RE: [fw-wiz] PIX -> ISA -> OWA Configuration

From: Thomas W Shinder (tshinder_at_tacteam.net)
Date: 05/13/05

  • Next message: Nick Brandson: "[fw-wiz] Check Point ISP Redundancy for Incoming Mail Service"
    To: <firewall-wizards@honor.icsalabs.com>
    Date: Fri, 13 May 2005 13:16:03 -0500
    
    

    Since the ISA firewall was designed to protect OWA, what would be the
    rationale for not using an ISA firewall?

    Tom
    www.isaserver.org/shinder
    Tom and Deb Shinder's Configuring ISA Server 2004
    http://tinyurl.com/3xqb7
    MVP -- ISA Firewalls

    -----Original Message-----
    From: firewall-wizards-admin@honor.icsalabs.com
    [mailto:firewall-wizards-admin@honor.icsalabs.com] On Behalf Of Chris
    Blask
    Sent: Monday, May 09, 2005 8:44 PM
    To: vbwilliams@neb.rr.com; Paul Melson
    Cc: woodsd001@hawaii.rr.com; firewall-wizards@honor.icsalabs.com
    Subject: Re: [fw-wiz] PIX -> ISA -> OWA Configuration

    Hi folks!

    At 10:47 AM 5/7/2005, Victor Williams wrote:
    >Personally, I didn't see any reason to state the obvious when it was
    there
    >for everyone to see.
    >
    >There is no *safe* or *best* way to deploy that architecture as far as
    I'm
    >concerned. The sooner everyone just accepts that, the better off
    everyone
    >will be.

    Everyone that counts (the folks who pay for all this stuff) don't give a

    mongoose's hooter what architecture is used, they just want their apps
    to
    work where they need them. On this one I agree with them
    whole-heartedly:
    I'd like to be able to read my email displayed on the fannies of
    migratory
    waterfowl. I'll settle for bioptic HUD glasses that can overlay the
    text
    as opposed to actually laser-printing on loons, but it better be no less

    secure than a workstation in a cube however it gets done.

    >I've found personally that a correctly implemented VPN solution is 1000

    >times better than trying to get OWA deployed and *safe*.

    The only problem with VPNs are kiosks and other Not-My-Computer
    situations. Webmail will be implemented (even, I shudder to say, OWA)
    because we haven't yet made VPNs fully portable.

    If you have to use OWA, I'd use one of the mail firewalls out there
    (BorderWare or IronMail, for example) in front of it. Something like
    that
    gives you a break in the chain between your MaxiSoft servers and the
    World,
    and a dev team to maintain it and pester when you feel antsy.

    -cheers!

    -chris

    Chris Blask
    chris@blask.org
    blaskworks.blogspot.com

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Nick Brandson: "[fw-wiz] Check Point ISP Redundancy for Incoming Mail Service"

    Relevant Pages

    • OWA - cannot SEND mail - unusual problem
      ... I'm running MS Exchange 2003 behind the MS ISA firewall. ... mail, calendar, and all other OWA functions work perfectly... ... This is verified by opening the account in Outlook 2003. ...
      (microsoft.public.exchange.clients)
    • RE: Ports to open for OWA from the internet
      ... > im not running the ISA firewall im using a cisco PIX ... You'll need to have port 443 open to your SBS server to get ... OWA working externally. ... to make available externally when you ran the Connect to the Internet ...
      (microsoft.public.backoffice.smallbiz2000)
    • RE: OWA Page Cannot be Found Error
      ... I'm running Exchange 2003 with an ISA firewall and when I try to open e-mails through OWA with dots in the subject line I get The page cannot be found. ... >>Our users are having trouble diplaying email messages ... >>When we access the system from inside, OWA opens ...
      (microsoft.public.exchange.connectivity)
    • Re: Problem regarding authentication
      ... Hi Tom if he's only using the server in cached mode there should be no need ... > order to send credentails to the ISA firewall. ...
      (microsoft.public.isa)
    • Re: where to install isa 2004 server
      ... > Tom and Deb Shinder's Configuring ISA Server 2004 ... I figured that I'd have to purchase another server to run ISA. ... The ISA firewall is a network firewall, ... >:> HTH, ...
      (microsoft.public.isa)