RE: Protecting an Exchange server?

From: Depp, Dennis M. (deppdm_at_ornl.gov)
Date: 05/15/04

  • Next message: lepka_at_ukr.net: "scanning NATed network question"
    Date: Fri, 14 May 2004 18:52:55 -0400
    To: Joe Polk <listuser@javelinux.com>, "Mark G. Spencer" <mspencer@evidentdata.com>, security-basics@securityfocus.com
    
    

    Joe,

    I think Mark had it correct the first time. It is not a good practice
    to allow traffic from the internet to go directly to your internal
    network. Having an intermediary in front of the firewall is the best
    bet. Of course a better solution would be to have two firewalls. One
    to protect your email gateway from the internet and the other to protect
    your internal network.

    Denny

    -----Original Message-----
    From: Joe Polk [mailto:listuser@javelinux.com]
    Sent: Friday, May 14, 2004 2:08 PM
    To: Mark G. Spencer; security-basics@securityfocus.com
    Subject: Re: Protecting an Exchange server?

    You actually would want this:

    Internet -> Firewall -> Email gateway -> Exchange

    In this scenerio, a port is opened on the Firewall to the gateway. This,
    in Exchange terms, is called a "smart host" setup. You could easily do
    this with another SMTP server, say like Sendmail on a Linux server, so
    that all mail crosses that server. This has not only the advantage you
    are looking for, but also the ability to use RBL/SBL spam protection and
    you could even add SpamAssassin to it. Of course, you could use an
    appliance too.

    <<JAV>>

    ---------- Original Message -----------
    From: "Mark G. Spencer" <mspencer@evidentdata.com>
    To: <security-basics@securityfocus.com>
    Sent: Thu, 13 May 2004 10:51:56 -0700
    Subject: Protecting an Exchange server?

    > Hello,
    >
    > I'm wondering if there is any way to locate an Exchange server on my
    > internal network and place some kind of email appliance on our DMZ to
    > actually send and receive email to the world and to the Exchange
    > server on my internal network?
    >
    > Basically, I don't want my Exchange server to be accessible to the
    > world in any way.
    >
    > So ..
    >
    > Internet -> My Email Appliance -> Firewall -> Exchange Server
    >
    > I envision setting up a dedicated route in the firewall between the
    > email appliance out on the Internet and my Exchange server behind the
    > firewall on my local network?
    >
    > Are there any email appliances that can work with Exchange in this
    way?
    > It's my (limited) understanding that Exchange server can't "pop" to
    > another email server to pull each Exchange users email, so I'm not
    > sure exactly how or if my plan could be put into action.
    >
    > Thanks,
    >
    > Mark
    >
    > ----------------------------------------------------------------------
    > ----- Ethical Hacking at the InfoSec Institute. Mention this ad and
    > get
    > $545 off any course! All of our class sizes are guaranteed to be 10
    > students or less to facilitate one-on-one interaction with one of our
    > expert instructors. Attend a course taught by an expert instructor
    > with years of in-the-field pen testing experience in our state of the
    > art hacking lab. Master the skills of an Ethical Hacker to better
    > assess the security of your organization. Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    > ----------------------------------------------------------------------
    > ------
    ------- End of Original Message -------

    ------------------------------------------------------------------------

    ---
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545
    off any course! All of our class sizes are guaranteed to be 10 students
    or less to facilitate one-on-one interaction with one of our expert
    instructors. 
    Attend a course taught by an expert instructor with years of
    in-the-field pen testing experience in our state of the art hacking lab.
    Master the skills of an Ethical Hacker to better assess the security of
    your organization. 
    Visit us at: 
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
    any course! All of our class sizes are guaranteed to be 10 students or less 
    to facilitate one-on-one interaction with one of our expert instructors. 
    Attend a course taught by an expert instructor with years of in-the-field 
    pen testing experience in our state of the art hacking lab. Master the skills 
    of an Ethical Hacker to better assess the security of your organization. 
    Visit us at: 
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------
    

  • Next message: lepka_at_ukr.net: "scanning NATed network question"

    Relevant Pages

    • Re: Exchange 4 Calendar only, Mail is externally, problem sending
      ... my case the Exchange server does NOT accept mail directly from the internet. ... The client has Outlook with both external pop3 and internal ... the user populates the mail type as "EX" instead of SMTP. ...
      (microsoft.public.exchange.admin)
    • Re: Exchange PLUS POP3
      ... That cannot be so because the SBS Internet Users rule is to allow ... their mail servers so if our Exchange server goes down we can log onto ... We need to login to the POP3 mailboxes ...
      (microsoft.public.windows.server.sbs)
    • RE: publications concerning port forwarding
      ... planned work submitted by another contractor. ... Exchange server is listed. ... This company has a PIX with a DMZ port. ... and company are planning to allow access to the server from the internet ...
      (Pen-Test)
    • Re: Missing Email Attachments
      ... The messages come from the Internet. ... please send another test mail with an attachment to the three users and keep me in CC line. ... I suggest you temporarily disable the anti-virus software and firewall on the Exchange server and test again. ... Microsoft Online Partner Support ...
      (microsoft.public.exchange.admin)