Re: Exhange 5.5 Behind Firewall?

From: Robert Moir (maranbat@bitey.force9.co.uk)
Date: 08/08/02


From: "Robert Moir" <maranbat@bitey.force9.co.uk>
Date: Thu, 8 Aug 2002 20:06:07 +0100


"Steve" <howard_steve@medicalert.org> wrote in message
news:1ed501c23f0d$9398bae0$35ef2ecf@TKMSFTNGXA11...
> We just recently moved our Exhcnage Server from our
> internal LAN to our DMZ for protection.
>
> But In the process, I have had to make a lot of changes
> and open ports just to allow the Exchange server to work.
> Backup went from 15 minutes to several hours.
>
> Was it worth it? The jury is still out.
>
> I could have left it where it was, with only 3 ports
> open ( 80,443, and 25) and watch it closely, or the
> current plan on the DMZ but with HTTP, HTTPS, SMTP,
> NETBIOS, RPC, Static DS and ISA ports mapped, and the list
> goes on.
>
> And, when I move to Exchange 2000, I will need to open
> more for AD Replication.
>
> How are most of you maintaining your email servers, on
> the LAN, or on a DMZ?

On the lan. If you have to open all those ports to put something on the
other side of your firewall it kinda makes you wonder why you bothered
having the firewall installed to begin with. You can publish HTTP pages
behind a proxy, use a SMTP gateway, etc, theres no reason to expose your
network in this way.



Relevant Pages

  • Re: Web portal security
    ... win2003 standard server with IIS, SSL enabled and will be placed on ... So I will be fwding port 443 in firewall to my DMZ port. ... Well, assuming you are going to use teh SQL database from SBS, you can ... subnet than my LAN and map one to one from firewall to dmz. ...
    (microsoft.public.windows.server.sbs)
  • Re: 2 NICs Configuration Problem
    ... Servers on the DMZ are public, ... provides NAT for the LAN machines, allowing them to reach the Internet ... effectively bypassing firewall filtering to that server. ... Ethernet adapter Server Local Area Connection: ...
    (microsoft.public.windows.server.networking)
  • Re: Where to put the server
    ... Put the 2003 IIS Server in the DMZ. ... SBS box or another LAN server. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Hosting, in or out?
    ... proprietary SQL based application is the core of the business. ... A new requirement calls for a report only server, ... SBS LAN is called PRIVATE or LAN ... Web LAN is called RESTRICTED or DMZ ...
    (microsoft.public.windows.server.sbs)
  • RE: [fw-wiz] Backup exec agent in dmz
    ... This way you could block these specific ports inbound from the ... mail/antivirus server, a dns server, and a web server. ... I have a windows 2000 server running backup exec version 9 on the primary ... have to set up a separate backup system for the dmz computers. ...
    (Firewall-Wizards)