RE: [fw-wiz] (no subject)

From: Paul Robertson (proberts@patriot.net)
Date: 11/25/02


From: Paul Robertson <proberts@patriot.net>
To: Don Goldstein <Don.Goldstein@CCBUSA.COM>
Date: Mon Nov 25 17:02:03 2002

On Mon, 25 Nov 2002, Don Goldstein wrote:

> You can put an outlook web access server in the DMZ and the Exchange server
> on your LAN.

OWA and IIS haven't exactly had the best record. Add in password
guessing and a pipe in to an AD or DC, and the upsides don't look all that
attractive to me. Now, if you're talking about a VPN'd segment off the
DMZ, you could perhaps minimize the risk, but I don't think I'd advise my
closest competitor to field OWA on their DMZ as a strategy without some
more serious and direct protection.

Paul
-----------------------------------------------------------------------------
Paul D. Robertson "My statements in this message are personal opinions
proberts@patriot.net which may have no basis whatsoever in fact."
probertson@trusecure.com Director of Risk Assessment TruSecure Corporation



Relevant Pages

  • Re: OK, Im sold on SBS2003 now
    ... >>> talking about a real DMZ with a different network. ... A web server belongs in the DMZ, not in the LAN. ... > An Exchange server, for a single server, works very nicely in the DMZ ...
    (microsoft.public.windows.server.sbs)
  • RE: [fw-wiz] NTLM authentication from DMZ
    ... The key threat is that someone will hack your IIS box and then sit on it ... gathering valid password pairs for the LAN domain, ... but believe me when I say that once someone has control over the DMZ box ... > place to put a company's Exchange server. ...
    (Firewall-Wizards)
  • Re: More DMZ
    ... Without buying a new exchange server I don't think there is ... you somehow sychronise the DMZ Exchange with another one in the LAN? ... I am about to use the DMZ port on the firewall to add a ... LAN, i.e. not being routed through the DMZ port. ...
    (microsoft.public.windows.server.sbs)
  • Re: Setting TCP/IP Ports for Exchange 2003 and Outlook Client Connections Through a Firewall
    ... DMZ is supposed to have very ... I want one MAPI client ... > Then I opened for the port 135 and now it points to the exchange server, ...
    (microsoft.public.exchange.admin)
  • Re: [fw-wiz] NTLM authentication from DMZ
    ... Exchange server is part of the normal company domain, ... have one authentication database to deal with. ... Place the exchange server in the DMZ, but that would require a whole ... Place it on the LAN, but that would require opening ports from the ...
    (Firewall-Wizards)