Petri IT Knowledgebase Forums
 

Petri.co.il forums Home Forums Start Page Forums Frequently Asked Questions FAQ Member List Members List
Go Back   Petri IT Knowledgebase Forums > Messaging Software > Exchange 2000 / 2003
Petri.co.il is happy to award auglan the title of Most Valuable Member !!!
Register Calendar Calendar Search Petri IT Knowledgebase Forums Search Todays Posts Today's Posts Mark Forums Read

Notices

Exchange 2003 - OWA Setup

Exchange 2003 - OWA Setup

this thread has 5 replies and has been viewed 1163 times

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 12th September 2012, 13:08
Senan Senan is offline
Casual
Casual
 
 Join Date: May 2007
  6 month star 12 month star
 Posts: 34
 Reputation: Senan is on a distinguished road (10)
Default Exchange 2003 - OWA Setup

Hi Guys

Im looking for some clarification or sanity check.

Ive come across this setup on a new client site, they have an Exchange 2003 Cluster (2 node) on their lan, then they have a OWA Front-end in their DMZ but what i discovered alarmed me. (Do i really see this?)

The OWA server has two nics one called LAN Nic and one called DMZ nic, non-sercure (HTTP) traffic is permitted from the internet to the DMZ nic to allow a non-secure connection for OWA/OMA (Obviously needs to be reconfigured to HTTPS)

I am correct in thinking because the two nics reside on the one box, if the dmz nic is compromised then the attacker has full access to the LAN awell as there is no router or software as far as i can see regulating traffic between the two nics on the one server?

Shouldnt the OWA front end server just have one DMZ nic and any interaction between the lan and dmz be governed by the cisco router and appropriate traffic rules?

Thanks in advance
  #2  
Old 12th September 2012, 21:55
Sembee's Avatar
MVP Sembee Sembee is offline
MVP
MVP
 
 Join Date: Apr 2006
  6 month star 12 month star
 Location: Newbury, UK
 Posts: 6,201
 Reputation: Sembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud of (1100)
Default Re: Exchange 2003 - OWA Setup

To be honest, there are no good reasons for putting an Exchange server in a DMZ. Doesn't matter how you configure it, compromise the frontend server and you can walk straight in, one or two NICs, doesn't really matter.

Two solutions:

1. Bring the frontend server inside or build a new one fresh inside, then open 443/25 ONLY on the firewall.
2. Bring the frontend server inside or build a new one fresh inside (notice the pattern here), and publish OWA with a reverse proxy like ISA/TMG.

Simon.
__________________
--
Simon Butler
Exchange MVP

Blog: http://blog.sembee.co.uk/
More Exchange Content: http://exchange.sembee.info/
Exchange Resources List: http://exbpa.com/
In the UK? Hire me: http://www.sembee.co.uk/
  #3  
Old 12th September 2012, 23:43
Senan Senan is offline
Casual
Casual
 
 Join Date: May 2007
  6 month star 12 month star
 Posts: 34
 Reputation: Senan is on a distinguished road (10)
Default Re: Exchange 2003 - OWA Setup

Thanks Simon

Its Exchange 2003, is it not more secure using a DMZ , port 443 is the only open port being passed to the front end since i fixed the SSL? I closed off port 80. OWA/OMA traffic only passes through port 443.

At least if the front end somehow gets comprimised its buffered in a DMZ no?

Is it not best practice to have the back end hosting the Info Stores and the Front end hosting public SMTP and OWA/OMA and both zones firewalled?
  #4  
Old 12th September 2012, 23:47
Senan Senan is offline
Casual
Casual
 
 Join Date: May 2007
  6 month star 12 month star
 Posts: 34
 Reputation: Senan is on a distinguished road (10)
Default Re: Exchange 2003 - OWA Setup

Had a good read of this and I see where your coming from

http://tigermatt.wordpress.com/2009/...ge-server-dmz/
  #5  
Old 13th September 2012, 00:10
Senan Senan is offline
Casual
Casual
 
 Join Date: May 2007
  6 month star 12 month star
 Posts: 34
 Reputation: Senan is on a distinguished road (10)
Default Re: Exchange 2003 - OWA Setup

So i see if i use a Vamsoft VM or Hosted spam service locked to my IP that hardens port 25 but could you explain a little more about how secure it is opening up port 443 and forwarding it to my exchange FE on my private lan? Sorry if this sounds like a stupid question, just need a sanity check!

Thanks Simon

Last edited by Senan; 13th September 2012 at 00:19..
  #6  
Old 14th September 2012, 03:22
Sembee's Avatar
MVP Sembee Sembee is offline
MVP
MVP
 
 Join Date: Apr 2006
  6 month star 12 month star
 Location: Newbury, UK
 Posts: 6,201
 Reputation: Sembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud ofSembee has much to be proud of (1100)
Default Re: Exchange 2003 - OWA Setup

Secure? It is more secure than putting it in a DMZ. Single port only.

http://blog.sembee.co.uk/post/Why-yo...-in-a-DMZ.aspx

Explains more.

Simon.
__________________
--
Simon Butler
Exchange MVP

Blog: http://blog.sembee.co.uk/
More Exchange Content: http://exchange.sembee.info/
Exchange Resources List: http://exbpa.com/
In the UK? Hire me: http://www.sembee.co.uk/
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Exchange 2003 setup one one box snajam.ahmed@gmail.com Exchange 2000 / 2003 1 6th August 2012 14:47
Setup environment Migration Exchange 2003 to Exchange 2007 gaza Exchange 2007 / 2010 / 2013 4 28th April 2008 20:37
Brand new Exchange 2007 setup Existing Exchange 2003 BirdDog Exchange 2007 / 2010 / 2013 1 8th October 2007 09:41
Exchange 2003 setup help msberrigan Exchange 2000 / 2003 1 1st September 2005 01:29
Setup and Configure Exchange 2003 on Server 2003 lcvangtech Exchange 2000 / 2003 2 4th May 2004 20:11


All times are GMT +3. The time now is 05:07.

Steel Blue 3.5.4 vBulletin Style ©2006 vBEnhanced
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
 

Valid XHTML 1.0!   Valid CSS!

Copyright 2005 Daniel Petri