Only IIS in DMZ, Exchange (with AD) and SQL Server on internal network

From: Baki (bobradovic2001@yahoo.com)
Date: 09/16/02


From: "Baki" <bobradovic2001@yahoo.com>
Date: Sun, 15 Sep 2002 18:12:10 -0400


Hi guys,
I need to reconfigure our network. We have a 3COM firewall with DMZ. I want
to place IIS in DMZ, and Exchange Server and SQL Server (internet
application database) on our internal network. What ports do I have to open?
I know that I should open TCP 80 for inbound traffic on extrernal interface,
and TCP 1433 between DMZ and internal network. What port do I have to open
for Exchange Server? I suppose it is TCP 25 (SMTP), but do I have to open it
on all interfaces (external, internal and DMZ)?
Thank you in advance,
Baki



Relevant Pages

  • Re: [fw-wiz] Rationale of the great DMZ
    ... >DMZ and its implied security has changed. ... Network activity wouldn't ... >necessarily begin from the DMZ and be tunneled in to the internal network. ... >Commonly SSL accelerators terminate the SSL end point prior to the ...
    (Firewall-Wizards)
  • Re: Firewall and DMZ topology
    ... > network, Windows and Linux. ... > laptop used as a simple firewall setup. ... > machine and placing it in a DMZ. ... > internal network, one for the DMZ and one for the Internet. ...
    (Security-Basics)
  • Re: Firewall and DMZ topology
    ... >> I would like to set up a SOHO network with a firewall and DMZ for mostly ... >> machine and placing it in a DMZ. ... >> internal network, one for the DMZ and one for the Internet. ... >> The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)
  • RE: DMZ
    ... you've got an internal network consisting of workstations and 1 or more ... or other undesirables would be your DMZ machine which means you can harden ... very secure type of setup as it ensures traffic flows through one and ONLY ...
    (Focus-Microsoft)
  • Re: OK, Im sold on SBS2003 now
    ... >>> talking about a real DMZ with a different network. ... A web server belongs in the DMZ, not in the LAN. ... > An Exchange server, for a single server, works very nicely in the DMZ ...
    (microsoft.public.windows.server.sbs)