Re: Where do I put Exchange Server?

From: Sam (sam_at_globalwebcentral.com)
Date: 05/11/04

  • Next message: Biju Basheer: "Re: httpwebrequest timing out"
    Date: Tue, 11 May 2004 14:17:27 -0400
    
    

    Kenny,

    Again, thanks for the response. Those AD queries would be between the DMZ
    and the internal network. Do you still think that it would be problematic to
    open those ports for requests between two protected zones -- internal and
    the DMZ?

    Sam

    "Kenny Wu" <kenny.penghu@msa.hinet.net.NO-SPAM> wrote in message
    news:uNv8Ly2NEHA.2716@tk2msftngp13.phx.gbl...
    > Hi,
    >
    > If you put the mail server in DMZ,
    > you have to open many ports to allow AD query, client access mail server,
    > netbios sessions, name resolutions etc,
    > so, you have to do many thing when you put it in DMZ, and it's not good if
    > your firewall open many ports.
    >
    >
    >
    > --
    > ==============
    > Kenny Wu
    > Taiwan
    > MCSE, MCSA
    > ==============
    > "Sam" <sam@iQinternet.com> 撰寫於郵件新聞
    > :O9GQYYvNEHA.2820@TK2MSFTNGP10.phx.gbl...
    > > Hi Kenny,
    > >
    > > Thanks for the response. Why not put it in the DMZ?
    > >
    > > Sam
    > >
    > > "Kenny Wu" <kenny.penghu@msa.hinet.net.NO-SPAM> wrote in message
    > > news:u4F7OinNEHA.3420@TK2MSFTNGP11.phx.gbl...
    > > > Hi,
    > > >
    > > > My suggestion is put the mail server behind the ISA server,
    > > > and use secure mail function to publish your mail server.
    > > >
    > > > --
    > > > ==============
    > > > Kenny Wu
    > > > Taiwan
    > > > MCSE, MCSA
    > > > ==============
    > > > "Sam" <sam@iQinternet.com> 撰寫於郵件新聞
    > > > :ePY##TeNEHA.2884@TK2MSFTNGP10.phx.gbl...
    > > > > Hi,
    > > > >
    > > > > Where should I put our Exchange Server, on the Internal network or
    the
    > > > DMZ?
    > > > > Thanks.
    > > > >
    > > > > Sam
    > > > >
    > > > >
    > > >
    > > >
    > >
    > >
    >
    >


  • Next message: Biju Basheer: "Re: httpwebrequest timing out"

    Relevant Pages

    • RE: Firewalling with a webserver and DB
      ... But the DB on the internal network. ... only allow port 80 into your DMZ IF all you have are ... As clients computers will use these ports dynamically to talk to ... Firewalling with a webserver and DB ...
      (Security-Basics)
    • Re: [SLE] SuSEfirewall2 logging
      ... That alleviates one response. ... DMZ and my internal network: ... FW-ACCEPT messages for are the responses from port 800 in my DMZ back to ... traffic, or that it's a low port, but I also have this rule for printing ...
      (SuSE)
    • Re: Only IIS in DMZ, Exchange (with AD) and SQL Server on internal network
      ... What TCP ports on what interface do I have to open in order to make Exchange ... to 1) and not using DMZ at all (placing IIS on internal network)? ...
      (microsoft.public.security)
    • Re: No front-end in DMZ
      ... ISA server is out of consideration at all immediately. ... ISA server placed in the DMZ requires (as to best ... internal network card to be connected to internal network directly, ... and open above named ports just between these two. ...
      (microsoft.public.exchange.admin)
    • Re: New to ISA2004 and FE Exchange 2003
      ... You should have read the scenario guide before posting a response. ... Exchange in a DMZ requires a number of ports open between the DMZ and ... The options are to simply put the FE on the internal network and only ...
      (microsoft.public.exchange.setup)