Re: Exchange 2000 FE / BE Config Questions
From: Mark Arnold [MVP] (mark_at_mvps.org)
Date: 05/28/04
- Next message: Gayle Heizer [MSFT]: "RE: Recipient Policy"
- Previous message: Mark Arnold [MVP]: "Re: Exchange 2003 SP1 Probs"
- In reply to: David Hodgson: "Exchange 2000 FE / BE Config Questions"
- Messages sorted by: [ date ] [ thread ]
Date: Fri, 28 May 2004 18:49:55 +0100
"David Hodgson" <david.hodgson@vianet.co.uk> wrote:
>Hi folks,
>
>can someone please verify that this will work for me.
>
>Domain = domain.co.uk
>Exchange 2000 FE in DMZ behind firewall with external IP address NAT'd to
>it.
>Exchange 2000 BE in Internal Network
>
>All clients will be be able to get OWA, IMAP and POP3 by connecting to FE.
>
>MX records on my ISP's DNS servers for domain domain.co.uk will use Exchange
>2000 FE external IP address.
>(If this is correct then SMTP emails will be sent to the FE server, is this
>correct? will the FE send emails to the BE server and vice versa?)
>
>Thankyou
>Dave
>
Dave, the FE is in the wrong place. It should not be in the DMZ. There
are far too many ports open from the DMZ to the LAN to make the DMZ
secure. If you must put something in the DMZ then use ISA (in a
workgroup, not the domain) and point every protocol at the ISA. ISA
can then publish those services for the users on the Internet.
If this means that you can only have an ISA and a BE then that's not a
problem for Exchange. If you do have a 3rd box then you can direct the
ISA at the internal IP of the FE.
To route the mail through one box on its way out, you create a routing
group with two members and select the FE as the local bridgehead. This
enables you to put the spam filter / disclaimer software on one box
only. Use of an RG rather than pointing the smtp VSI on the BE to a
smarthost address of the FE lets you enter such things as sender
restrictions should you have people on the lan who are not permitted
to send Internet mail.
Mark Arnold MCSA MCSE+M MVP,
FAQ: http://www.swinc.com/resource/exchange.htm
Blog: http://www.msexchange.me.uk
- Next message: Gayle Heizer [MSFT]: "RE: Recipient Policy"
- Previous message: Mark Arnold [MVP]: "Re: Exchange 2003 SP1 Probs"
- In reply to: David Hodgson: "Exchange 2000 FE / BE Config Questions"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|