RE: [fw-wiz] Single Exchange/OWA on LAN with Internet Access - a good

From: Thomas W Shinder (tshinder_at_tacteam.net)
Date: 11/17/05

  • Next message: Behm, Jeffrey L.: "RE: [fw-wiz] Single Exchange/OWA on LAN with Internet Access - a good"
    To: "Ravdal, Stig" <SRavdal@Quiznos.com>, <firewall-wizards@honor.icsalabs.com>
    Date: Thu, 17 Nov 2005 11:30:09 -0600
    
    

    Hi Stig,

    The front-end/back-end Exchange Server topology was *never* about
    security, it was about load balancing and routing.

    You can put the FE Exchange Server in a authenticated access DMZ, as
    I've done many times, but there's no point to putting the FE Exchange
    Server in an anonymous access DMZ.

    HTH,
    Tom

    Thomas W Shinder, M.D.
    Site: www.isaserver.org
    Blog: http://spaces.msn.com/members/drisa/
    Book: http://tinyurl.com/3xqb7
    MVP -- ISA Firewalls
    **Who is John Galt?**

     

    > -----Original Message-----
    > From: firewall-wizards-admin@honor.icsalabs.com
    > [mailto:firewall-wizards-admin@honor.icsalabs.com] On Behalf
    > Of Ravdal, Stig
    > Sent: Thursday, November 17, 2005 9:50 AM
    > To: firewall-wizards@honor.icsalabs.com
    > Subject: [fw-wiz] Single Exchange/OWA on LAN with Internet
    > Access - a good
    >
    > Hi everyone,
    >
    > I hope that someone has been through this before and have some
    > substantial arguments for/against:
    >
    > Our MS admins are proposing to implement single OWA/Exchange servers
    > on the LAN and allow access directly to the server through
    > the firewall.
    > The primary reason for doing it this way is to reduce the cost of the
    > front-end server that would otherwise reside in a DMZ.
    > Their argument
    > is that with OWA 2003 you have to have a bunch of ports open anyway
    > and so what is the reason to put a front end server in the DMZ - if
    > that server were compromised they would practically have
    > access to the
    > network anyway. With the OWA/Exchange server inside the firewall
    > access from the Internet can be limited to 80 and/or 443 only.
    >
    > My concern is that with the next OWA vulnerability someone will own
    > the server in the DMZ through a single exploit. However, I cannot
    > find anything that suggests that the front end server solution is
    > really any more secure. Yeah it's another hop but it would
    > be an easy
    > one as soon as the front end server is compromised.
    >
    > Thoughts?
    >
    > Thanks,
    >
    > Stig
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizards@honor.icsalabs.com
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    >
    >
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Behm, Jeffrey L.: "RE: [fw-wiz] Single Exchange/OWA on LAN with Internet Access - a good"

    Relevant Pages

    • RE: fedora-list Digest, Vol 6, Issue 266
      ... Re: OT: Setting up a forwarding mail domain in DMZ without ... Re: Sound Problem ... downloaded the yum.conf for fedora from Redhat's website. ... Server: Fedora.us Extras ...
      (Fedora)
    • Re: Exchange Server in DMZ
      ... > do I need to open for the server to participate in the local domain ??? ... DMZ and your LAN, not a good thing imho, if possible, I'd suggest ... do as well) and configuring it to forward mail to the Exchange server ...
      (comp.security.firewalls)
    • RE: Webserver on a DMZ still needed?
      ... Certainly your suggestion to have a email server in a DMZ but still have ... having the exchange server on the internal LAN with only the smtp ports ... Talking of the financial cost of setup by the book vs the security cost ...
      (Security-Basics)
    • RE: Exchange Server and External Access
      ... You don't need windows advanced server for FE/BE setup. ... I wouldn't recommend putting FE in DMZ, because you need to punch holes into your firewall aside of 80/443. ... Exchange Server and External Access ... Symantec is the Diamond sponsor. ...
      (Security-Basics)
    • Re: Best Practices for exposing Exchange to web
      ... You suggest setting up a ISA server in the DMZ so I have a few questions. ... >>We are in the process of migrating to Exchange server and I am ...
      (microsoft.public.exchange.admin)