Re: Exchange Server in DMZ

From: ObiWan (anzen.NO_at_SPAM.gmx.net)
Date: 12/14/04


Date: Tue, 14 Dec 2004 17:57:17 +0100


> I helping to setup A Exchange server in a DMZ, what port(s)
> do I need to open for the server to participate in the local domain ???

Oh boy ... you'll need to open a whole lot of "sensible" ports since
the machine will need to join the domain, so all the netbios traffic
and so on... this in turn will drill a whole lot of holes between your
DMZ and your LAN, not a good thing imho, if possible, I'd suggest
you to place a simple SMTP server on the DMZ (the IIS SMTP will
do as well) and configuring it to forward mail to the Exchange server
sitting on your LAN, this will only require opening port 25 between
DMZ and LAN and won't expose your LAN to so many risks; by the
way this isn't feasible if you need to publish OWA, in such a case
you'll need to put the Exchange on the DMZ but .. in this case I'd
suggest installing the Exchange as a standalone machine and
not as a domain member; I know this means duplicating users
accounts and so on, but it you want to keep things secure it's
the only real way to do it imho

Regards

-- 
* ObiWan
Microsoft MVP: Windows Server - Networking
http://www.microsoft.com/communities/MVP/MVP.mspx
http://mvp.support.microsoft.com
DNS "fail-safe" for Windows clients.
http://ntcanuck.com
408+ XP/2000 tweaks and tips
http://ntcanuck.com/tq/Tip_Quarry.htm


Relevant Pages

  • Re: Web portal security
    ... win2003 standard server with IIS, SSL enabled and will be placed on ... So I will be fwding port 443 in firewall to my DMZ port. ... Well, assuming you are going to use teh SQL database from SBS, you can ... subnet than my LAN and map one to one from firewall to dmz. ...
    (microsoft.public.windows.server.sbs)
  • Re: 2 NICs Configuration Problem
    ... Servers on the DMZ are public, ... provides NAT for the LAN machines, allowing them to reach the Internet ... effectively bypassing firewall filtering to that server. ... Ethernet adapter Server Local Area Connection: ...
    (microsoft.public.windows.server.networking)
  • Re: Where to put the server
    ... Put the 2003 IIS Server in the DMZ. ... SBS box or another LAN server. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Groklaws "Bias" and the SCO DDoS Attack
    ... >on the same local LAN your office machines are you can congest that ... routers, with port 80 redirected to a web server on the LAN side. ... I've also used Sonicwall DMZ routers. ...
    (comp.unix.sco.misc)
  • Re: Hosting, in or out?
    ... proprietary SQL based application is the core of the business. ... A new requirement calls for a report only server, ... SBS LAN is called PRIVATE or LAN ... Web LAN is called RESTRICTED or DMZ ...
    (microsoft.public.windows.server.sbs)