Solved

adding a linux firewall for exchange server

Posted on 2006-07-07
3
287 Views
Last Modified: 2010-03-18
Right now I have been asked to add a firewall to our network for our exchange server. We are running Exchange server on a stand alone server that also acts as a secondary dns server for our network. Is there a distro anyone would reccomend? Or is there any applications or services we should use in paticular?

Also what potential complications would there be running a firewall in front of our exchange server/secondary dns server?

Would it be much easier just to run a isa server instead?

Thanks for your help as allways!

-Brian
0
Comment
Question by:Calv1n
3 Comments
 
LVL 19

Expert Comment

by:alextoft
ID: 17061834
IPcop is very capable in these kinds of scenarios. Plug internet into 1 socket, LAN into the other. Point and click gui interface. For mail all you're going to need is port 25 open. 80 & 443 for the Outlook Web Access, and 53 for DNS.

Any linux distro can easily take care of this, but if you're not comfortable working command line, try something like SuSE which has a very easy to use graphical firewall control panel.

ISA (InSecurity &  Annihilation  server) is the worst kind, and avoided at all costs.
0
 
LVL 22

Accepted Solution

by:
pjedmond earned 500 total points
ID: 17069084
I particularly recommend smoothwall www.smoothwall.org, or Devil Linux www.devil-linux.org. Astaro linux is a superb (but commercial Firewall distribution - www.astaro.com).

Why use a dedicated linux firewall?:

1.  Minimal software on the box to be compromised.
2.  chroot setup minimises the software available to 'abuse' from 1 even further.
3.  Seperate box, so even if the firewall is compromised, the attackers still haven't gained access to corporate secrets.
4.   Can be used to provide a firewall/vpn capability without degrading your main server's capabilities.
5.   If you use an 'old' PC, then you can have a high quality configurable firewall virtually free of charge! How much will the isa server set you back?

(   (()
(`-' _\
 ''  ''
0
 
LVL 5

Expert Comment

by:xylog
ID: 17069395
If you are inexperienced at Linux I would recommend Smoothwall - http://www.smoothwall.org/ or IPcop as above, both are similar and capable linux based firewalls, Smoothwall has a free version as well as a commercial version. I have used both and both are good IMHO.

If you are hardcore I would recommend OpenBSD. You dont need much beyond the default install to have a highly capable firewall and it is one of, if not the most secure OS's there is.

I have to disagree with the previous comments on ISA server. It is a fine firewall - the big problem here is the underlying OS - You dont want to have reboot your firewall everytime MS puts out a browser patch. That said You can lock down ISA and Windows to make a secure it just takes alot longer than with a linux based system.
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Join & Write a Comment

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now