of the Exchange infrastructure" ... ISA 2004 Enterprise it is! ...
    (microsoft.public.exchange.setup)
  • Re: ISA wont be my main firewall
    ... > will remain my primary firewall and I don't want ISA to stand between ... > the Pix and my internal network or DMZ. ... > setting up ISA and OWA are focused on that scenario. ... I have Exchange 2000 on my inside network. ...
    (microsoft.public.exchange.admin)
  • Re: Exchange Security and Administration: Small/Tiny Site
    ... Adding to what Michael suggested, put your Exchange Server behind a hardware firewall such as Cisco ASA or Sonicwall and its very secure since you are only opening two ports, 25 and 443. ...
    (microsoft.public.exchange.setup)

Loading