Exhange 5.5 Behind Firewall?

From: Steve (howard_steve@medicalert.org)
Date: 08/08/02


From: "Steve" <howard_steve@medicalert.org>
Date: Thu, 8 Aug 2002 11:58:26 -0700


We just recently moved our Exhcnage Server from our
internal LAN to our DMZ for protection.

  But In the process, I have had to make a lot of changes
and open ports just to allow the Exchange server to work.
Backup went from 15 minutes to several hours.

  Was it worth it? The jury is still out.

   I could have left it where it was, with only 3 ports
open ( 80,443, and 25) and watch it closely, or the
current plan on the DMZ but with HTTP, HTTPS, SMTP,
NETBIOS, RPC, Static DS and ISA ports mapped, and the list
goes on.

  And, when I move to Exchange 2000, I will need to open
more for AD Replication.

  How are most of you maintaining your email servers, on
the LAN, or on a DMZ?



Relevant Pages

  • RE: [fw-wiz] Backup exec agent in dmz
    ... This way you could block these specific ports inbound from the ... mail/antivirus server, a dns server, and a web server. ... I have a windows 2000 server running backup exec version 9 on the primary ... have to set up a separate backup system for the dmz computers. ...
    (Firewall-Wizards)
  • RE: [fw-wiz] Single Exchange/OWA on LAN with Internet Access - a good
    ... OWA front ended by ISA 2003 is solid. ... DMZ - it is designed to "publish" MS products including MS CRM. ... The DMZ server should be able to do ... more than just port filtering and *shouldn't* require all those ports to ...
    (Firewall-Wizards)
  • Re: DMZ & Security
    ... > yes, deployement price, security level (depending what ... > open ports... ... > case what sense has my DMZ? ... if I have a web server on DMZ that have to access sqlserver database ...
    (microsoft.public.security)
  • Re: Best Practices for exposing Exchange to web
    ... >server in the DMZ that handles web access. ... >We are in the process of migrating to Exchange server and I am investigating ... This seems a little scary opening up all these ports ...
    (microsoft.public.exchange.admin)
  • Re: Sonicwall Pro 230 DMZ windows authentication problem
    ... I just replaced the w2k dmz machine with an nt4 server, and set up port 25, ... registry keys to fix the rpc ports, ... This leaves me confused why the w2k server didn't work. ...
    (comp.security.firewalls)