How to setup Authentication against my Domain for my Secure SMTP Relay running on my ISA Firewall box.

Posted on 2004-10-11
Medium Priority
Last Modified: 2013-12-04
Hope this is possible...

I have a secure authenticated SMTP relay running on my ISA 2000 firewall box.  This is a W2K Server with IIS 5.0 SMTP services and is a stand alone server located in my perimeter network (same subnet but is not part of my Domain).

When I am outside of my network, I authenticate against the SMTP relay ONLY IF the User Account exists on the stand alone server (ISA Box).  Then the relay forwards mail appropriately.

Obviously, I do not want to maintain users and passwords both on the ISA 2000 box and in the Domain, but want the users to authenticate against my domain AD.

I have been unfruitful thus far in figuring out how to accomplish this.

Anyone have any suggestions or guidance?

Thanks in advance,

Question by:dabrennan
LVL 11

Expert Comment

ID: 12282663
Hi dabrennan,
i found theeses artices,if yoou wish read point:
"Preventing the IIS 5.0 SMTP Server from Relaying E-mail Messages" from the url:

What about enabling Basic Authentification on your IIS using SSL?


Please,post here your reply ;eg whether i have understood you right or not.
Additional sources:

Author Comment

ID: 12291365
<<<<  Excerpt >>>>>

 Using ISA Server 2004 RADIUS Authentication in Web Publishing Rules (Part 1)
    Date - Oct 07, 2004      Author - Paul Baldwin      Section - Tutorials :: Publishing

A valuable feature in any firewall is an ability to authenticate users before they are allowed to communicate with servers behind that firewall. ISA Server is one of the few firewalls that can provide this service for any Web servers that it publishes, [[[[[[[[[but previously this feature had only been practical if the ISA Server was a domain member with access to the Active Directory.]]]]]]]]]]] With ISA Server 2004 additional methods of authenticating were introduced, one of which allows the ISA Server to authenticate users in the Active Directory without requiring the ISA Server to be a member of that Active Directory forest. The mechanism it uses is RADIUS, a protocol perhaps better known in connection with dial-up and VPN access.

<<<<< www.isaserver.org >>>>>>>

1. I can either disable the SMTP Application Filter on ISA (Which eliminates my protection against buffer overflow) and use a Server Publishing rule to authenticate directly against my Exchange Server SMTP Service.  (Not use a secure SMTP authenticated relay on the ISA Server at all).


2. Must become a member of a domain and setup an incoming one way non-transitive trust to my domain so users can authenticate against my Domain's AD at the ISA Server Box at my Secure SMTP relay.

Accepted Solution

RomMod earned 0 total points
ID: 12330955
The question has been PAQ'd and the 500 points have been refunded.
Community Support Moderator

Featured Post

We Need Your Input!

WatchGuard is currently running a beta program for our new macOS Host Sensor for our Threat Detection and Response service. We're looking for more macOS users to help provide insight and feedback to help us make the product even better. Please sign up for our beta program today!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
How to fix display issue, screen flickering issue when I plug in power cord to the machine. Before I start explaining the solution lets check out once the issue how it looks like after I connect the power cord. most of you also have faced this…
Watch the video to learn how one can deal with PST file corruption issue with an outstanding Kernel for Outlook PST Repair Tool easily. Using this tool, non-technical users can swiftly perform the repair process to restore their essential data witho…
Suggested Courses

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question