Re: DMZ setup on firewall
From: John (jwholmes_at_earthlink.net)
Date: 08/06/03
- Next message: Robin T Cox: "Re: Seek MD5 Hash of Kerio PFWADMIN.EXE v2.15"
- Previous message: John: "Re: need comments on proposed network archtecture-correct diagram this time"
- In reply to: Phil: "Re: DMZ setup on firewall"
- Next in thread: Phil: "Re: DMZ setup on firewall"
- Reply: Phil: "Re: DMZ setup on firewall"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 06 Aug 2003 06:58:55 GMT
On Mon, 04 Aug 2003 19:38:13 -0700, Phil wrote:
> What if the server on the DMZ were an MS Exchange 2K server that
> needed to have OWA access to the internet as well as a connection the
> the protected network. Could you put 2 network cards on the Exchange
> server and point one nic to the DMZ and one nic to the protected
> network. Could this configuration work if the DMZ had a public IP
> address and the other nic had a private IP address? Would there be any
> security issues between the nic's.
>
> I have only one Exchange server and I am required to supply OWA to
> home users through a PIX 515.
>
> Thanks for any help.
>
Please do not circumvent your firewall by using dual nics!!!! Yes there
are potentially huge risks of doing this.
Put the owa box in the dmz. The PIX will allow access from the inside
interface to the dmz interface by default. Then put a rule in the
access-list on the outside interface to allow access to the owa box only
on port 443 and if you must port 25. You will also need to give it a
public address or else do a nat 0.
I think so highly of the security of Exchange that I prefer to put a
Postfix or Qmail box to deal with mail to/from the public and not list the
exchange box in dns as a mail server. The unix mail server will be a sort
of proxy for Exchange with it passing mail between Exchange and the world.
I only allow port 443 access to the Exchange box from the outside.
-- ___________ John Holmes jwholmes@earthlink.net
- Next message: Robin T Cox: "Re: Seek MD5 Hash of Kerio PFWADMIN.EXE v2.15"
- Previous message: John: "Re: need comments on proposed network archtecture-correct diagram this time"
- In reply to: Phil: "Re: DMZ setup on firewall"
- Next in thread: Phil: "Re: DMZ setup on firewall"
- Reply: Phil: "Re: DMZ setup on firewall"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|