Solved

Linux Firewall for Microsoft Exchange Server

Posted on 2006-07-07
2
246 Views
Last Modified: 2006-11-18
Right now I have been asked to add a firewall to our network for our exchange server. We are running Exchange server on a stand alone server that also acts as a secondary dns server for our network. Is there a distro anyone would reccomend? Or is there any applications or services we should use in paticular?

Also what potential complications would there be running a firewall in front of our exchange server/secondary dns server?

Would it be much easier just to run a isa server instead?

Thanks for your help as allways!

-Brian
0
Comment
Question by:Calv1n
2 Comments
 
LVL 17

Accepted Solution

by:
BudDurland earned 500 total points
ID: 17063113
If the only functionality you need is firewall, there are several Linux based solutions.  The one I like best (mostly because I'm NOT very familiar with Linux) is SmoothWall Express (www.smoothwall.org). It's free, runs on just about anything pentium based, and installes from a single CD.  It's kid of an appliance.  This is not a linux distro for doing general computing.  it only does firewalling.  It's very easy to configure, and opening ports so that your Exchange box can continue to be a secondary DNS visible to the internet is easily accomplished.

They also have a commercial version that offers more advanced features -- content filtering, access control, VPN, multiple 'red' addresses, etc.
0
 
LVL 104

Expert Comment

by:Sembee
ID: 17065422
I ran a Linux firewall infront of an Exchange server for two years. It was fine. Exchange doesn't need many ports open - just 25 (smtp) and 443 (https). I only ditched it because I wanted a PIX and its VPN solution.

I used floppyfw for mine. An old 486 with two NICs, no hard disk or CD-ROM drive.

The choice of firewall is down to what you have experience in.

ISA is a complex beast with a learning curve. It is more than just a firewall, it is also a proxy server and will inspect the packets.

If you have confidence in using a Linux solution, then go ahead and use that.
If you want something where you can get a support contract, then look at something like a PIX, Netscreen etc.
Either of those two solutions will be much cheaper than an ISA and will give you a dedicated box.

Simon.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Greetings, Experts! First let me state that this website is top notch. I thoroughly enjoy the community that is shared here; those seeking help and those willing to sacrifice their time to help. It is fantastic. I am writing this article at th…
Trying to figure out group policy inheritance and which settings apply where can be a chore.  Here's a very simple summary I've written which might help.  Keep in mind, this is just a high-level conceptual overview where I try to avoid getting bogge…
I've attached the XLSM Excel spreadsheet I used in the video and also text files containing the macros used below. https://filedb.experts-exchange.com/incoming/2017/03_w12/1151775/Permutations.txt https://filedb.experts-exchange.com/incoming/201…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question