Re: Email server+network architecture

From: Michael Osten (mosten@bleepyou.com)
Date: 01/15/03

  • Next message: John_Buhler@notes.tcs.treas.gov: "Re: Associating Windows Processes to TCPIP Ports?"
    Date: Wed, 15 Jan 2003 13:40:18 -0500 (EST)
    From: Michael Osten <mosten@bleepyou.com>
    To: dataclaus1@hushmail.com
    
    

    >
    > I can set up a 'corporate' mail server Inside (and no external linkage)without much trouble. But then the external-permitted people have to manage two accounts, one for inside and one for external mail (since those having external mail are some of the least computer savvy, this is not the best answer).

    Set up forwarding rules for the people that access mail externally so that
    all mail is forwarded to the correct mail server.

    It gets messy, but it looks like things around there are messy any due to
    policy.

    >
    > Research indicates that putting a mail server Inside and then configuring a conduit through our firewall is the least preferable option, as compromise would allow Inside access.
    >

    Uh? Maybe, but you've got to get mail in and out right? just set the
    tightest set of access rules you can think of. I would assume that there
    are "open" ports on your firewall currently right?

    > We don't want to place the server in the DMZ because then we'd have to permit smtp/POP3 to all users outside, and this does not meet the 'no customer data Outside' criteria.

    that is completly untrue. Bind the service to a particuliar interface, or
    restrict access based on netbock.

     



    Relevant Pages

    • Port Forwarding and 1:1 NAT dilemma with email
      ... I looked for a firewall problem previously, but could find no fault with the ... and x.x.x.34 to our mail server. ... I changed the 1:1 NAT on the SonicWall a month ago to point to the IP of our ... spam firewall to forward acceptable mail to the IP of our mail server. ...
      (microsoft.public.windows.server.networking)
    • Re: Exchange emails ending up in Outlook 2007 junk folder
      ... be opened in my firewall for an SBS installation? ... Your mail server is not answering, and I cannot telnet to it. ... this may be the recipient email server issue. ...
      (microsoft.public.windows.server.sbs)
    • Re: Setting another machine as a firewall
      ... I don't think a firewall is really the right technology to ... The alternative to implementing a proxy mail server on your firewall ... internet, then that is just a matter of writing filter rules to allow ... As far as DNS goes, combining a NAT'ing firewall with a mailserver on ...
      (freebsd-questions)
    • Re: Need Advice to form outbound rule -Vista, WindowsMail and Symantec
      ... Antivirus scanning of mail often takes so long that mail clients and/or servers think that the mail server is non-responsive. ... I don't use the Norton Firewall. ... But Windows Mail is being blocked, ...
      (microsoft.public.windows.vista.security)
    • Re: Firewall and DMZ topology
      ... If the MAIL server is in the DMZ. ... >able to sniff all the traffic on the internal side of the firewall, ... >>The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
      (Security-Basics)

    Loading