Re: OK, I'm sold on SBS2003 now





In news:MPG.1d991d33a3ee0c7798a0ce@xxxxxxxxxxxxxxxxxxxxxxxxxxx,
Leythos <void@xxxxxxxxxxx> typed:
> In article <OL#Y7VTvFHA.3860@xxxxxxxxxxxxxxxxxxxx>,
> lanwench@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx says...
>>
>>
>> In news:MPG.1d96702ba38d325b98a0aa@xxxxxxxxxxxxxxxxxxxxxxxxxxx,
>> Leythos <void@xxxxxxxxxxx> typed:
>>> In article <ex69oM4uFHA.1256@xxxxxxxxxxxxxxxxxxxx>,
>>> okf22@xxxxxxxxxxx says...
>>>> I would not put SQL in there
>>>
>>> I don't know WHERE where is that you are replying about.
>>>
>>> DC = LAN
>>> SQL = LAN
>>> Exchange = DMZ
>>>
>>> I'm not talking about a DMZ in the same network, I'm strictly
>>> talking about a real DMZ with a different network.
>>
>> Why a DMZ at all? What's it facing? What's the purpose?
>
> Do you not understand network security?

Well, I'd like to think I at least dabble in it, and my cllients' networks
have never yet been hit with anything at all, for what it's worth. Call it
luck, skill, or a combination of both, but this is a fact. Sarcasm tags on
or off, as you choose. ;)
>
> The DMZ is where you place nodes that have public facing services
> offered. A web server belongs in the DMZ, not in the LAN.

Yes. A regular web server - absolutely. In a perfect world, I could run OWA
on a dedicated non-MS webserver. I can't, and my clients want OWA, so I do
what I can to provide them with the functionality they wish, with the
security I can assign.
>
> An Exchange server, for a single server, works very nicely in the DMZ
> as long as you have the rules setup that the LAN side must contact the
> Exchange server in the DMZ before the exchange server can communicate
> with the LAN devices.

Actually, this is not by any means considered a 'best practice' config for
Exchange server. Ask any of the gurus in the Exchange groups, or the MS
Exchange folks themselves. If you want a front-end/back-end config for OWA,
you can use ISA....if you don't want to expose your production Exchange box
to the Internet for mail, stick a Postfix (or similar) box in your DMZ, and
relay mail from it to the Exchange box...on the LAN.

Putting Exchange in a DMZ means poking so many holes in your DMZ that it
isn't really a DMZ anymore. I wouldn't do it myself.
>
> Since I don't put Exchange servers in the same Domain as the LAN
> computers, it's very simple to maintain control of users
> login/passwords for the exchange server and still provide a less
> exposed service to the rest of the network. Since the exchange server
> can't contact the LAN without an Invite, it means that should the
> exchange server be compromised, that it can't reach the LAN systems,
> even if it could, the security accounts don't match between then (no
> users with the same account/password) so it can't reach in that way
> either.

Your mileage may vary. Like I said, this is not a generally recommended
config.


.



Relevant Pages

  • Re: Exchange Server in DMZ
    ... > do I need to open for the server to participate in the local domain ??? ... DMZ and your LAN, not a good thing imho, if possible, I'd suggest ... do as well) and configuring it to forward mail to the Exchange server ...
    (comp.security.firewalls)
  • Re: Running Exchange 2000 on a DMZ
    ... firewall and not on a DMZ. ... I need some help finalizing the Exchange Server setup so that it will ... > firewall to your intenal network, you might as well have no firewall. ...
    (microsoft.public.exchange.setup)
  • Only IIS in DMZ, Exchange (with AD) and SQL Server on internal network
    ... I need to reconfigure our network. ... We have a 3COM firewall with DMZ. ... and Exchange Server and SQL Server (internet ... application database) on our internal network. ...
    (microsoft.public.security)
  • RE: [fw-wiz] NTLM authentication from DMZ
    ... The key threat is that someone will hack your IIS box and then sit on it ... gathering valid password pairs for the LAN domain, ... but believe me when I say that once someone has control over the DMZ box ... > place to put a company's Exchange server. ...
    (Firewall-Wizards)
  • Re: Running Exchange 2000 on a DMZ
    ... firewall to your intenal network, you might as well have no firewall. ... go search for exchange server in a dmz and give the results to your boss and ... > Server on the DMZ to isolate it from the network. ...
    (microsoft.public.exchange.setup)