Re: Sonicwall Pro 230 DMZ windows authentication problem

From: David (davidwnh_at_adelphia.net)
Date: 05/11/03


Date: Sun, 11 May 2003 18:26:51 GMT


> If I continue with the plan to run owa in the dmz and exchange in the lan,
> with exchange on a w2k box, and I'm indifferent (although preferring w2k)
> for the dmz box os, are you saying that I'd be better off with exchange
2000
> over 5.5? This is a company with only three mail accounts for 6 users,
with
> minimal requirements, so there's no reason to upgrade unless there are
> compelling security reasons.
With three accounts for six users upgrading almost anything is not cost
effective I would think. If you are only giving them additional access from
their homes then you might be able to use packet filters for all of your
server access into the DMZ. If you can packet filter ALL your available
internet access to the DMZ services so that you are not effectively allowing
public access to any of them, then having some of the additional DMZ to LAN
connections for NetBIOS, RPC, AD, etc. is not nearly as bad and can be done
with a lot less risk. If you are looking to give them access from the road,
however, then packet filtering may not be an option, so you would
effectively be setting up the services for public access. You can run the
services on high non standard ports to hide them from the usual automated
scanning tools and worms, which isn't perfect but also severely reduces the
risk associated with what you are trying to do. (This may not be possible
with FTP since NAT translators are used with NAT traversals and are usually
only applied to the normal FTP ports) Otherwise if you are trying to provide
mobile access and hence cannot effectively use packet filtering then setting
up one of your internal servers for RAS dial-ins might be a better solution.
If your mobile users are dialing into ISP's for this then you may not be
reducing the bandwith available in the first place, and are possibly only
looking at a higher long-distance bill, since RAS comes with the server OS.
Otherwise VPN connections might be feasible if you already have most or all
of the capability.

The Planning Guide for Exchange Server explains the different ports
necessary between the two versions. It's Chapter 10-Planning OWA Access
Servers. I get my info from a Technet Subscription, but this info should be
reproduced somewhere on MS's Technet website. The big difference is that
with Exchange 2000 the fe/be connection works through http/DAV as opposed to
using MAPI.

For Exchange 2K you simply have to look at what each port is for to figure
out how to eliminate its access. OWA queries the global catalog to find the
backend exchange server that has the user store for each specific user
logging in. Since you only have one user store than the lookup is
unnecessary because all OWA access will be retrieving information from the
same backend exchange server and can be "hardcoded". This is also found
somewhere in Technet, and probably also on the MS Technet website.
>
> Is there a techno you can point me to that explains the port requirements
> and the technique for limiting the ports as you describe?



Relevant Pages

  • RE: Webserver on a DMZ still needed?
    ... Certainly your suggestion to have a email server in a DMZ but still have ... having the exchange server on the internal LAN with only the smtp ports ... Talking of the financial cost of setup by the book vs the security cost ...
    (Security-Basics)
  • Re: Exchange, OWA and SBS2003
    ... OWA in the DMZ, it should be the front-end Exchange. ... I'm planning to run SBS 2003 and I would like the server to host ... I would also like to use OWA to be able to read my emails when I'm ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS2k Exchange recovery - HELP!
    ... as it pulls mail out into a SQL database. ... I discovered something else I didn't know about Exchange.. ... If I could have got OWA working from the RDP into the Server (so only ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Exchange 2003 OWA
    ... Please check SMTP addresses setting for Exchange Virtual Server ... Path" of the OWA virtual server he/she is trying to use. ... Install MBExplorer by installing IIS 6 Resource Kit Tools:http://www.microsoft.com/downloads/details.aspx?FamilyId=56FC92EE-A71 ... ...
    (microsoft.public.windows.server.sbs)
  • RE: OWA HTTP 500 Error for users, but not for Admin (?)
    ... None of the previously added users can see the right side panel in OWA ... Exchange Server via OWA, you cannot see the right pane in OWA; ... Right click on Exchange virtual directory, ...
    (microsoft.public.windows.server.sbs)