Re: Protecting an Exchange server?

From: Ned Fleming (ned_at_kaw.us)
Date: 05/14/04

  • Next message: Kelly Martin: "Re: INSTALLING MYSQL PHP"
    To: <security-basics@securityfocus.com>
    Date: Fri, 14 May 2004 12:44:48 -0500
    
    

    On Thu, 13 May 2004 10:51:56 -0700, "Mark G. Spencer"
    <mspencer@evidentdata.com> wrote:

    >I'm wondering if there is any way to locate an Exchange server on my
    >internal network and place some kind of email appliance on our DMZ to
    >actually send and receive email to the world and to the Exchange server on
    >my internal network?

    Windows only? Sure, there's no doubt $$$ something.

    If you're willing to dip your toe into open source, I recommend
    postfix running on FreeBSD (or on Linux). Total cost: the price of the
    PC -- and the time you spend installing and configuring it, which may
    not be insubstantial. It's not overwhelming (I did it), but if you've
    never administered Linux or FreeBSD, well, you might want to start
    elsewhere.

            http://www.linuxjournal.com/article.php?sid=4241

    It's not an appliance, per se, but pretty close.

    >Basically, I don't want my Exchange server to be accessible to the world in
    >any way.

    Excellent idea.

    >
    >So ..
    >
    >Internet -> My Email Appliance -> Firewall -> Exchange Server
    >
    >I envision setting up a dedicated route in the firewall between the email
    >appliance out on the Internet and my Exchange server behind the firewall on
    >my local network?

    You won't set up a route. Instead, you'll point your DNS MX record to
    the box on the DMZ. Then you'll set up a transport map on the DMZ box
    that points to your internal Exchange box. Note: "transport map" is
    the terminology postfix uses; you might see it listed as a
    "smarthost." You'll also point your Exchange box to the DMZ box as its
    "smarthost."

    >Are there any email appliances that can work with Exchange in this way?
    >It's my (limited) understanding that Exchange server can't "pop" to another
    >email server to pull each Exchange users email, so I'm not sure exactly how
    >or if my plan could be put into action.

    Hmmm. Are you wanting to make your users' email accounts available to
    them outside your network? If so, that's a separate story.

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: Kelly Martin: "Re: INSTALLING MYSQL PHP"

    Relevant Pages

    • Re: Deploying microsoft exchange 2003
      ... Not recommended in the DMZ - it typically sits on your internal network, ... I haven't worked before with microsoft exchange but now, ... DMZ or inside. ... some clients in the external network. ...
      (microsoft.public.exchange.design)
    • RODC deployment in DMZ,
      ... I am in the middle of migration AD and Exchange. ... The client is asking if RODC is supported in DMZ. ... I am not able to locate any information so far if MS is supporting the RODC ... with limited risk towards your internal network when the box gets ...
      (microsoft.public.windows.server.active_directory)
    • Re: Add frontend server - Exchange 2000
      ... Generally, it is not a good practice to put Exchange FE in a DMZ, because it is a domain member and you have to open a number of ports if you want to allow the necessary traffic to the internal network. ... Another solution is to use ISA Server, where you can publish your FE server placed again in the internal network. ...
      (microsoft.public.exchange.setup)
    • Re: Running Exchange 2000 on a DMZ
      ... Do you now realize that Exchange needs to ... Exchange in a DMZ? ... >> server in the DMZ (the exchange server) that needs to talk to AD thus ... >> opening quite a few holes from the DMZ to the internal network. ...
      (microsoft.public.exchange.setup)
    • Re: Protecting an Exchange server by placing on LAN?
      ... So long as you set the appliance to push the ... scanned email to Exchange via SMTP you should be good to go. ... > internal network and place some kind of email appliance on our DMZ to ... > actually send and receive email to the world and to the Exchange server on ...
      (microsoft.public.exchange.admin)