RE: Secure SMTP setup/ISA 2004

From: Stephane Auger (stephaneauger_at_pre2post.com)
Date: 10/26/04

  • Next message: H Carvey: "Re: IIS Logfile"
    Date: Tue, 26 Oct 2004 11:19:06 -0400
    To: <security-basics@securityfocus.com>
    
    

    There's a strong risk there. If your SMTP gets compromised, ISA is
    compromised and vice-versa. A good setup is having an ISA, with another
    server acting as an SMTP gateway (Mdaemon is pretty good for that), thus
    relaying your inbound and outbound mail to/from your Exchange.

    Stephane Auger

    -----Original Message-----
    From: Dan Tesch [mailto:dan.tesch@comcast.net]
    Sent: October 23, 2004 12:14 PM
    To: security-basics@securityfocus.com
    Subject: Secure SMTP setup/ISA 2004

    I have installed a new 2003 Server with Exchange 2003 and while planning
    the deployment I started reading and thinking about not opening my
    firewall to the Ex server and putting an SMTP server in my DMZ.

    I have a test 2003 Srvr. with ISA on it and I have the
    2003 SMTP service running - the 2003/ISA box will receive mail from the
    internet and the Ex Srvr will pull mail from ISA.

    My question is this- is this a good way to go about it with the SMTP
    service running on the ISA server?
    How likely might this be to be compromised? and being that the ISA
    server with SMTP running on it touches my LAN would it be better to have
    ISA or another firewall as the border and a separate box for SMTP?


  • Next message: H Carvey: "Re: IIS Logfile"

    Relevant Pages

    • Re: Intermittent inbound delivery to Exchange
      ... > This also sounds like it could be a problem with what addresses SMTP ... >> to forward mail to the internal Exchange 2003 server on Windows ... the queue fills on the ISA Server. ... >> use an internal DNS on the DC, ...
      (microsoft.public.exchange.admin)
    • Re: ISA 2004 SMTP Filtering
      ... But I was under the impression that the SMTP filter allowed ... Trying to make the loads on each server smaller, ... being able to deliver mail to the ISA would ... your IMail to control everything else related to relaying, spam, ect. ...
      (microsoft.public.isa)
    • Re: Intermittent inbound delivery to Exchange
      ... If ISA ... My thought is the SMTP filer is corrupt. ... > forward mail to the internal Exchange 2003 server on Windows 2003. ... > All servers use an internal DNS on the DC, ...
      (microsoft.public.exchange.admin)
    • RE: Relaying
      ... Disabled SMTP filter and things seem to be working. ... Is this the correct configuration with ISA and Exchange ... information is not sent to the Exchange server. ...
      (microsoft.public.isa)
    • Re: External messages "spoofed" as coming from our internal domain are accepted
      ... SMTP server should accept mail from any from address as long as the TO is ... > external IP of an ISA firewall. ... > for "mydomain.com" to our Exchange Server. ...
      (microsoft.public.exchange2000.transport)

  • Quantcast