Network Architecture Advice

Posted on 2006-06-07
Last Modified: 2010-04-11
I'm coming into this situation where someone else set things up.  I just started looking into a network layout and I'm not sure that I like what I see.  I want to run this by everyone for some advice.  Currently, I'm looking at a network where the domain server is running on windows 2003 business server.  There is one server running linux and two more servers running windows 2003.  Exhange is running on one of the two windows 2003 servers.  VPN access is setup on the exhange server.  Does this layout seem correct?  Does anyone have any suggestions?  I also don't think the system was managed well before because there seems to be some DNS issues on the network.  Any advice would be appreciated.  Should I just start from scratch and reload the main domain server that runs windows 2003 business server?  Thanks in advance your all of your help.
Question by:Quetysis
    LVL 8

    Accepted Solution

    I would not run VPN on the exchange server, for security reasons.  You never want to put your DC or exchange on the edge of you network.  You can run DNS on the DC.  You need one server for DC and DNS, the other for exchange.  You don't need to buy another server to run a backup DC and DNS, just use a desktop.  What is running on the linux box?  You could redo that one and run VPN on it.  

    Author Comment

    An oracle database is running on the linux server.  Maybe we should look at getting a cisco system for our VPN solution.  What do you think?  
    LVL 8

    Expert Comment

    absolutly, was was going to bring that up but it is expensive.  You would need to look into getting a vpn concentrator and that is a much better solution than using windows.  Do you have some money to spend?  I'm just guessing because I have never looked at the cheaper ones but I would say about 10K.
    LVL 16

    Expert Comment

    I don't see a firewall mentioned in your description - depending on the size of your network, you may be able to get a cheaper cisco which could handle your VPN connections and do some firewalling as well (the concentrators are geared towards mucho VPN connections - if you only need a few, you likely don't need the concentrator).

    LVL 5

    Expert Comment

    I was going to say the same - a 501 is man enough for most smaller networks and only costs a few hundred pounds.

    I dont really see having the vpn handled on your exchange server sepcifically as a huge problem in itself, if its implemented correctly. Generally a vpn will give full access into your network, including your exchange server. Small business setup tends to be a matter of compromise.

    The network layout does sound unusual in that if you are running SBS the network, usually exchange would be running on this - not on a seperate server.

    I would get to concerned about the VPN issue just yet. If you are considering formatting an SBS server and 'starting over' because of a few dns problems, you have far greater things to worry about, such as job security.

    Featured Post

    What Should I Do With This Threat Intelligence?

    Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

    Join & Write a Comment

    Let’s list some of the technologies that enable smooth teleworking. 
    ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
    Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    728 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    19 Experts available now in Live!

    Get 1:1 Help Now