Re: Ex2003 ports to AD?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Lee Li [MSFT] (v-leeli_at_online.microsoft.com)
Date: 10/14/04


Date: Thu, 14 Oct 2004 10:40:57 GMT

Dear Tony,

Thank you for posting here. Thanks Rand and Leif for sharing great
experience.

First, I agree with Rand and Leif, it is better to set Exchange Server and
Domain Controller in the Internal Network for the security consideration.
If you still prefer to set them in DMZ and internal network separately, you
may refer to the article below to open the port for the communication.

280132 XCCC: Exchange 2000 Windows 2000 Connectivity Through Firewalls
http://support.microsoft.com/?id=280132

Meanwhile, as a secure and convenient alternative, you can configure
Front-End and Back-End Topology with FE in DMZ and BE in internal network
so that it can secure the internal network with less port communication.
For more information, please refer to the White Paper: Exchange Server 2003
and Exchange 2000 Server Front-End and Back-End Topology.

Exchange Server 2003 and Exchange 2000 Server Front-End and Back-End
Topology
http://www.microsoft.com/technet/prodtechnol/exchange/2003/library/febetop.m
spx

Hope this helps. Please let me know if you have any other concerns or
questions. Thanks and have a nice day!

Thanks & Regards,

Lee Li
Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.



Relevant Pages

  • Re: Exchange POP3 DNS issue
    ... the same POP3 client tries to connect from our internal network it ... If I try to telnet to the Exchange server on 110 it will ... connect but never return a banner from the Exchange Server. ... Could this be a sign of DNS problems? ...
    (microsoft.public.exchange.admin)
  • SMTP and E2 w/SP3
    ... I am running Exchange Server 2000 with SP3 installed on an internal network. ... All outside mail is handled through the ISP email and there is no forwarding ...
    (microsoft.public.exchange.admin)
  • Re: Multiple Nics
    ... Put 1 NIC in the Exchange server and put that on the internal network. ... Please do not send email directly to this alias. ... >I want to configure exchange to run behind a firewall utilizing 1 to 1 nat. ...
    (microsoft.public.exchange.setup)
  • Re: Protecting an Exchange server?
    ... > internal network and place some kind of email appliance on our DMZ to ... > actually send and receive email to the world and to the Exchange server on ... Securing Microsoft Groupware Environments with Unix ... to facilitate one-on-one interaction with one of our expert instructors. ...
    (Security-Basics)
  • RE: Mailbox to receive mail from inside only
    ... Thanks for Leif for sharing great experience. ... restrict the Exchange Server from receiving and sending Internet mails. ... Microsoft Online Partner Support ... This posting is provided "AS IS" with no warranties, ...
    (microsoft.public.exchange2000.admin)