Re: [fw-wiz] Exchange & Blackberry

strider_at_mailworks.org
Date: 06/22/04

  • Next message: Paul D. Robertson: "Re: [fw-wiz] Web server security?"
    To: "Geoff Bleau" <geoffb@bellsouth.net>, "Firewall Wizards" <firewall-wizards@honor.icsalabs.com>
    Date: Tue, 22 Jun 2004 06:46:43 -0500
    
    

    I agree with others that I wouldn't put my Exchange server as MX for
    whatever domain you're dealing with. Certainly I would at least put some
    sort of relay in front of it for both inbound and outbound traffic. My
    favorite flavor MTA for this is Postfix but there are others, some
    really cool SPAM/AV MTAs depending on the bucks you've got.

    As for Blackberry, it's an outbound TCP connection on one port (3101 I
    think) to Blackberry's srp servers (additional outbound requirements if
    you are doing MDS). However the connections from Blackberry to Exchange
    require a MAPI connection and is not firewall friendly. See:

    http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8179/270935/279244/Placing_the_BlackBerry_Enterprise_Server_for_Microsoft_Exchange_in_a_demilitarized_zone.pdf?nodeid=18034&vernum=1

    Therefore, for placement, I usually go with:

    Border MTA on the DMZ with only port 25 inbound from the world, port 25
    outbound to the world and port 25 to/from the internal Exchange server.
    Config the MTA as a relay for only your Exchange server.

    Exchange on the inside config'ed to forward to the border MTA.

    As for Blackberry, it's a risk tradeoff. What's the chances of that
    outbound connection doing bad things vs. the pain of trying to get it
    config'ed in the DMZ and what would that buy you?

    Cheers,

    Don

    On Mon, 21 Jun 2004 12:37:52 -0400, "Geoff Bleau" <geoffb@bellsouth.net>
    said:
    > Hi,
    >
    > I'm looking for suggestions on 'best-policy' for implementing
    > a MS Exchange Server 2003 and Blackberry Server installation
    > at a client site.
    >
    > Will be using a Sonicwall 2040 ( which has a DMZ port )
    >
    > 1) Where should the servers be placed ( LAN or DMZ ) ??
    > 2) What security issues will this 'open up' ??
    > 3) Any other caveats ??
    >
    > Thanks,
    >
    > Geoff Bleau
    >
    >
    > --
    > " I like my women like I
    > like my coffee......
    > bitter and murky. "
    > GC
    >
    > Geoff Bleau - geoffb@bellsouth.net
    > Florida Software & Data Systems http://www.flsoft.com
    >
    >
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizards@honor.icsalabs.com
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

    -- 
      
      strider@mailworks.org
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Paul D. Robertson: "Re: [fw-wiz] Web server security?"

    Relevant Pages

    • Re: published mail server behind 2006 cannot telnet out on port 25?
      ... I tried creating an outbound access rule (port 25 of internal ... From the outside, POP3 works, and SMTP can be used to send an email to ... But, the Exchange Server cannot send emails to the outside world, they ...
      (microsoft.public.isa)
    • Re: Block port 25
      ... by default ISA denies all outbound traffic, so if your clients have acces to ... port 25 outbound, then this is happening because of some rule that permits ... > network clients to send SMTP traffic outbound, ... > I have ISA Server 2000, and it publishes my Exchange Server. ...
      (microsoft.public.isaserver)
    • Re: KMail Addressbook: Group names for mutiple addresses?
      ... Today most distros have Postfix or Exim as default MTA. ... It's very well tested as an industrial grade MTA: many folks find others easier to configure or apply new features to, such as SPF or sophisticated spam filtering. ... I laughed like a hyena when the place I worked had to put a sendmail server in front of the Exchange Server to take in all incoming email, because the Exchange server couldn't take two simultaneous incoming SMTP connections. ...
      (comp.os.linux.setup)
    • Re: Cannot start MTA stacks service
      ... If your not on Service Pack 4, apply that to your Exchange Server, if the ... then apply the Post SP4 build of the MTA it addresses the ... Exchange Server 5.5 Post-Service Pack 4 Message Transfer Agent ... > Verify that the Microsoft Exchange MTA service has started. ...
      (microsoft.public.exchange2000.admin)
    • Re: stop spamming
      ... They should show any outbound ... port 25 traffic, and what the originating IP is... ... >> engine, so it may not be going through your exchange server, but may be ... >>> It seems that originating IP is mine. ...
      (microsoft.public.exchange.admin)