I am curious what those of you running OWA have done to make it as secure as possible. It was mentioned in the PIX firewall forum by Yizhar that OWA should not be run from inside of the network unless the users only access via VPN. This makes sense to me but unfortunately our users access OWA from all over, and VPN is not always possible. I was considering putting the Exchange box in the DMZ. If any of you have security advice\experiences with OWA inside the network or in the DMZ, I would greatly appreciate any advice.
Thanks
Brian
Thanks
Brian