![]() |
|
|
|||||||
| Petri.co.il is happy to award auglan the title of Most Valuable Member !!! |
| Register | Calendar |
Search |
Today's Posts |
Mark Forums Read |
| Notices |
|
|
Exchange 2003 - OWA Setupthis thread has 5 replies and has been viewed 1163 times
|
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
||||||||
|
||||||||
|
Hi Guys
Im looking for some clarification or sanity check. Ive come across this setup on a new client site, they have an Exchange 2003 Cluster (2 node) on their lan, then they have a OWA Front-end in their DMZ but what i discovered alarmed me. (Do i really see this?) The OWA server has two nics one called LAN Nic and one called DMZ nic, non-sercure (HTTP) traffic is permitted from the internet to the DMZ nic to allow a non-secure connection for OWA/OMA (Obviously needs to be reconfigured to HTTPS) I am correct in thinking because the two nics reside on the one box, if the dmz nic is compromised then the attacker has full access to the LAN awell as there is no router or software as far as i can see regulating traffic between the two nics on the one server? Shouldnt the OWA front end server just have one DMZ nic and any interaction between the lan and dmz be governed by the cisco router and appropriate traffic rules? Thanks in advance |
|
#2
|
||||||||||
|
||||||||||
|
To be honest, there are no good reasons for putting an Exchange server in a DMZ. Doesn't matter how you configure it, compromise the frontend server and you can walk straight in, one or two NICs, doesn't really matter.
Two solutions: 1. Bring the frontend server inside or build a new one fresh inside, then open 443/25 ONLY on the firewall. 2. Bring the frontend server inside or build a new one fresh inside (notice the pattern here), and publish OWA with a reverse proxy like ISA/TMG. Simon.
__________________
-- Simon Butler Exchange MVP Blog: http://blog.sembee.co.uk/ More Exchange Content: http://exchange.sembee.info/ Exchange Resources List: http://exbpa.com/ In the UK? Hire me: http://www.sembee.co.uk/ |
|
#3
|
||||||||
|
||||||||
|
Thanks Simon
Its Exchange 2003, is it not more secure using a DMZ , port 443 is the only open port being passed to the front end since i fixed the SSL? I closed off port 80. OWA/OMA traffic only passes through port 443. At least if the front end somehow gets comprimised its buffered in a DMZ no? Is it not best practice to have the back end hosting the Info Stores and the Front end hosting public SMTP and OWA/OMA and both zones firewalled? |
|
#4
|
||||||||
|
||||||||
|
Had a good read of this and I see where your coming from
http://tigermatt.wordpress.com/2009/...ge-server-dmz/ |
|
#5
|
||||||||
|
||||||||
|
So i see if i use a Vamsoft VM or Hosted spam service locked to my IP that hardens port 25 but could you explain a little more about how secure it is opening up port 443 and forwarding it to my exchange FE on my private lan? Sorry if this sounds like a stupid question, just need a sanity check!
Thanks Simon Last edited by Senan; 13th September 2012 at 00:19.. |
|
#6
|
||||||||||
|
||||||||||
|
Secure? It is more secure than putting it in a DMZ. Single port only.
http://blog.sembee.co.uk/post/Why-yo...-in-a-DMZ.aspx Explains more. Simon.
__________________
-- Simon Butler Exchange MVP Blog: http://blog.sembee.co.uk/ More Exchange Content: http://exchange.sembee.info/ Exchange Resources List: http://exbpa.com/ In the UK? Hire me: http://www.sembee.co.uk/ |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Exchange 2003 setup one one box | snajam.ahmed@gmail.com | Exchange 2000 / 2003 | 1 | 6th August 2012 14:47 |
| Setup environment Migration Exchange 2003 to Exchange 2007 | gaza | Exchange 2007 / 2010 / 2013 | 4 | 28th April 2008 20:37 |
| Brand new Exchange 2007 setup Existing Exchange 2003 | BirdDog | Exchange 2007 / 2010 / 2013 | 1 | 8th October 2007 09:41 |
| Exchange 2003 setup help | msberrigan | Exchange 2000 / 2003 | 1 | 1st September 2005 01:29 |
| Setup and Configure Exchange 2003 on Server 2003 | lcvangtech | Exchange 2000 / 2003 | 2 | 4th May 2004 20:11 |