RE: [fw-wiz] Outlook Web Access - Paranoid?

From: Matt Wilbur (matt@efs.org)
Date: 11/30/02


From: "Matt Wilbur" <matt@efs.org>
To: "'Mark L. Evans'" <MEvans@CO.SLC.UT.US>, "''Firewall-Wizards (E-mail)'" <firewall-wizards@honor.icsalabs.com>
Date: Sat Nov 30 19:35:01 2002


> -----Original Message-----
> From: firewall-wizards-admin@honor.icsalabs.com
> [mailto:firewall-wizards-admin@honor.icsalabs.com] On Behalf
> Of Mark L. Evans
> Sent: Tuesday, November 26, 2002 10:01 AM
> To: 'Firewall-Wizards (E-mail)
> Subject: [fw-wiz] Outlook Web Access - Paranoid?
>
[snip]
> We're trying to come up with the least dangerous method of
> allowing our
> users to check their email on MS Exchange. We currently allow
> them to use
> POP3 only. Our management would like to use Outlook Web Access. I have
> followed the issue on several mailing lists. I know it's a
> bad idea to use
> Exchange at all but management thinks I am too paranoid on
> this issue.
>
> It seems the best method is a reverse proxy using squid on a
> DMZ machine and
> then into the IIS server on the inside over SSL. What are your
> opinions/suggestions on this issue? Do you have any other
> methods that are
> more secure?
>

Mark,

If you just need to give end users access to email and email directory
services from the outside, why not use one of the many "webmail"
applications out there, all of which need far less access to your
internal networks. You could plunk, for example, squirrelmail out on a
DMZ system, allow port 143 (IMAP) and port 389 (LDAP) to an exchange
server (proxy them if that's appropriate - oh, and enable them in the
exchange server), and you'd be in business. End-users would lose a
little bit of added "features" OWA would give them, but you'd mitigate
so many other issues it would most likely be worth it, even to the
"suits".

Regards,
Matt Wilbur



Relevant Pages

  • Re: 2000 SBS -> 2003 Standard inkl. Exchange
    ... Geht der Exchange dann auch oder muss ich da auch was übernehmen? ... "Mark Heitbrink " wrote: ... > Marc Bäuml schrieb: ... Erst dann ist der Server sauber aus dem AD ausgetragen. ...
    (microsoft.public.de.german.windows.server.setup)
  • Re: Instant messaging
    ... Mark, I read the document and I simply dont get it, its talking about ... creating new DNS zones for the public domain, ... our server is behind a firewall and the domain name is domain.local, ... > If you are running Exchange Enterprise then you can install the Microsoft ...
    (microsoft.public.exchange2000.admin)
  • Re: Moving to New Exchange 5.5 Server
    ... Mark ... install Exchange 5.5 joining the existing org and ... > first server. ... > to recieve internet mail and change the firewall to direct inbound traffic ...
    (microsoft.public.exchange.setup)
  • Re: Moving to New Exchange 5.5 Server
    ... Mark ... install Exchange 5.5 joining the existing org and ... > first server. ... > to recieve internet mail and change the firewall to direct inbound traffic ...
    (microsoft.public.exchange.admin)
  • Re: Moving to New Exchange 5.5 Server
    ... Mark ... install Exchange 5.5 joining the existing org and ... > first server. ... > to recieve internet mail and change the firewall to direct inbound traffic ...
    (microsoft.public.exchange.design)