Hi there,
Currently configuring Exchange 2003 and need to have OWA access through pix firewall to exchange server sitting on dmz. Users will also have to authenticate to domain controller on inside network. What ports do I need to open on outside interface other than dns, smtp and 443. Don't I need to open ports for authentication as well? Also what ports need to be opened between exchange server and domain controller? Installing CA on domain controller for secure http on exchange server, what ports need to be opened for CA?
Finding alot of conflicting information, just wondering if anybody knows the correct combination of allowed ports.
Here is an example of my access lists so far for these services:
access-list acl_outside permit tcp any host x.x.x.x eq 443
access-list acl_outside permit tcp any host x.x.x.x eq domain
access-list acl_outside permit udp any host x.x.x.x eq domain
access-list acl_outside permit tcp any host x.x.x.x eq smtp
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 135
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 139
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 137
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 138
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 445
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 389
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 636
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq domain
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq domain
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq smtp
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 119
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 110
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 995
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 143
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 993
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq www
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 443
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 88
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 464
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 500
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 593
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 1645
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 1646
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 1701
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 1723
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 1812
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 1813
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 3268
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 3269
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 3389
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 gt 1023
access-list dmz permit tcp host 10.100.75.5 any eq smtp
access-list dmz permit tcp host 10.100.75.5 any eq 443
access-list dmz permit udp host 10.100.75.5 any eq domain
access-list dmz permit tcp host 10.100.75.5 any eq domain
Pretty sure I don't need to allow all the ports I have specified so far, however wondering which ones I really need and any that I have missed. Can someone please help me straighten this mess out?
Thanks,
Loyalist
Currently configuring Exchange 2003 and need to have OWA access through pix firewall to exchange server sitting on dmz. Users will also have to authenticate to domain controller on inside network. What ports do I need to open on outside interface other than dns, smtp and 443. Don't I need to open ports for authentication as well? Also what ports need to be opened between exchange server and domain controller? Installing CA on domain controller for secure http on exchange server, what ports need to be opened for CA?
Finding alot of conflicting information, just wondering if anybody knows the correct combination of allowed ports.
Here is an example of my access lists so far for these services:
access-list acl_outside permit tcp any host x.x.x.x eq 443
access-list acl_outside permit tcp any host x.x.x.x eq domain
access-list acl_outside permit udp any host x.x.x.x eq domain
access-list acl_outside permit tcp any host x.x.x.x eq smtp
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 135
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 139
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 137
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 138
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 445
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 389
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 636
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq domain
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq domain
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq smtp
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 119
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 110
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 995
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 143
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 993
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq www
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 443
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 88
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 464
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 500
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 593
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 1645
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 1646
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 1701
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 1723
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 1812
access-list dmz permit udp host 10.100.75.5 host 10.100.50.5 eq 1813
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 3268
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 3269
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 eq 3389
access-list dmz permit tcp host 10.100.75.5 host 10.100.50.5 gt 1023
access-list dmz permit tcp host 10.100.75.5 any eq smtp
access-list dmz permit tcp host 10.100.75.5 any eq 443
access-list dmz permit udp host 10.100.75.5 any eq domain
access-list dmz permit tcp host 10.100.75.5 any eq domain
Pretty sure I don't need to allow all the ports I have specified so far, however wondering which ones I really need and any that I have missed. Can someone please help me straighten this mess out?
Thanks,
Loyalist