Re: ISA and Exchange

Tech-Archive recommends: Fix windows errors by optimizing your registry



I came across the Front-End/Back-End scenario in my general reading, not in
particular for the Direct Push feature itself.

"Ray" <no@xxxxxxxxxxxxxxxxx> wrote in message
news:u%23AiZ9RzGHA.3440@xxxxxxxxxxxxxxxxxxxxxxx
I am learning that to securely publish OWA and Direct Push, I should set
up a
Front-End Exchange Server that would sit in my DMZ. Here are my
questions, your help is appreciated:

Although a DMZ is usually recommended for a web-facing box, I think ISA's
ability to terminate the SSL connection on ISA's external interface,
inspect the traffic and then pass it on via SSL to the Exchange server is
more secure (and I use another vendor's firewall in front of ISA!)

Microsoft understands the intricacies of their products better than anyone
else, and ISA 2004 is a pretty solid product.

Did you find this recommendation because of Direct Push? I'm not using
that feature myself.

Ray


"SD" <smd6169@xxxxxxxxxxx> wrote in message
news:%23EZoNzQzGHA.4580@xxxxxxxxxxxxxxxxxxxxxxx
After years of outsourcing our email (clients would POP3 email in) we are
in
the stages of deploying our own email solution in house - Exchange 2003
SP2.

I am learning that to securly publish OWA and Direct Push, I should set
up a
Front-End Exchange Server that would sit in my DMZ. Here are my
questions, your help is appreaciated:

1. What Ports (Using ISA 2004) must I open to allow inbound email and
will this be between my back-ennd (internal Network) and External or
Front-End (DMZ) and External?
3. What ports must I open between Internal Back-End and DMZ Front-End to
allow proper communication between the Back-end and Front-End Servers?
4. Anything else to keep in mind?

Thanks - SD





.



Relevant Pages

  • Re: Should Front-End Server need join domain?
    ... back-end. ... DMZ, I'd reconsider that...you'd have to open a slew of ports between DMZ ... > Between these days I would like to setup a front-end Exchange server. ...
    (microsoft.public.exchange.admin)
  • Re: OWA Front end server
    ... the OWA front-end should NEVER sit in the DMZ. ... the firewall to put an Exchange server in the DMZ. ... the Exchange Server 2003 and Exchange 2000 Front-End ...
    (microsoft.public.exchange.setup)
  • RE: Exchange in the DMZ
    ... There have been several different Front-End Back-End whitepapers, ... My first question is why do you have to have it in the DMZ, ... I assume you are running Exchange 2000 on Windows 2000 in an AD Domain? ...
    (Focus-Microsoft)
  • RE: Exchange in the DMZ
    ... Can you resolve DNS names on the DNS supporting AD? ... I would recommend against Exchange front-end in DMZ because too much connectivity is required back to the private intranet. ...
    (Focus-Microsoft)
  • Re: DMZ and AD
    ... do you have a firewall between the DMZ and the internal network? ... why are you using clustering on DC's? ... > Front-End passes request for mail to the Back-End. ... > I have two Domain Controllers running Windows 2003 Server ...
    (microsoft.public.windows.server.active_directory)