Re: OWA access and security



IIS6 has been rock solid.

As paranoid as I am I have port 443 open. I never ever had it open on SBS 2000.

If you have local admin on the desktop, your risks are probably bigger over there.

Gerko wrote:

There is now a need for going to work with Outlook Web Access on our company. What I first like to know is what port(s) does OWA needs to access from outside?
If I want to give our employees a save way to use this, what are the safety issues, e.g. do we need SSL etc. ?


We have a SBS2003 Premium Server with two NIC's. One for the internal network, on the other NIC the e-mail from outside is delivered. This NIC is connected to a external router and firewall and for this NIC only port 25 is open. We do not use ISA.

Is it save to open the required ports on the firewall, to give employees access?

Thanks in advance,

Gerko



--
An open letter to the Security Community:: http://msmvps.com/bradley/archive/2004/12/12/23540.aspx
.




Relevant Pages

  • Re: keeping ports open
    ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
    (microsoft.public.security)
  • Re: How to Maintain an IIS Server?
    ... > server running on a Windows 2000 server. ... before a firewall and antivirus have been installed]. ... open ports; however, this will not identify which program is using the port. ...
    (microsoft.public.inetserver.iis.security)
  • Re: CEICW fails at firewall config
    ... ISA Server prevents connection to a remote desktop when you connect through ... Remote Web Workplace on a Windows Small Business Server 2003-based computer ... Acceleration Server as a firewall. ... connection uses TCP port 4125. ...
    (microsoft.public.windows.server.sbs)
  • Re: How to Maintain an IIS Server?
    ... >> server running on a Windows 2000 server. ... > before a firewall and antivirus have been installed]. ... > program or executable using that port. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Is secedit.exe left by a hacker?
    ... > tested on port 445. ... > I have a Linksys router that I use as a firewall to my ... Secedit.exe is the name of a legitimate Windows file, ... investigate the files on your computer - antivirus with the latest updates ...
    (microsoft.public.win2000.security)