RE: [fw-wiz] PIX -> ISA -> OWA Configuration

From: Sanford Reed (sanford.reed_at_cox.net)
Date: 05/03/05

  • Next message: jimmy_at_chickenhollow.net: "Re: [fw-wiz] Hopefully not too OT"
    To: "'Ben Nagy'" <ben@iagu.net>, <firewall-wizards@honor.icsalabs.com>
    Date: Tue, 3 May 2005 10:34:50 -0400
    
    

    I hate to disagree but in 1 the [hackable box] is the ISA Proxy which is
    'protected' by the outer PIX. The 'pot-o-gold' as you put it is behind the
    second PIX. Access to the internal network for this box is very limited to
    only port 443.

    IN 2 you have out two MS boxes 'out there' for the Hackers to get to and as
    Paul points out, having the [OWA] Server out there 'forces' you to open many
    ports so that Active Directory can function.

    I've tried it both ways and I strongly agreed with Paul AND 9unfortunaly in
    this case) Microsoft 2 is a 'bad' choice due simply to the un-needed
    exposure of the additional ports by putting the [OWA] in the 'DMZ'.

    Sanford Reed
    (V) 757.406.7067
    -----Original Message-----
    From: firewall-wizards-admin@honor.icsalabs.com
    [mailto:firewall-wizards-admin@honor.icsalabs.com] On Behalf Of Ben Nagy
    Sent: Tuesday, May 03, 2005 7:54 AM
    To: firewall-wizards@honor.icsalabs.com
    Subject: RE: [fw-wiz] PIX -> ISA -> OWA Configuration

    Post order fixed, response inline.

    </whips out dusty cluestick...>

    > -----Original Message-----
    [Jason Gomes]
    [...]
    >
    > What is the preferred placement for a OWA front-end server
    > given these two possible network configurations and why?
    >
    > 1) [Internet] <==> [PIX Firewall] <==> [ISA Proxy] <==> [PIX
    > Firewall] <==> [OWA] <==> [Internal Net w/Exchange Svr]
    >
    > 2) [Internet] <==> [PIX Firewall] <==> [ISA Proxy] <==> [OWA]
    > <==> [PIX Firewall] <==> [Internal Net w/Exchange Svr]

    [Paul Melson at least has courage of his convictions]
    > #1, definitely.

    Wow, this may be the first time I recall disagreeing with you, Paul...

    [Sanford Reed hides behind Microsoft documentation ;]
    > Per MS (Using Microsoft Exchange 2000 Front-End Servers.pdf -
    > available from MS TechNet) it is configuration 1).

    Once again proving that while MS have made a lot of progress in security
    some of their authors still have no idea what they are doing. The problem is
    that people get too excited about their architecture diagrams.

    I always internally parse these diagrams as:

    [spaghetti] --> [hackable box] --> [pot of gold]

    In 1) there are no controls at all between the hackable box and the pot of
    gold. In 2) there is.

    Once you simplify things the choice becomes obvious.

    But hey, you could throw another firewall into 2) if you want. And maybe an
    IPS as well. A red one, even.

    Cheers,

    ben

    (reliving the glory days of "grumpy old man" responses)

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: jimmy_at_chickenhollow.net: "Re: [fw-wiz] Hopefully not too OT"

    Relevant Pages

    • Re: Johnny Huang STILL Can NOT Answer
      ... >>>that Rich Shewmaker is Aloha Rich? ... >> Have you counted everyones' posts? ... >> of the things that Paul suggested could be downright dangerous ... >> I respect you for your opinion but respectfully disagree. ...
      (misc.health.alternative)
    • Re: A great evil : the men of Sodom & Gomorrah?
      ... If not, you would be agreeing with Christ ordained Paul, that women must be ... When beginning his letter to the Corinthians Paul states....."2 Unto the church of God which is at Corinth, to them that are sanctified in Christ Jesus, called to be saints, WITH ALL that in EVERY PLACE call upon the name of Jesus Christ our Lord, both theirs and ours." ... disagree with the Scripture itself. ... "6 For if a woman is not veiled, let her also be shorn: but if it is a shame to a woman to be shorn or shaven, let her be veiled." ...
      (uk.religion.christian)
    • Re: An Open Letter to President Obama
      ... It just means that you disagree. ... In general, I'd agree with you, but Paul brings it on himself a bit. ... He's insulting in general, and tends to get a bit harsh towards folks, ... Joe - Linux User #449481/Ubuntu User #19733 ...
      (alt.smokers.cigars)
    • Re: C++: Pointer to a string in a class
      ... If the server disallows it, ... "sever administrators", a point that may have merit, but it doesn't ... disagree with anything I posted, therefore "I disagree" seemed to have no ... Paul Lutus ...
      (comp.programming)
    • Re: Outlook Web Access alternatives
      ... > Paul wrote: ... >> away from the office with Outlook Web Access and don't like it. ... > & sync to an offline file. ... > laptop/computer and don't like OWA - well, don't bother, honestly. ...
      (microsoft.public.exchange.applications)