Re: Forest/Domain in the "DMZ" to accomodate web, front-end servers

From: Keith I (kirby)
Date: 09/20/05


Date: Mon, 19 Sep 2005 19:04:38 -0500

Marlon,

What is the purpose of the network segmentation? Would the Front-End
Exchange and Share Point Services (SPS) now exposed directly to the
Internet? If so, you are negating the value of ISA 2004. ISA 2004 has the
hardened External interface, the other server roles do not by default. Do
you trust ISA, if not dump it and use another device for your network
segmentation control. However, I believe ISA 2004 provides a hardened
service for Exchange and SPS. That is the objective of using ISA.

Second, would that DMZ-Domain be trusted by the corporate domain for
authentication? If you are trusting, what should be non-trusted, then you
are again devising a less secure solution than existed prior. The domain is
not the not the Windows 200x security boundy, the forest is the boundry.
So, you'd have to create a new forest with a minimum of two domain
controllers for redundancy.

The other solution might be the DMZ-Domain trusting the corporate domain for
management. While this makes it easier to manage this domain, and is
recommended by some persons for systems of 25 or greater in DMZ, it seems
like this is not your case.

This IT guru is imposing solutions that are just bad ideas, based on ideas
5-10 years ago. Your solution seems right on track. I like Microsoft's
solution provided at
http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/workgroup_ee.mspx
the best.



Relevant Pages

  • Re: Forest/Domain in the "DMZ" to accomodate web, front-end servers
    ... you are negating the value of ISA 2004. ... is accessible from the Internet must be in the perimeter network. ... > service for Exchange and SPS. ...
    (microsoft.public.security)
  • Re: ActiveSync
    ... I've made sure all certs are exported from Exchange to ISA box. ... Before ISA reboot, when ActiveSync starts syncing, nothing gets logged in ... The security certificate on the server is not valid. ...
    (microsoft.public.isa.configuration)
  • Re: Virtueller Speicher reicht nicht aus
    ... Exchange und den Provider in Verdacht gehabt. ... Rückblickend, nachdem der ISA Server durchgestartet wurde, und alles wieder ...
    (microsoft.public.de.german.isaserver)
  • Re: Changing ISPs
    ... Then install the edge device but leave ISA in place. ... Run the CEICW and set the all the ip addresses and the default email ... I would look at the SMTP properties of the userwho cannot receive ... Exchange will not be held anywhere, so a POP connector will not retrieve ...
    (microsoft.public.windows.server.sbs)
  • OWA: SSL-Bridging works with ISA 2000 but not with ISA 2006
    ... this works fine with a web publishing rule on ... I created an Exchange Publishing Rule with SSL and spelled the ... The public name references to an existing DNS record for the ISA ... After saving the rule I'm able to connect to the ISA server and the ...
    (microsoft.public.isa)