Exchange in DMZ?
Comments
-
sprkymrk Member Posts: 4,884 ■■■□□□□□□□Yeah, I agree. Exchange doesn't belong anywhere other than behind the main corporate firewall. His suggestions of using ISA are valid. A better solution IMHO is to use a VPN to an edge device, then let the firewall inspect the traffic to/from the authenticated clients and the Exchange server.All things are possible, only believe.
-
royal Member Posts: 3,352 ■■■■□□□□□□“For success, attitude is equally as important as ability.” - Harry F. Banks
-
sprkymrk Member Posts: 4,884 ■■■□□□□□□□icroyal wrote:
Looks good - the Exchange server is not in the DMZ.
Personally I wish we were using an ISA firewall where I work. I really got attached to the 2 I managed for a couple of years back in 2001-2002. ISA 2004 and 2006 are looking like they stomp all over ISA 2000 too.All things are possible, only believe. -
garv221 Member Posts: 1,914I declined the dmz exchange as well. I have a ASA5505 I am currently setting up but debated the exchange on a dmz, it just seems like a huge headache with ACLs.