RE: SMTP setup for connecting through Firewall

From: Kenny Wood (Kenwood_at_online.microsoft.com)
Date: 01/09/05

  • Next message: Robert: "NDR smtp address"
    Date: Sun, 09 Jan 2005 01:47:39 GMT
    
    

    Hello and thank you for your post.

    How are these other workstations sending email (Outlook RPC, SMTP, POP3, IMAP4)? It
    sounds as if they are some type of SMTP client, but just checking. If they are an SMTP client,
    configure them to authenticate to the SMTP server, but remember that you are sending user
    names and password clear text (to resolve this apply a TLS cert to transport protocols).

    829721 How to Help Protect SMTP Communication by Using the Transport Layer
    http://support.microsoft.com/?id=829721

    823019 How to Help Secure SMTP Client Message Delivery in Exchange 2003
    http://support.microsoft.com/?id=823019

    As for configuring Outlook, if you don't use IPSEC you have to open several ports through your
    firewall:

    280132 XCCC: Exchange 2000 Windows 2000 Connectivity Through Firewalls
    http://support.microsoft.com/?id=280132

    278339 TCP/UDP ports used by Exchange 2000 Server
    http://support.microsoft.com/?id=278339

    270836 Exchange 2000 and Exchange 2003 static port mappings
    http://support.microsoft.com/?id=270836

    298369 How to Configure a Global Catalog Server to Use a Specific Port When
    http://support.microsoft.com/?id=298369

    Also read these:

    821746 HOW TO: Prevent Unsolicited Commercial E-Mail in Exchange 2003
    http://support.microsoft.com/?id=821746

    278339 TCP/UDP ports used by Exchange 2000 Server
    http://support.microsoft.com/?id=278339

    Kenny Wood
    CISSP, MCSE (+S, +M)
    PSS Security
    Microsoft Corporation

    -- 
    This posting is provided "AS IS" with no warranties, and confers no rights. Use of included 
    script samples are subject to the terms specified at http://www.microsoft.com/info/cpyright.htm 
    Note:  For the benefit of the community-at-large, all responses to this message are best 
    directed to the newsgroup/thread from which they originated.  
    --------------------
    Thread-Topic: SMTP setup for connecting through Firewall
    thread-index: AcT0+7hFSVGGBBseQ9m7HEiAtjOgZA==
    X-WBNR-Posting-Host: 65.221.166.7
    From: "=?Utf-8?B?Skg=?=" <JH@discussions.microsoft.com>
    Subject: SMTP setup for connecting through Firewall
    Date: Fri, 7 Jan 2005 12:59:03 -0800
    Lines: 8
    Message-ID: <5C639E17-92EA-47EC-8283-4EC6ED83FA1C@microsoft.com>
    MIME-Version: 1.0
    Content-Type: text/plain;
    	charset="Utf-8"
    Content-Transfer-Encoding: 7bit
    X-Newsreader: Microsoft CDO for Windows 2000
    Content-Class: urn:content-classes:message
    Importance: normal
    Priority: normal
    X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
    Newsgroups: microsoft.public.exchange2000.protocols
    NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.1.29
    Path: cpmsftngxa10.phx.gbl!TK2MSFTNGXA03.phx.gbl
    Xref: cpmsftngxa10.phx.gbl microsoft.public.exchange2000.protocols:8028
    X-Tomcat-NG: microsoft.public.exchange2000.protocols
    We have Exch 2003 on the internal portion of our network no frontend server.  
    My internal clients send mail fine, however I have workstations placed in 
    lower secure DMZ's that need to send mail through my server.  They can do 
    this fine only if I select both Anonymous and IW authentication.  My question 
    is how can I allow my clients to authenticate to my server without having 
    Anonymous authentication selected.  I read were I could open all the 
    standarded ports used and assign static port on the GC, would that be my only 
    solution??..
    

  • Next message: Robert: "NDR smtp address"

    Relevant Pages

    • Re: opening firewall ports on multiple IP mail server
      ... If we are still talking about mail server and not firewall then ... instead of using SMTP service this time you need to edit and ... It will open up the appropriate TCP ports. ... > listen for SMTP ...
      (microsoft.public.windows.server.networking)
    • Re: ANN: Basil -- Internet Message (email) and MIME library for Ada v 1.0
      ... library into AdaCore's Ada Web Server, ... which already includes an SMTP client and server but apparently lacks ... 2821 (SMTP) and you actually wouldn't need MIME in an RFC 2821 MTA, ... use the structured header parsers, ...
      (comp.lang.ada)
    • IPTABLES mail forwarding ?
      ... I have a firewal running on my fixed ip address and closed most ports. ... server on the local net 192.... ... I also need some help with input and output rules for smtp. ...
      (comp.os.linux.security)
    • Re: TCP/IP filter & SMTP
      ... Also, if you are using MS SMTP server or Exchange server, you'll need to ... and I can't find any other ports that SMTP might use. ... > If I enable all UDP ports, ...
      (microsoft.public.inetserver.iis.security)
    • Re: SmtpClient sending emails driectly from own computer
      ... through an SMTP client out on some server. ... You do realise that even if you use your own SMTP server, ... Port 25 is much more likely. ...
      (microsoft.public.dotnet.languages.csharp)