Re: Why is Win Explorer accessing the Net?

From: David (davidwnh_at_adelphia.net)
Date: 12/25/03


Date: Thu, 25 Dec 2003 07:28:28 GMT

You don't mention the version of Exchange server, but I would use
Exchange Web access. It's not very cost effective to set up a vpn unless
the users need other lan access also. You can use SSL to encrypt and
also client certificates to make authentication tighter.

Avoid using anything over the internet that requires access to the
portmapper unless it is over a vpn or other secure link. There are still
unresolved issues with it and probably always will be.

>
> Here's an issue that I've run into that perhaps you could clue
> me in on:
>
> Client contacts Exchange Server (pre-AD). Client negotiates
> a port via RPC (TCP 135). Client holds short TCP conversation and
> drops the connection. Later (a few hours, up to a couple of weeks),
> Exchange server wishes to send information to client. Exchange
> server attempts to contact client at -same- IP address and port
> that client used last time they connected many days before.
> Firewall does not let server through because the original port
> the client used was dynamically allocated and the TCP connection
> had been closed long ago. Exchange server retries and retries
> and retries, persisting in attempting to contact the dynamic
> TCP port for over a week.
>
> Now, not having control over the corporate Exchange servers, how
> can I configure the client to stop the server from remembering the
> ip + port (both of which could have been dynamically allocated) --
> or how can I *reasonably* configure a stateful firewall to
> recognize this situation and make the appropriate back-connection
> even if the public IP has been long ago reallocated?



Relevant Pages

  • Re: Problem viewing messages generated with OWA on Groupwise web c
    ... message properly in IE without manually changing the encoding. ... yahoo.mail to Groupwise web mail, but it does with messages sent from our ... used if a client does understand UTF-8. ... Exchange Server 2003 SP2 ...
    (microsoft.public.exchange.admin)
  • Re: POP3 and Firewalls
    ... The user does not want to VPN. ... >> remote user who wants from home to download his email to a mail client ... >> our exchange server. ...
    (microsoft.public.exchange.setup)
  • Re: Problem viewing messages generated with OWA on Groupwise web c
    ... it is viewable without having to change the encoding. ... using their Groupwise Web client, but I really need to find a solution on the ... used if a client does understand UTF-8. ... Exchange server to site #2, the message is viewable with the GroupWise Web ...
    (microsoft.public.exchange.admin)
  • Re: outlook VPN ports
    ... With a vpn it is not really the ports it is the ability of the client to ... resolve the Exchange server by name. ...
    (microsoft.public.exchange2000.clients)
  • Re: VPN and Exchange. Unable to connect
    ... I have an issue with connecting to the Exchange server thru VPN. ... but not from VPN client. ...
    (microsoft.public.windows.server.dns)