Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

OWA in DMZ, nearly there, just a couple of Questions

Status
Not open for further replies.

ianbla

IS-IT--Management
Oct 31, 2001
156
0
0
GB
I have it up & running. Exchange 2000 Enterprise in the DMZ, Exchange 2000 on the inside, all necessary ports on the PIX open, SSL installed. Everything works fine, just a couple of questions.

from inside I cannot get to
1) I have put in an entry on the internal DNS to point the hostname mail > 172.16.128.103, I can nslookup and get the right result but still cannot enter
2) What extra security steps can I take on the DMZ machine, it has W2K SP3 and Exchange SP3, only 80 & 443 are open on the firewall, is this good enough?

Many thanks
Ian.
 
The brower may be leaving your network and not looking on your DMZ. you may have to add DNS entries for to resolve that URL and add more than one IP address.

Also try changing the PIX permits to any any to the email servers to see if it changes the error message or fixes the problems you are having.

--
On the DMZ exchange server remove all information stores so it becomes just a gateway. Then use IPSEC mandatory GPO and configure NICS same way, except the public side nic will have to support non-IPSEC too.
 
Also run the IIS lockdown tool and Microsoft Baseline security analyzer agianst the server. if you dont you could have some major problems.

have a nice day Doomhamur
Network Engineer

"Certifications? we dont need no stinking certifiaction."
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top