[fw-wiz] PIX -> ISA -> OWA Configuration

woodsd001_at_hawaii.rr.com
Date: 05/04/05

  • Next message: Paul D. Robertson: "RE: [fw-wiz] Hopefully not too OT"
    To: firewall-wizards@honor.icsalabs.com
    Date: Wed, 04 May 2005 11:02:34 -1000
    
    

    Option #1 would have to be the worst option for security, all you have
    to do is re-read Ben Nagy's response and think about it for a few more
    minutes. When you place the OWA server directly into your internal
    network without controls, you have no controls unless of course you
    truely believe that a Microsoft product is not considered a "Hackable
    device" and in this case we are talking about two Microsoft products -
    ISA Proxy Server and OWA.....
    [spaghetti] --> [hackable box] --> [hackable box] --> [pot of gold]

    Option #2 is the better solution since there is atleast on additional
    contol added in the diagram.

    -----Original Message-----
    Subject: Re: [fw-wiz] PIX -> ISA -> OWA Configuration

    Definitely. In #1, if the ISA server is configured via the OWA publishing
    wizard, it will create ACL's that prevent requests that don't match
    /exchange/* from being passed to IIS. You can also run urlscan at the ISA
    server (though it requires some tweaking to keep from breaking some of OWA's
    functionality).

    In #2, the same thing applies, but should the ISA server be compromised say
    via buffer overflow, then there is no protection for the internal AD domain,
    since those holes must be punched straight through the firewall (and they
    are BIG holes).

    PaulM

    -----Original Message-----
    Subject: Re: [fw-wiz] PIX -> ISA -> OWA Configuration

    Definitely? Under #1 it seems like something as simple as a directory
    traversal attack against IIS/OWA that manages to get through ISA leaves your
    entire internal network exposed. Under #2 it appears to me that an attacker
    would need at the very least a second exploit to gain further access to the
    trusted network.

    > -----Original Message-----
    > What is the preferred placement for a OWA front-end server given these
    > two possible network configurations and why?
    >
    > 1) [Internet] <==> [PIX Firewall] <==> [ISA Proxy] <==> [PIX Firewall]
    > <==> [OWA] <==> [Internal Net w/Exchange Svr]
    >
    > 2) [Internet] <==> [PIX Firewall] <==> [ISA Proxy] <==> [OWA] <==>
    > [PIX Firewall] <==> [Internal Net w/Exchange Svr]
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul D. Robertson: "RE: [fw-wiz] Hopefully not too OT"

    Relevant Pages

    • Re: odd owa issue
      ... Since you access the OWA from external thru ... On the SBS 2003 Server open the Server Management console. ... Please open the ISA management console, ...
      (microsoft.public.windows.server.sbs)
    • Re: ISA 2006 configuration question - multiple VLANs and domains
      ... very familiar with network segments vs. domains et. al. ... multihomed ISA 2006 server forward a DHCP request to the proper VLAN ... ISA is a Firewall Product designed to protect a network from the Internet. ...
      (microsoft.public.isa.configuration)
    • RE: Firewall service and remoteaccess service shut down frequently
      ... Do you have run the CEICW after installing the ISA components? ... please open SBS server management console, ... Click the Add Adapter button, and add your internal network adapter ... Meanwhile, from the subject, you said you the firewall service and RRAS ...
      (microsoft.public.windows.server.sbs)
    • Re: VPN breaks after installing patches
      ... I have just received your email due to some network traffic problems. ... access the network shares was denied by ISA Server. ... Open the Server management console, navigate to "Internet and E-mail", ...
      (microsoft.public.windows.server.sbs)
    • Re: Connect the SBS to a remote IIS for Internet Printing
      ... the server can access the Internet with no problems at all. ... Checking network connection, and after a few seconds it says The ... the problem is cause by the configuration of ISA. ...
      (microsoft.public.windows.server.sbs)