Solved

How safe is Outlook Web Access?

Posted on 2004-04-12
2
401 Views
Last Modified: 2011-09-20
I currently only have OWA available through VPN access because I'm afraid that if I open up the port we are going to be attacked.  How safe is OWA?  Is it only safe when you have front and back end servers?  It would be a lot easier for me to just allow users to access their e-mail without the use of a VPN, because most of the user's don't like the VPN and have trouble using it.  Thank your for any information you have on the subject.
0
Comment
Question by:jonykarate
2 Comments
 
LVL 10

Accepted Solution

by:
dstoker509 earned 50 total points
ID: 10807692
OWA is very safe when setup correctly.  For Exchange 2000/2003, the best method is to have the FE servers located in the internal network with an ISA proxy located in the DMZ.  Read http://www.msexchange.org/tutorials/pubowa2003toc.html

You can also do it with the FE server located in the DMZ, but you will have to open more ports through your internal firewall.
http://www.msexchange.org/tutorials/OWA_Exchange_Server_2003.html
0
 
LVL 10

Expert Comment

by:OneHump
ID: 10808090
The safety question is not with OWA, but with the data OWA provides access to.  Keep in mind that you're running IIS which has its share of security concerns.  Keep your security patches current, open only the ports you need and use SSL AND, without question, use dual factor authentication.  Do those things and you are probably OK.  

The only way to completely secure your data is to not expose it to the Internet.  All you are doing here is reducing risk, not eliminating it.

OneHump
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Skype for Business server 6 45
Exchange 2013 - Recieve Connectors 4 24
Exchange 2013 on premise  mailbox  issue 2 37
Error on OWA 2016 14 21
This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question