RE: Exchange in the DMZ

From: David Sommers (dsommers@dialogmedical.com)
Date: 11/26/02

  • Next message: Jack Lyons: "RE: Exchange in the DMZ"
    Date: Tue, 26 Nov 2002 12:13:35 -0500
    From: "David Sommers" <dsommers@dialogmedical.com>
    To: "Pidgorny, Slav" <slav.pidgorny@anz.com>, "Dean Pullen" <deanpullen@yahoo.com>, <focus-ms@lists.securityfocus.com>
    

    I agree as well. ISA server has many benefits to using
    front-end/back-end Exchange Servers. Including the fact that you have
    to run Exchange Enterprise as the front-end server, which costs more
    than the Standard version. Plus ISA offers protection to OWA (web
    access) and can provide externally encrypted RPC handling for directly
    connecting Outlook from the Internet to your Exchange server.

    This article provides information on whether or not ISA will benefit
    you.
    http://www.fawcette.com/dotnetmag/2002_12/magazine/columns/maximumexchan
    ge/

    /David.

    -----Original Message-----
    From: Pidgorny, Slav [mailto:slav.pidgorny@anz.com]
    Sent: Monday, November 25, 2002 10:54 PM
    To: Dean Pullen; focus-ms@lists.securityfocus.com
    Subject: RE: Exchange in the DMZ

    Dean,

    Some details about the error messages you have and event log entries
    would be useful. Is there NAT in the picture? Can you resolve DNS names
    on the DNS supporting AD? What about other connectivity (LDAP, LDAP to
    GC, Kerberos over TCP and UDP, CIFS)?

    Try to run Netmon and capture traffic from the front-end server during
    startup. It helps.

    Genarally, I would recommend against Exchange front-end in DMZ because
    too much connectivity is required back to the private intranet. Also I
    think that DMZ should be a separate authentication domain.

    Regards

    Slav

    -----Original Message-----
    From: Dean Pullen [mailto:deanpullen@yahoo.com]
    Sent: Saturday, 23 November 2002 10:01 PM
    To: focus-ms@lists.securityfocus.com
    Subject: Exchange in the DMZ

    Hi guys,

    I've basically been told that we require an Exchange
    system operated within our DMZ setup. After much
    reading I've decided to go for a front-end, back-end
    Exhange system, with the Exchange front-end in the DMZ
    and the back-end in the LAN. However, even though I've
    opened up all the ports specified in MS' white papers
    between the DMZ and LAN, I cannot connect to the
    domain/active directory from the Front-End server. How
    do I go about this? I mean all I am trying at the
    moment is to connect to our internal Domain by
    accessing the network ID in the My Computer properties
    and trying typing in the Domain. Do I have to do
    anything else?! Sorry for my amateurishness(!) but
    we're a small firm and cannot afford a fully-fledged
    exchange specialist, thus I'm doing it!

    Thanks in advance.

    Dean Pullen.

    __________________________________________________
    Do you Yahoo!?
    Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
    http://mailplus.yahoo.com



    Relevant Pages

    • RE: Webserver on a DMZ still needed?
      ... Certainly your suggestion to have a email server in a DMZ but still have ... having the exchange server on the internal LAN with only the smtp ports ... Talking of the financial cost of setup by the book vs the security cost ...
      (Security-Basics)
    • RE: Webserver on a DMZ still needed?
      ... OWA server. ... Webserver on a DMZ still needed? ... It is still recommended to have your exchange box (and any other outward ... to interact securely with the Domain Controller on the secure subnet? ...
      (Security-Basics)
    • Re: Netzschema
      ... Wenn du den SMTP Server in der DMZ zusätzlich auch als OWA Server verwenden möchtest, bedeutet das zwangsläufig, dass du Exchange installieren musst. ... Insofern braucht der DMZ Exchange auch entsprechende Zugriffe auf das AD. ... Denke an das Regelwerk, das nötig ist, um alleine den Intra-Domain-Traffic zu routen, zusätzlich zu den SMTP und Publishing-Regeln. ...
      (microsoft.public.de.german.isaserver)
    • Re: Netzschema
      ... Insofern braucht der DMZ Exchange auch entsprechende ... dass du durch den ISA Server etliche ... Stell doch deinen OWA Server in die Domain und publishe SMTP und OWA durch ...
      (microsoft.public.de.german.isaserver)
    • Re: Exchange, OWA and SBS2003
      ... I'm planning to run SBS 2003 and I would like the server to host ... My hope is to have SBS host my exchange server with about 10 ... I have a 3Com OfficeConnect firewall box with a DMZ ...
      (microsoft.public.windows.server.sbs)