Re: Security

From: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa_at_pacbell.net)
Date: 12/17/04


Date: Fri, 17 Dec 2004 12:42:41 -0800

Pro POP = no ports open
Pro SMTP - can't use Exchange IMF filter

POP - password is sent to ISP in clear text.. if the mailbox password is
the same as your domain password.. you are shipping over the web

POP - gunky email can clog up box

POP - have to buy third party program if you want a <15 minute pull

SMTP is an issue if you use stupid passwords... DON'T DO THAT.

I would argue that Remote web workplace has IMHO the ability to be
"less" exposed than an VPN. If you are opening VPN, you are already
opening a risk factor just as large as SMTP. You have a port open there.

You do realize that CISCO pix firewalls need maintenance and patching,
right? I personally would sandwich the Cisco and have two nics and keep
the ISA to ensure egress filtering...but that's just me :-)

Colin T wrote:
> Hi all,
>
> I haven't as yet set up an SBS box but intend to do so soon. I have read
> many of this newsgroups postings and have picked up numerous tips which will
> no doubt help me when I come to start using SBS 2003. I still have
> reservations about opening/forwarding ports to allow the SBS box receive SMTP
> mail as opposed to using the POP3 connector. Can anyone shed any light on the
> pro's and con's of using SMTP as opposed to the POP3 connector ? My first
> choice would be the POP3 connector simply because I would not have to open
> any ports. I intend to install my SBS machine with 1 NIC and use a Cisco PIX
> Firewall for perimeter security and will use this device to enable any VPN's
> required. My intended topology will be :
>
> Internet -> DSL Router -> Cisco PIX -> Switch ->SBS Box & Clients
>
> OWA will not be required by my client and neither will RWW. My client who
> needs SBS has extremely confidential medical data and this is my reason for
> not wanting to open up any ports. Incidentally, my client only has 5 mail
> addresses to collect. Any comments welcomed :) TIA.
>
> Regards Colin.



Relevant Pages

  • SMTP service on Cisco VPN Concentrator
    ... I was carrying out a pen-test on a Cisco VPN Concentrator, ... nessus 3.0 scan discovered a number of mail-related ports such as SMTP ... imaps at 993 and https at 443. ...
    (Pen-Test)
  • Re: Default SMTP Virutal Server
    ... Be sure those other ports you mentioned are TCP and not UDP. ... You can and should test the outgoing DNS and SMTP connection yourself from ... Also, if your router was blocking anything, it should show up in the logs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Securing Exchange Server
    ... Port forward SMTP and HTTPS. ... I find going through a secure proxy or daemon a mixed ... quirk specific to watchguard; if inbound email addresses have an apostrophe ... I'm a little weary of opening the firewall ports from past experience. ...
    (microsoft.public.exchange.design)
  • Re: Mein Problem mit OE Power Tool
    ... An allen Ports lauscht der Hamster Playground (SMTP 3025 weil Port 25 ... "Was hat ein zweiter Rechner in einem einfachen Test zu suchen?" ...
    (microsoft.public.de.german.inetexplorer.ie6.outlookexpress)
  • RE: SMTP Error #5.3.5
    ... I suggest you contact your smarthost provider to confirm how to configure the SMTP connector on your SBS. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)