Re: Sonicwall Pro 230 DMZ windows authentication problem

From: furgus news (bob_at_furgus.com)
Date: 05/10/03


Date: Sat, 10 May 2003 15:14:24 GMT

I just replaced the w2k dmz machine with an nt4 server, and set up port 25,
135, 137 through 139 and dns between the dmz machine and the domain
controllers and now everything works fine. I expect that once I set the
registry keys to fix the rpc ports, then OWA should work.

This leaves me confused why the w2k server didn't work. I'd found a pair of
technotes on setting up exchange 2000 through a firewall dmz, and it listed
all the ports required. This would have w2k and exchange 2000 communicating
with the lan segment. I opened all these ports and alternatively created a
"default all dmz ->lan" rule but neither worked for windows authentication.
Most confusingly, there were no entries in the log of dropped traffic
between dmz and lan, so it's possible that all ports were open.

Rather then replace the dmz w2k box with another w2k box, I went backwards
to nt4, so I could close all the active directory ports.

What is the best-practice way to set up OWA through a firewall? I'm still
surprised to find no info about this, given the market share of exchange.
"Don Kelloway" <dkelloway@commodon.com> wrote in message
news:qHPua.44$mf1.21@tornadotest1.news.pas.earthlink.net...
> "Don Kelloway" <dkelloway@commodon.com> wrote in message
> news:HEPua.43$mf1.31@tornadotest1.news.pas.earthlink.net...
> > If I am mistaken, I apologize. It was originally stated that this
server
> is
> > part of the domain and that there has been issues to authenticate
because
> > the server cannot communicate with a Domain Controller (DC) or Active
> > Directory Server (ADS). This is quite opposite of being a standalone
> > server.
> >
> > A standalone server would best be described as a server that does not
> > require the need to login to or be a part of a domain. Hence its
ability
> to
> > "stand alone". A standalone server is one that you would login locally
to
> > the server itself.
> >
> > In further respect to your situation and I if I understand it correctly.
> > The purpose of the server in the DMZ is to act as an SMTP server for
> > accepting incoming mail from the 'net and subsequently relay the mail
(via
> > SMTP) to an MS Exchange server (MSX) located within the LAN. Thus the
> only
> > protocol required to be passed inbound through the firewall (from the
DMZ
> to
> > the LAN) is SMTP (TCP port 25). Nothing else is required. And a
> previously
> > stated, to prevent authentication related issues between the server on
the
> > DMZ and the DC or ADS, ensure that you login locally to the server on
the
> > DMZ.
> >
>
> While I did not specify it. You also need to ensure that the firewall is
> configured to allow SMTP (TCP port 25) from the Internet (WAN) to the DMZ.
>
> --
> Best regards,
> Don Kelloway
> Commodon Communications
>
> Visit http://www.commodon.com to learn about the "Threats to Your Security
> on the Internet".
>
>



Relevant Pages

  • RE: fedora-list Digest, Vol 6, Issue 266
    ... Re: OT: Setting up a forwarding mail domain in DMZ without ... Re: Sound Problem ... downloaded the yum.conf for fedora from Redhat's website. ... Server: Fedora.us Extras ...
    (Fedora)
  • RE: [fw-wiz] Backup exec agent in dmz
    ... This way you could block these specific ports inbound from the ... mail/antivirus server, a dns server, and a web server. ... I have a windows 2000 server running backup exec version 9 on the primary ... have to set up a separate backup system for the dmz computers. ...
    (Firewall-Wizards)
  • RE: [fw-wiz] Single Exchange/OWA on LAN with Internet Access - a good
    ... OWA front ended by ISA 2003 is solid. ... DMZ - it is designed to "publish" MS products including MS CRM. ... The DMZ server should be able to do ... more than just port filtering and *shouldn't* require all those ports to ...
    (Firewall-Wizards)
  • Re: DMZ & Security
    ... > yes, deployement price, security level (depending what ... > open ports... ... > case what sense has my DMZ? ... if I have a web server on DMZ that have to access sqlserver database ...
    (microsoft.public.security)
  • Re: Best Practices for exposing Exchange to web
    ... >server in the DMZ that handles web access. ... >We are in the process of migrating to Exchange server and I am investigating ... This seems a little scary opening up all these ports ...
    (microsoft.public.exchange.admin)