Solved

How to setup Authentication against my Domain for my Secure SMTP Relay running on my ISA Firewall box.

Posted on 2004-10-11
4
247 Views
Last Modified: 2013-12-04
Hope this is possible...

I have a secure authenticated SMTP relay running on my ISA 2000 firewall box.  This is a W2K Server with IIS 5.0 SMTP services and is a stand alone server located in my perimeter network (same subnet but is not part of my Domain).

When I am outside of my network, I authenticate against the SMTP relay ONLY IF the User Account exists on the stand alone server (ISA Box).  Then the relay forwards mail appropriately.

Obviously, I do not want to maintain users and passwords both on the ISA 2000 box and in the Domain, but want the users to authenticate against my domain AD.

I have been unfruitful thus far in figuring out how to accomplish this.

Anyone have any suggestions or guidance?

Thanks in advance,

Dave
0
Comment
Question by:dabrennan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 11

Expert Comment

by:mwnnj
ID: 12282663
Hi dabrennan,
i found theeses artices,if yoou wish read point:
"Preventing the IIS 5.0 SMTP Server from Relaying E-mail Messages" from the url:
http://support.microsoft.com/default.aspx?scid=kb;en-us;q310356&sd=tech

What about enabling Basic Authentification on your IIS using SSL?

http://www.winnetmag.com/Web/Article/ArticleID/15843/Web_15843.html
http://www.win2000mag.com/articles/index.cfm?articleid=8443
http://support.microsoft.com/default.aspx?scid=kb;en-us;301457&sd=tech

Please,post here your reply ;eg whether i have understood you right or not.
Thanks!
-------------------
Additional sources:
http://www.iis-resources.com/index.php
http://www.isaserver.org/
http://www.microsoft.com/technet/itsolutions/howto/admhow.mspx
http://support.microsoft.com/default.aspx?scid=kb;en-us;300958&sd=tech
0
 

Author Comment

by:dabrennan
ID: 12291365
<<<<  Excerpt >>>>>

 Using ISA Server 2004 RADIUS Authentication in Web Publishing Rules (Part 1)
    Date - Oct 07, 2004      Author - Paul Baldwin      Section - Tutorials :: Publishing

A valuable feature in any firewall is an ability to authenticate users before they are allowed to communicate with servers behind that firewall. ISA Server is one of the few firewalls that can provide this service for any Web servers that it publishes, [[[[[[[[[but previously this feature had only been practical if the ISA Server was a domain member with access to the Active Directory.]]]]]]]]]]] With ISA Server 2004 additional methods of authenticating were introduced, one of which allows the ISA Server to authenticate users in the Active Directory without requiring the ISA Server to be a member of that Active Directory forest. The mechanism it uses is RADIUS, a protocol perhaps better known in connection with dial-up and VPN access.

<<<<< www.isaserver.org >>>>>>>

1. I can either disable the SMTP Application Filter on ISA (Which eliminates my protection against buffer overflow) and use a Server Publishing rule to authenticate directly against my Exchange Server SMTP Service.  (Not use a secure SMTP authenticated relay on the ISA Server at all).

or

2. Must become a member of a domain and setup an incoming one way non-transitive trust to my domain so users can authenticate against my Domain's AD at the ISA Server Box at my Secure SMTP relay.
0
 

Accepted Solution

by:
RomMod earned 0 total points
ID: 12330955
The question has been PAQ'd and the 500 points have been refunded.
RomMod
Community Support Moderator
0

Featured Post

Why You Need a DevOps Toolchain

IT needs to deliver services with more agility and velocity. IT must roll out application features and innovations faster to keep up with customer demands, which is where a DevOps toolchain steps in. View the infographic to see why you need a DevOps toolchain.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
OfficeMate Freezes on login or does not load after login credentials are input.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question