RE: Webserver on a DMZ still needed?



* We must have enough IT controls and infra setup to achieve the secured
computing network/ services *

Coming from above statement --
Lets have the Main Exchnage Server inside your LAN and build a separate
OWA server (for roaming/ remote users). The OWA box must be kept in the
DMZ only with open only bare min. ports for domain authentication &
Exchnage Server.
This way we can have secured environment established for Messaging
services.

Thanks,
- Neeraj

-----Original Message-----
From: Peter Marshall [mailto:Peter.Marshall@xxxxxxxx]
Sent: Tuesday, September 05, 2006 10:02 PM
To: Davie Elliott - Eluse; security-basics@xxxxxxxxxxxxxxxxx
Subject: RE: Webserver on a DMZ still needed?

It is still recommended to have your exchange box (and any other outward
accessible services) hosted in a DMZ to prevent access to the internal
segment if they are compromised. If you do put the exchange box in the
DMZ, however, you need to open up a bunch of ports to allow the exchange
box to query the global catalog, perform authentication, etc. which, to
a certain degree, removes the safety added by having it in the DMZ in
the first place. MS recommends using front end/back end exchange
servers coupled with an ISA server to do it by the book but this is
expensive and complicated for a small/mid sized organization. Many
small/mids simply place the exchange server on the inside and only open
up tcp 25 (SMTP) and TCP 443 (HTTPS for OWA) to that box.

In your instance, since the exchange box is also a DC, I would not
recommend putting it into the DMZ. Technically, you should split those
roles for performance and security but again, budget is sometimes more
important than doing everything by the book.


Cheers,

-----Original Message-----
From: Davie Elliott - Eluse [mailto:delliott@xxxxxxxxxxx]
Sent: Sunday, September 03, 2006 7:43 AM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: Webserver on a DMZ still needed?

Hi all,

I have been working as a systems admin for a charity for about 3 years,
I have no schooling in network I have learnt everything myself. During
my research I read that servers with public services should be put on a
separate subnet which is used as a DMZ (such as POP3, SMTP, webserver
ect).

Recently I have left that charity and a network company is taking over
the administration, and they want to put the Exchange (email) server on
the trusted network subnet (the network has a smoothwall firewall, so
there are literally 2 separate networks). My question is this: does the
Exchange server definatly, need to be put in the DMZ? Or should
Microsoft have patched all the vulnerabilities by now? There isn't any
other software on the server, such as forums which I see have
vulnerabilities found just about ever day.

Secondly, if the Exchange server is on the DMZ subnet, how do you get it
to interact securely with the Domain Controller on the secure subnet?
When I built the network, I made the Exchange server its own Domain
Controller.

Thanks for your advice,

Davie Elliott



------------------------------------------------------------------------
---
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE The NSA has
designated Norwich University a center of Academic Excellence in
Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting
experience.
Using interactive e-Learning technology, you can earn this esteemed
degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
------------------------------------------------------------------------
---


------------------------------------------------------------------------
---
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE The NSA has
designated Norwich University a center of Academic Excellence in
Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting
experience.
Using interactive e-Learning technology, you can earn this esteemed
degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
------------------------------------------------------------------------
---


---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • RE: Webserver on a DMZ still needed?
    ... Certainly your suggestion to have a email server in a DMZ but still have ... having the exchange server on the internal LAN with only the smtp ports ... Talking of the financial cost of setup by the book vs the security cost ...
    (Security-Basics)
  • Re: Netzschema
    ... Wenn du den SMTP Server in der DMZ zusätzlich auch als OWA Server verwenden möchtest, bedeutet das zwangsläufig, dass du Exchange installieren musst. ... Insofern braucht der DMZ Exchange auch entsprechende Zugriffe auf das AD. ... Denke an das Regelwerk, das nötig ist, um alleine den Intra-Domain-Traffic zu routen, zusätzlich zu den SMTP und Publishing-Regeln. ...
    (microsoft.public.de.german.isaserver)
  • Re: Netzschema
    ... Insofern braucht der DMZ Exchange auch entsprechende ... dass du durch den ISA Server etliche ... Stell doch deinen OWA Server in die Domain und publishe SMTP und OWA durch ...
    (microsoft.public.de.german.isaserver)
  • Re: Exchange, OWA and SBS2003
    ... I'm planning to run SBS 2003 and I would like the server to host ... My hope is to have SBS host my exchange server with about 10 ... I have a 3Com OfficeConnect firewall box with a DMZ ...
    (microsoft.public.windows.server.sbs)
  • Re: Critical services to unblock?
    ... "I am secure because I have a Firewall" ... "I am secure because I use a DMZ" ... Probably the best answer to that would be that if the Server is compromised ... It sounds like it is an SQL Server in your case,...therefore with the server ...
    (microsoft.public.isa.configuration)