Where to Place Email Gateway?
From: Yogi (ybher_at_cox.net)
Date: 03/07/04
- Next message: Russ: "Re: telnet into port 25"
- Previous message: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]: "Re: telnet into port 25"
- In reply to: Tony Su: "Where to Place Email Gateway?"
- Next in thread: John LeMay: "Re: Where to Place Email Gateway?"
- Messages sorted by: [ date ] [ thread ]
Date: Sat, 6 Mar 2004 19:25:40 -0800
Thanks, I wasn't aware of the "socket pooling" thing. By
the way, I'm testing with the RC edition so I don't have
ISA to configure, yet. But when I finally get my hands on
Premium...Nevertheless, I'll see how far I go with the
the setup in the GFI manual. At least with what you've
suggested, it gives me something more to learn about.
Yogi
>-----Original Message-----
>Yes, I've done that, too.
>
>The key is the relatively unknown requirement that SMTP
>socket pooling has to be disabled. Usually people only
>know about web socket pooling. The reason for disabling
is
>the same as for disabling web socket pooling... if you
>have more than one application listening for a common
>service, you have to ensure that they listen only for
what
>they are configured and don't pool socket resources.
>
>On as SBS2K, I've configured an inbound message to be
>accepted by ISA, forwarded to a LAN IP adddress
configured
>with an IIS SMTP virtual server, then forwarded to
>Exchange with its hidden IIS SMTP virtual server. I'm
>saying hidden because unless you disable SMTP socket
>pooling, it doesn't show up in the ISM.
>
>Then, for good measure on that SBS, I configured the
>Exchange outbound SBS SMTP Connector (not an SMTP
virtual
>server) to point to another LAN address with <another>
>SMTP virtual server, whereupon ISA was configured to
>forward through a second WAN address.
>
>This was when I was trying to figure out why my ISA SMTP
>filter was only filtering inbound mail and by splitting
>inbound and outbound this was proof positive that no
>outbound mail was filtered. The bonus which may benefit
>you is that this is clearly how to run multiple SMTP
>applications on the same box.
>
>If you need to try to duplicate any or all of what I
did,
>ISA was configured with two SMTP Server Publishing rules
>for inbound and outbound, three SMTP servers, one for
>Exchange and another each for inbound and outbound and
as
>I stated in the Exch System Manager the SMTP virtual
server
>(s) are for inbound and the Small Business SMTP
connector
>is for outbound.
>
>Note that at least if you use ISA, by Publishing your
SMTP
>application, it is protected from the Internet, both by
>separating networks and by implementing the SMTP
>application filter which closely analyzes the content
and
>headers of the SMTP packets. If you don't think that
>separating your SMTP from your LAN is important, this
>solution may work for you.
>
>HTH,
>Tony Su
>
>
>
>
>
>
>>-----Original Message-----
>>Thanks for responding Tony,
>>
>>GFI MailEssentials can also be installed on a separate
>>machine...says the manual. But with the 2 NIC system of
>>SBS2K3, I wanted to know if anyone actually configured
>>the mail/relay box with an IP address that coincides
with
>>the WAN NIC or with the LAN NIC. Either way, I'm
looking
>>at putting it in a DMZ.
>>
>>>-----Original Message-----
>>>The GFI applications I evaluated recently have an
>>Exchange
>>>plug-in architecture, not SMTP standalone.
>>>
>>>So, you should configure your Exchange exactly the
same
>>as
>>>if you were not using GFI (which can vary depending on
>>>your situaion).
>>>
>>>Tony Su
>>>
>>>
>>>
>>>>-----Original Message-----
>>>>Hi All,
>>>>
>>>>I want to test GFI MailEssentials and MailSecurity
from
>>a
>>>>relay gateway. My test SBS2K3 machine is configured
with
>>>>2 NICs: 192.168.16.2(LAN), 192.168.2.2(WAN). My
Router
>>is
>>>>at 192.168.2.1. What IP should I address my relay
>>>>gateway? 192.168.2.3 or 192.168.16.3? I'm looking at
>>>>possibly putting the gateway in a DMZ..."Get out your
>>red
>>>>digital pens and critique please." Thanks.
>>>>
>>>>Yogi
>>>>.
>>>>
>>>.
>>>
>>.
>>
>.
>
- Next message: Russ: "Re: telnet into port 25"
- Previous message: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]: "Re: telnet into port 25"
- In reply to: Tony Su: "Where to Place Email Gateway?"
- Next in thread: John LeMay: "Re: Where to Place Email Gateway?"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|