Re: Is it better let users access webmail with different URL's inside vs. outside ?

From: Byron Hynes (nospam_at_byronetta.com)
Date: 04/01/05


Date: Thu, 31 Mar 2005 19:48:23 -0800


> However, I talked today to another securty guy and he claims that it
> is better to distinguish URL's and let ISA between external traffic
> (https://webmail.domain.com/exchange). If I make the 'internal' users
> getting redirected to the ISA box in the DMZ, that means anyone
> spoofing my internal addresses could be accepted as well.

Most large organizations handle it by having two sets of DNS servers. DNS
inside the LAN/WAN directs mail.ourcorp.com to 10.0.0.10 and publicly accessible
DNS servers outside the LAN/WAN directs to, say, 199.247.2.1.

I smaller organizations with less technically-savvy users, I usually have
internal and external users use the same FQDN.

Personally, I think the most important thing is to REQUIRE SSL. And, if doing
that, remember that you may have issues with https://ourmail/exchange not
matching the certificate issued to https://mail.ourcorp.com

- Byron Hynes



Relevant Pages

  • Re: DNS / Outgoing Mail Issue
    ... >> Is it forwarding to ISA or to your ISP? ... > the DNS servers we are using, ...
    (microsoft.public.windows.server.dns)
  • Re: Initial browse to a web site is painfully slow
    ... You could check the registry setting for PathMTU. ... I think the SBS ISA 2004 installation fixed the external MTU at a small number like 512 bytes due to an ISA vulnerability at the time. ... That way, the SBS will use the Internet Root DNS servers instead of your ISP's servers, at least for experimental purposes. ...
    (microsoft.public.windows.server.sbs)
  • Re: DNS Server does not answer "nslookup" on ISA Server 2004
    ... Certainly setting up two DNS servers (one Internal and one ... External) is the recommended solution, but I guess in this case, the original ... > Phillip Windell ... >> Although, that is a good suggestion, isn't is possible to run ISA on a DC? ...
    (microsoft.public.isa)
  • Re: ISA slow
    ... I had a similar issue - again down to DNS servers being ste wrong. ... We have a fast DSL connection and directly going out ... over the DSL modem does not show any slowdown so something is up with ISA. ... Lots of information on user usage but ...
    (microsoft.public.windows.server.sbs)
  • Re: Arghhh..... DNS and ISA :-0
    ... Most corporations use stateful firewalls that understand the traffic flow. ... I'm not sure how ISA handles this, since I don't think it supports static ... A good site to check your DNS from the Internet is www.dnsreport.com. ... How do I implement DNS servers in an ISA Server environment? ...
    (microsoft.public.isa)