Solved

Bad idea to run File server as Exchange server, too?

Posted on 2002-05-28
9
259 Views
Last Modified: 2010-03-05
Our company is contemplating moving to an Exchange server.  (We currently use POP mail from the host of ouwebsites.)  The consultants who are helping us with the project have suggested getting a new server that will run Exchange (with OWA) for our corporate email, while also serving as the file server.  Any issues with this?  It's been suggested by someone else in the company that this constitutes a serious security risk, given that it will be publicly accessible (in order to provide remote access to email via the Web).  

We will most likely put the Exchange/file server behind a (Cisco PIX) firewall, if that makes any difference.  We won't run websites on it, and it will only serve one other application, a payroll database (small company, 35 employees).  We hope to go ahead and start purchasing hardware and software by Friday, so that's more or less my deadline.  Thanks in advance for your comments.  
0
Comment
Question by:jonathanv_00
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
  • +3
9 Comments
 
LVL 23

Expert Comment

by:slink9
ID: 7041623
The firewall is a plus.  If you have the firewall configured properly and haven't missed anything, you should be okay.  I wouldn't want to stake my job (and possibly freedom) on that, though.  If someone skirts around the firewall or it is not configured to block them as it should, they will have access to your payroll information.  That could possibly send the installer and company higher-ups to jail.  I would go for a separate, non-connected server for the payroll app.
0
 
LVL 28

Expert Comment

by:vinnyd79
ID: 7041796
listening...
0
 
LVL 3

Expert Comment

by:MCummings111400
ID: 7042028
I agree with slink9 on this one. Although you are a small business, storing company sensitive information like payroll, on your Exchange server, to save money on hardware, may only cause you problems in the future.

As for the comment about not running any websites on it, where is OWA going to be installed? Typically this will run on your exchange server, and will require the installation of IIS. So your E\xchnage server will expose (by default) ports for the following services HTML,POP3,IMPA4, and NNTP, not to mention the standard NT ports that are used.

Depending on the firewall you use, it is recommended to statically assign a forwarding for ONLY those ports you want to have access to to your exchange server, in your case port 80.
0
Creating Instructional Tutorials  

For Any Use & On Any Platform

Contextual Guidance at the moment of need helps your employees/users adopt software o& achieve even the most complex tasks instantly. Boost knowledge retention, software adoption & employee engagement with easy solution.

 

Author Comment

by:jonathanv_00
ID: 7042234
Ah, thanks, folks.  Good point about the OWA - I wasn't even thinking of that as a website, but obviously you have to have something to host the site if you're going to give folks web access.  (I'm a bit slow in the mornings.)  

Thinking out loud, or in print . . . we will have an extra server when this gets done - the old NT 4.0 file server.  Could that be configured to be the OWA server (it has IIS on it already)?  Or would it be a better idea just to leave the payroll app on that machine, separate from the Exchange/file server?  I had thought of using it to host an Intranet for the company after we move to Win2K and Exchange.

Thanks very much -- there will be points for each of you when we're finished.
0
 
LVL 23

Expert Comment

by:slink9
ID: 7042242
Separate.  The intranet isn't a bad idea.  
0
 
LVL 55

Expert Comment

by:andyalder
ID: 7042442
You could apply an extra level of security above the normal OWA username/password by securing the webserver with Secure Computing's SafeWord. A hacker would have to guess the one-time pseudo-random password the token generates from the users PIN as well as their username and password.

See if you can access my OWA account at www.genisys.co.uk/exchange
0
 
LVL 8

Expert Comment

by:steinmto
ID: 7042863
What version of exchange are you going to?  If it is Exchange 2000 to install the web access on a different server you have to install another copy of exchange on the server.  Here is a white paper on doing this.

With many of our clients we put the owa on a port different from 80.  We do this mainly to stop worms that work on port 80 from entering the server.
http://www.microsoft.com/Exchange/techinfo/deployment/2000/E2KFrontBack.asp

It looks like you would be a good fit for Small Business Server 2000 unless you have more that 50 connections.  This is much cheaper that buying one copy of exchange and of copy w2k plus the licences.

Tom
0
 
LVL 3

Accepted Solution

by:
MCummings111400 earned 200 total points
ID: 7042876
I would leave your payroll on the NT4 box, you could also host an intranet on there as well. (The optimizations for a fileserver and web server are pretty much the same) Exhcnage and OWA on thier own box. And if you really need it a sepreate fileserver machine. Exchange Servers and fileservers do not optimize the same way. So I would see 2-3 servers in your case.

1) FileServer - Coporate files and Payroll DB
2) Exchange Server
3) Web Server - OWA and Intranet
0
 

Author Comment

by:jonathanv_00
ID: 7057625
Thanks to all for your replies.  Look for some separate point questions going out to a few of you.

We're going to stick with the consultants' plan as far as putting Exchange and the file server on the same machine. We just upped the processor and improved the RAM quite a bit over the Dell machine that they spec'd for us; we'll be getting a white box that's much more powerful for about 2/3 the cost.  That should make up for some of the Exchange licenses, too -- unfortunately, there's something about SBS that doesn't like multiple sites (we have three offices).

But I do like the different port idea, Steinmoto. 100 points consolation for that.  AndyAlder - you always have very good advice, so I'll look into that security solution.  Thanks again to all.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Utilizing an array to gracefully append to a list of EmailAddresses
MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question