Re: Remote Access: IP vs domain name?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Les Connor [SBS Community Member] (les.connor_at_DEL.cfive.ca)
Date: 11/30/04


Date: Mon, 29 Nov 2004 22:20:06 -0600

I think the issue might be that the cert wouldn't match. So you really only
want one record, as you only have the one sbs cert for both /remote and
/exchange.

I generally use mail.domain.com for email, and <whatever>.domain.com for
both remote and exchange. Allthough, lots just have the mail record and so
long as you use that fqdn to generate the cert there's not problem.

-- 
Les Connor [SBS Community Member]
-----------------------------------------------------------
SBS Rocks !
"Lanwench [MVP - Exchange]" 
<lanwench@heybuddy.donotsendme.unsolicitedmail.atyahoo.com> wrote in message 
news:%23CF20co1EHA.1524@TK2MSFTNGP09.phx.gbl...
> OLOT wrote:
>> Wow, that was quick, thank you.  So, for example, I would make:
>>
>> mail.diamondvids.com         A Host =  myip  (at Network Solutions)
>> remote.diamondvids.com    A Host = myip   (at Network Solutions)
>>
>> Once my A Host record updates ( a couple of hours...)
>>
>> mail.diamondvids.com/exchange will go to OWA and
>> remote.diamondvids.com/remote will go to RWW
>>
>> alternately I could make the A host record of server.diamondvids.com
>> = myip and
>>
>> server.diamondvids.com/exchange will go to OWA and
>> server.diamondvids.com/remote will go to RWW
>>
>> Is that right?
>>
>> p.s. - I already have an entry for mail.diamondvids.com for my MX
>> record: mail.diamondvids.com (10)  with A host entry for
>> mail.diamondvids.com = myip (at Network Solutions)
>> so I guess that one is already set up and working cuz I just tested
>> it. Doh!
>
> Since it sounds like you have only one server & one public IP, you could 
> use
> mail.diamondvids.com for everything. /exchange = owa. /remote = RWW.
> mail.diamondvids.com for VPN.
>>
>>
>> "Javier Gomez [SBS MVP]" <javier_gomez@remove.this.engineer.com>
>> wrote in message news:ueK717n1EHA.1564@TK2MSFTNGP09.phx.gbl...
>>>> During the Remote Access wizard, it asks for the Full Internet Name
>>>> of the server (is that the same as FQDN)?
>>>
>>> That is correct.
>>>
>>>> If my domain name is: diamondvids.com, and I type
>>>> www.diamondvids.com to access the website, what would be the
>>>> correct entry?
>>>
>>> Probably not. Unless you plan to host that website on the SBS box
>>> (not recommended).
>>>
>>>> (1) Do I use diamondvids.com or server01.diamondvids.com?
>>>
>>> You could... but I would use something more significant. Like
>>> mail.diamondvids.com or remote.diamondvids.com. However, you can use
>>> whatever you want.
>>>
>>>> (2) Does the server01 portion need to match the server name, or
>>>> does it merely have to match the A host entry?
>>>
>>> Nope. Just the (public) A host entry.
>>>
>>>> (3) Based on (1), what would my A host entry be where I maintain my
>>>> dns records?
>>>
>>> Let's say you decide to use remote.diamondvids.com then your A
>>> record should be (remember that this is on your public DNS, not on
>>> the SBS box):
>>>
>>> remote.diamondvids.com IN A XXX.XXX.XXX.XXX
>>>
>>> where xxxx represent the static public IP of your SBS box.
>>>
>>>> (4) It seems many users opt to use the static ip address and forego
>>>> the domain name, is there an advantage to this, security wise or
>>>> other...
>>>
>>> I don't think many users do this and I see no advantage of doing it
>>> (in fact it is a disadvantage because you have to remember the
>>> criptic IP instead of a nice hostname).
>>>
>>> --
>>> Javier [SBS MVP]
>>> www.msmvps.com/javier
>>> << SBS ROCKS !!! >>
>
> 


Relevant Pages

  • Re: CEICW after loading third party certificate
    ... GoDaddy cert would have to be for mail.company.com ... The DNS hosts will be contacted to ... is there any reference to company.com in the SBS DNS console? ... The wizard resolved it as the server name ...
    (microsoft.public.windows.server.sbs)
  • Re: CEICW after loading third party certificate
    ... pick a name that you wish to access your server by. ... way that ISA 2004 is setup. ... Choose a name for the server and get a cert with that name. ... IMHO not appropriate for SBS as it gives SO MUCH more than simply mail. ...
    (microsoft.public.windows.server.sbs)
  • Re: CEICW after loading third party certificate
    ... You are also quoting info from SBS' local DNS. ... The wizard resolved it as the server name ... AGAIN, when I revoke this certificate, purchase another, should the ... mail.etc gets a cert, as does ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 Premium and Cert Services
    ... that philosphy got blown out of the equation when SBS included Exchange OWA ... "Small Business Server" which is MS claim as to why the risk of exposing the ... the Certificate Server on another server, ... >> Cert, or you could edit the properties of your Certification Authority to ...
    (microsoft.public.windows.server.sbs)
  • Re: CEICW after loading third party certificate
    ... point to the server IP, and on IIS on that server there must be a folder ... running www on SBS is ill advised. ... Choose a name for the server and get a cert with that name. ... it is for ISA 2000 not directly for ISA ...
    (microsoft.public.windows.server.sbs)